diff --git a/reference/PAN-OS/addressed/12.2.2.html b/reference/PAN-OS/addressed/12.2.2.html new file mode 100644 index 0000000..cc71f3a --- /dev/null +++ b/reference/PAN-OS/addressed/12.2.2.html @@ -0,0 +1,38 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-242777
+
+
+ Fixed an issue where running debug online diagnostics run on a 5G + supported PA-400 firewall models reported "Missing device on I2C bus" + errors and did not execute cellular modem diagnostic tests. This + occurred because the diagnostics script used an incorrect I2C device + list for the 5G supported PA-400 hardware variants and did not + recognize it as a cellular-capable platform. With this fix, the I2C + scan correctly reflects the 5G supported PA-400 hardware configuration + and cellular modem tests run as expected. +
+
diff --git a/reference/PAN-OS/known/10.2.0.html b/reference/PAN-OS/known/10.2.0.html new file mode 100644 index 0000000..b9ab6f1 --- /dev/null +++ b/reference/PAN-OS/known/10.2.0.html @@ -0,0 +1,3797 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WIF-495
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ On the Panorama management server, edits made to an existing data + filtering profile (Objects > DLP > Data Filtering Profiles) can result in matching traffic not being detected by Enterprise + DLP. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-288097
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-264281
+
+
+ When upgrading a ZTP firewall from PAN-OS 10.2 to PAN-OS 11.1 or later + versions, if you use the + To SW Version column to specify the + target PAN-OS version, the upgrade process downloads and installs the + intermediary base version containing an expired root certificate. This + causes the ZTP firewall to lose connection with Panorama +
+
+ Workaround: Follow the standard upgrade process + from Panorama, which you use for non-ZTP firewalls, to upgrade to the + target PAN-OS version that contains the valid root certificate. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-241536
+
+
+ On the Panorama management server, a user with an Admin Role is unable + to modify or add filters to profiles under + PanoramaNetworkRoutingRouting ProfilesFilters, despite having the necessary read and write privileges. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-229702
+
+
+ After upgrading a Panorama HA pair to PAN-OS 11.1, the ElasticSearch + connectivity might fail to establish. The issue occurs because the + client certificate on one of the Panorama devices does not have the + necessary Extended Key Usage (EKU) set for server authentication, + which is required for secure TLS communication. +
+
+ Workaround:Contact Customer Support to renew the + root client certificate. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223488
+
+ This issue is now resolved. See + PAN-OS 10.2.7 Addressed Issues. +
+
+ Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. +
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests + for /config fail with the + following error due to exceeding the + total configuration size + supported on the M-600 appliance. +
+ +
+
504 Gateway timeout
+
+
+
PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209937
+
+
+ Certificate-based authentication for administrator accounts may be + unable to log into the Panorama or firewall web interface with the + following error: +
+
+ Bad Request - Your browser sent a request that this server could + not understand +
+
+
PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ The following NextGen firewalls and Panorama management server models + are unable to automatically renew the device certificate (DeviceSetupManagement + or + PanoramaSetupManagement). +
+
    +
  • M-300 and M-700
  • +
  • PA-410 Firewall
  • +
  • +
    PA-440, PA-450, and PA-460 Firewalls
    +
  • +
  • PA-3400 Series
  • +
  • +
    PA-5410, PA-5420, and PA-5430 Firewalls
    +
  • +
  • PA-5450 Firewall
  • +
+
+ Workaround: Log in to the + firewall CLI + or + Panorama CLI + and fetch the device certificate. +
+ +
+
admin>request certificate fetch
+
+
+
PAN-207629
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, selective push fails to managed + firewalls if the managed firewalls are enabled with multiple vsys and + the Push Scope contains shared objects in device groups. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the + configd process crashes. This + results in the Dedicated Log Collector losing connectivity to Panorama + despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-206268
+
+
+ On the Panorama management server, the Auth Key field was erroneously + displayed when you configure the Panorama Settings (DeviceSetupManagement) as part of a template or template stack configuration. +
+
+
PAN-206253
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ For PA-3400 Series firewalls, the default log rate is set too low and + the max configurable log rate is incorrectly capped resulting in the + firewall not generating more than 6,826 logs per second. +
+
+
PAN-206243
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ The PA-220 firewall reaches the maximum disk usage capacity multiple a + day that requires a disk cleanup. A critical system log (MonitorLogsSystem) is generated each time the firewall reaches maximum disk usage + capacity. +
+
+
PAN-205187
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ ElasticSearch may not start properly when a newly installed Panorama + virtual appliance powers on for the first time, resulting in the + Panorama virtual appliance being unable to query logs forwarded from + the managed firewall to a Log Collector. +
+
+ Workaround: + Log in to the Panorama CLI + and start the PAN-OS software. +
+ +
+
admin>request restart software
+
+
+
PAN-204663
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, you are unable to Context Switch + from one managed firewall to another. +
+
+ Workaround: After you Context Switch to a managed + firewall, you must first Context Switch back to Panorama before you + can continue to Context Switch to a different managed firewall. +
+
+
PAN-201855
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the Panorama management server, cloning any template (PanoramaTemplates) corrupts certificates (DeviceCertificate ManagementCertificates) with the + Block Private Key Export setting + enabled across all templates. This results in managed firewalls + experiencing issues wherever the corrupted certificate is referenced. +
+
+ For example, you have template A, B, and C where templates A and B + have certificates with the + Block Private Key Export setting + enabled. Cloning template C corrupts the certificates with + Block Private Key Export setting + enabled in templates A and B. +
+
+ Workaround: After cloning a template, delete and + re-import the corrupted certificates. +
+
+
PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On M-600 appliances in an Active/Passive high availability (HA) + configuration, the + configd process restarts due to a + memory leak on the + Active Panorama HA peer. This + causes the Panorama web interface and CLI to become unresponsive. +
+
+ Workaround: Manually reboot the + Active Panorama HA peer. +
+
+
PAN-197341
+
+
+ On the Panorama management server, if you create multiple device group + Objects with the same name in the + Shared device group and any additional device groups (PanoramaDevice Groups) under the same device group hierarchy that are used in one or more + Policies, renaming the object with a + shared name in any device group causes the object name to change in + the policies where it is used. This issue applies only to device group + objects that can be referenced in a Security policy rule. +
+
For example:
+
    +
  1. +
    + You create a parent device group + DG-A and a child device group + DG-B. +
    +
  2. +
  3. +
    + You create address objects called + AddressObjA in the + Shared, + DG-A and + DG-B device groups and add + AddressObjA to a Security + policy rule under DG-A and + DG-B. +
    +
  4. +
  5. +
    + Later, you change the + AddressObjA name in the + Shared device group to + AddressObjB. +
    +
  6. +
+
+ Changing the name of the address object in the + Shared device group causes the + references in the Policy rule to use the renamed + Shared object instead of the + device group object. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196720
+
+
+ During the CN-Series firewall deployment on Oracle OKEplatform, when + you delete the deployment by deleting yamls, the MP/DP pods are stuck + in Terminating state. +
+
+ Workaround: Delete the CN-Series DP pods, MP pods, + and then the pan-cni yaml file in a sequential order. +
+
+
PAN-194826
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ (WF-500 appliance only) System log forwarding + does not work over a TLS connection. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-193251
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ If SAML is configured as the authentication method for GlobalProtect, + authentication on the Portal page is not successful in the browser. +
+
+ Workaround: Use the GlobalProtect app installed on + the endpoint to authenticate. +
+
+
PAN-192403
+
+
+ (PA-5450 firewall only) There is no commit + warning in the web interface when configuring the management interface + and logging interface in the same subnetwork. Having both interfaces + in the same subnetwork can cause routing and connectivity issues. +
+
+
PAN-191570
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ The Traffic Activity and SSL/TLS widgets in the + ACC erroneously display + Report Error if there is no SSL + data to display. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-190435
+
+
+ When you Commit a configuration + change, the Task Manager commit + Status goes directly from + 0% to + Completed and does accurately + reflect the commit job progress. +
+
+
PAN-190311
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ (PA-220 and PA-220R firewalls and PA-800 Series firewalls only) There is an issue where management connectivity to the firewall is + lost due to the expiration of the DHCP lease, which causes the IP + configuration on the management port to be purged. +
+
+
PAN-189425
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, + Export Panorama and devices config bundle + (PanoramaSetupOperations) fails to export. When the export fails, you are redirected to a new + window and the following error is displayed: +
+
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log + (Permission denied) +
+
+
PAN-189395
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ Running any version of PAN-OS 10.2 on a PA-400 Series firewall can + cause the dataplane process to restart unexpectedly and trigger a + crash. +
+
+
PAN-189380
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ After you successfully upgrade a PA-3000 Series firewall to PAN-OS + 10.2.0 or later release and Enterprise data loss prevention (DLP) + plugin 3.0.0 or later release, the first configuration push from the + Panorama management server causes the firewall dataplane to crash. +
+
+ Workaround: Restart the firewall to restore + dataplane functionality. +
+
    +
  1. + Log in to the firewall CLI. +
  2. +
  3. +
    + Restart the firewall. +
    +
    admin> request restart system
    +
    +
    +
  4. +
+
+
PAN-189361
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ Panorama is unable to distribute antivirus signature updates to + firewalls with only an Advanced Threat Prevention license. Firewalls + with previously installed and active Threat Prevention license are + unaffected. +
+
+
PAN-189298
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ On deploying the HA with 10.2.0-98 in Packet-mmap mode, the session + sync for an existing session fails after restarting an active DP in + Packet-mmap mode. +
+
+
PAN-189214
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ When the Advanced Threat Prevention license is present on a firewall + without a Threat Prevention license, the antivirus signature update + packages that are normally available to install under + DeviceDynamic Updates + are not displayed. +
+
+ Workaround: Use the + request anti-virus upgrade {info | download | install} + CLI commands to retrieve a list of available antivirus updates and the + download and installation status, download specific antivirus + packages, and to install antivirus packages.Optionally, you can + schedule recurring automatic updates using the following CLI command: + set deviceconfig system update-schedule anti-virus recurring. +
+
+
PAN-189206
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ Device Group and Template administrator roles don't support a context + switch between the Panorama and firewall web interface. +
+
+ Workaround: Use a Superuser or Panorama + administrator role to context switch. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189106
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ On the Panorama management server, you must uninstall the ZTP Plugin + 2.0 before you can successfully downgrade to PAN-OS 10.1. After + successful downgrade, you must reinstall the latest ZTP Plugin 1.0 + version. +
+
+ Workaround: Before you downgrade Panorama to + PAN-OS 10.1, uninstall ZTP Plugin 2.0. After you successfully + downgrade Panorama to PAN-OS 10.1, re-install ZTP Plugin 1.0 and + re-enable ZTP functionality. +
+
    +
  1. + Log in to the Panorama web interface. +
  2. +
  3. + Uninstall the ZTP Plugin. +
  4. +
  5. Downgrade Panorama to PAN-OS 10.1.
  6. +
  7. + Log in to the Panorama web interface. +
  8. +
  9. + Install the ZTP plugin. +
  10. +
  11. + Select + PanoramaZero Touch Provisioning + and check (enable) ZTP. +
  12. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-189057
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ On the Panorama management server, Panorama enters a + non-functional state due to + php.debug.log life taking up too + much space. +
+
+ Workaround: Disable the debug flag for Panorama. +
+
    +
  1. + Log in to the Panorama web interface. +
  2. +
  3. +
    + In the same browser you are logged into the Panorama web + interface, enter the following URL. +
    +
    + https://<panorama_ip>/debug +
    +
  4. +
  5. + Uncheck (disable) Debug or + Clear Debug. +
  6. +
  7. + (HA configuration) Repeat this step on each + Panorama high availability (HA) peer if Panorama is in a HA + configuration. +
  8. +
+
+
PAN-189032
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ When the firewall has Advanced Routing enabled, an OSPFv3 interface + configured with the p2mp link type causes the commit to fail. +
+
+
PAN-188956
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ After successful upgrade to PAN-OS 10.2, logging in to the firewall or + Panorama web interface from the same Internet browser window or + session from which the firewall or Panorama was upgraded displays the + following error: +
+
+ Your login session has expired and you have been logged out for + security reasons. Please log in again if you wish to continue. +
+
+ Workaround: The following are different ways to + log in to the firewall or Panorama web interface after upgrading to + PAN-OS 10.2. +
+
    +
  • + Close the browser and log in to the firewall or Panorama web + interface from an entirely new browser session. +
  • +
  • + Clear your browser cache for the browser from which you upgraded the + firewall or Panorama. +
  • +
  • + Log in to the firewall or Panorama web interface from the browser in + Incognito mode. +
    + If you upgraded the firewall or Panorama from a browser in + Incognito mode, close the browser and log in to the firewall or + Panorama web interface from an entirely new browser session. +
    +
  • +
  • + Log in to the firewall or Panorama web interface from a different + browser than the one used to upgrade to PAN-OS. +
  • +
+
+
PAN-188904
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Certain web pages and web page contents might not properly load when + cloud inline categorization is enabled on the firewall. +
+
+
PAN-188489
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ On the Panorama management server, dynamic content updates are not + automatically pushed to VM-Series firewalls licensed using the + Panorama Software Firewall License plugin when + Automatically push content when software device registers to + Panorama + (PanoramaTemplatesAdd Stack) is enabled. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-188064
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ The SCP Server Profile configuration (DevicesServer ProfilesSCP + are not automatically deleted after downgrade from PAN-OS 10.2.0 to + PAN-OS 10.1 or earlier release. +
+
+
PAN-188052
+
+
+ Devices in FIPS-CC mode are unable to connect to servers utilizing + ECDSA-based host keys that impacts exporting logs (DeviceScheduled Log Export), exporting configurations (DeviceScheduled Config Export), or the scp export command in the + CLI. +
+
+ Workaround: Use RSA-based host keys on the + destination server. +
+
+
PAN-187846
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ On the Panorama management server, a selective push (CommitPush to DevicesPush Changes Made By + and + CommitCommit and Push Commit and Push Changes Made By) may push an incorrect configuration to managed firewalls causing + the firewalls to display as Out of Sync if the + Panorama pushed version for the Shared Policy and Template + configuration (PanoramaManaged DevicesSummary) are 20 version or more older than the current local running + configuration on Panorama. +
+
+ To determine the current configuration version, select + PanoramaConfig Auditand expand the + Local Running config menu to review + the list of Panorama configuration versions. +
+
+ Workaround: Push a more recent configuration to + your managed firewalls before performing a selective push. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187429
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ On PA-3400 & PA-5400 series firewalls (minus the PA-5450), the CLI + and SNMP MIB walk do not display the Model and Serial-number of the + Fan tray and PSUs. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-187234
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ Certain web pages submitted for analysis by Advanced URL Filtering + cloud inline categorization might experience high latency. +
+
+
PAN-186913
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ On the Panorama management server, + Validate Device Group (CommitCommit and Push + erroneously issues a CommitAll operation instead of a ValidateAll + operation when multiple device groups are included in the push and + results in no configuration validation. +
+
+ Workaround: Validate device group configurations + using one of the following methods. +
+
    +
  • + Select only one device group when you + Validate Device Group for a + Commit and Push to managed + firewalls. +
  • +
  • + To validate multiple device groups, select + CommitCommit to Panorama + first. After the device group configuration is committed to + Panorama, select + CommitPush to Devices + and Validate Device Group to + validate multiple device groups. +
  • +
+
+
PAN-186886
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ Individual configuration objects cannot be viewed when you commit + selective configuration changes (CommitCommit Changes Made By) on a multi-vsys firewall. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-186262
+
+
+ The Panorama management server in Panorama or Log Collector mode may + become unresponsive as Elasticsearch accumulates internal connections + related to logging processes. The chances Panorama becomes + unresponsive increases the longer Panorama remains powered on. +
+
+ Workaround: Reboot Panorama if it becomes + unresponsive. +
+
+
PAN-186137
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ The management interface of the PA-3400 Series firewall incorrectly + displays 10G port speed as an option. 10G speed is not supported on + the PA-3400 Series firewall management port and cannot be configured. +
+
+
PAN-186134
+
+
+ On the Panorama management server, performing a + Commit and Push (Commit > Commit and Push) may intermittently not push the committed configuration changes to + managed firewalls. +
+
+ Workaround: Select + Commit > Push to Devices to push + the committed configuration changes to your managed firewalls. +
+
+
PAN-185966
+
+
+ The + debug skip-cert-renewal-check-syslog yes + command is not available on Log Collector CLI to stop the Dedicated + Log Collector from trying to renew the device certificate and + displaying the following error: +
+
+ No valid device certificate found +
+
+
PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ (PA-5400 Series firewalls only) On the Panorama + management server, the device health resources (PanoramaManaged DevicesHealth) do not populate. +
+
+
PAN-184708
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184702
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ On the Panorama management server, an M-700 appliance in Log Collector + mode fails to connect to Panorama when added as a managed collector + (Panorama > Managed Collectors). +
+ +
+
PAN-184474
+
+
+ When the firewall has Advanced Routing enabled, a static route stays + active after the interface goes down. +
+
+ Workaround: For firewalls that support + Bidirectional Forwarding Detection (BFD), configure BFD for the static + route. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183567
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ On the Panorama management server, you must download and install the + ZTP Plugin 2.0 after successful upgrade to PAN-OS 10.2. After upgrade + to PAN-OS 10.2, the + show plugins installed command does + not display the ZTP plugin until you install ZTP Plugin 2.0. +
+
+ Workaround: After Panorama successfully upgrades + to PAN-OS 10.2, manually download and install the ZTP Plugin 2.0. +
    +
  1. + Log in to the Panorama web interface. +
  2. +
  3. + Select + PanoramaPlugins + and search for the ztp plugin. +
  4. +
  5. + Download and + Install ZTP Plugin 2.0. +
  6. +
+
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-182734
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel + configuration, BGP flaps. +
+
+
PAN-182492
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ The WildFire analysis report cannot be viewed from the firewall + WildFire submission log entry page. +
+
+ Workaround: You can retrieve the Wildfire analysis + reports through the WildFire API or the WildFire portal. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-179420
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ On the Panorama management server, a selective push (CommitPush to DevicesPush Changes Made By + and + CommitCommit and PushCommit and Push Changes Made By + to managed firewalls fails if you rename an existing device group, + template, or template stack that was already pushed to your managed + firewalls and you selectively committed specific configuration objects + from the renamed device group, template, or template stack. +
+
+ Workaround: After you rename the existing device + group, template, or template stack, + Push (CommitPush to Devices + all configuration changes for the named device group, template, or + template stack. +
+
+
PAN-178195
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ The URL filtering logs generated by traffic analyzed by Advanced URL + filtering cloud inline categorization does not display the name of the + URL. +
+
+
PAN-177455
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-176693
+
+ This issue is now resolved. See PAN-OS 10.2.1 Addressed Issues. +
+
+
+ The Activity (ACT) LEDs on the RJ-45 ports of the M-300 and M-700 + appliances do not blink while processing network traffic. +
+
+
PAN-176156
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues +
+ . +
+
+ Executing + show running resource-monitor with + the ingress-backlogs option produces + the following server error: + Dataplane is not up or invalid target-dp(*.dp*). +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-172132
+
+ This issue is now resolved by PAN-189643. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ QoS fails to run on a tunnel interface (for example, tunnel.1). +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-171069
+
+
+ Local Log Collectors for Panorama management servers in active/passive + high availability (HA) configuration cannot be added to the same + Collector Group (PanoramaCollector Groups). +
+
+ Workaround: Before you upgrade your Panorama + servers to PAN-OS 10.1.0, configure HA (PanoramaHigh Availability), add the local Log Collectors of the HA peers to the same Collector + Group, and upgrade to PAN 10.1.0. +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
+
PAN-163676
+
+
+ Next-Gen Firewalls are unable to connect to a syslog server when the + certificates required to connect to the syslog server are part of a + Certificate Profile (DeviceCertificate ManagementCertificate Profile) if the Use OCSP setting is + enabled to check the revocation status of certificates. +
+
+ Workaround: Enable + Use CRL to check the revocation + status of certificates in the Certificate Profile. +
+
diff --git a/reference/PAN-OS/known/10.2.1.html b/reference/PAN-OS/known/10.2.1.html new file mode 100644 index 0000000..92d35fa --- /dev/null +++ b/reference/PAN-OS/known/10.2.1.html @@ -0,0 +1,2968 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223488
+
+ This issue is now resolved. See + PAN-OS 10.2.7 Addressed Issues. +
+
+ Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. +
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests + for /config fail with the + following error due to exceeding the + total configuration size + supported on the M-600 appliance. +
+ +
+
504 Gateway timeout
+
+
+
PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ The following NextGen firewalls and Panorama management server models + are unable to automatically renew the device certificate (DeviceSetupManagement + or + PanoramaSetupManagement). +
+
    +
  • M-300 and M-700
  • +
  • PA-410 Firewall
  • +
  • +
    PA-440, PA-450, and PA-460 Firewalls
    +
  • +
  • PA-3400 Series
  • +
  • +
    PA-5410, PA-5420, and PA-5430 Firewalls
    +
  • +
  • PA-5450 Firewall
  • +
+
+ Workaround: Log in to the + firewall CLI + or + Panorama CLI + and fetch the device certificate. +
+ +
+
admin>request certificate fetch
+
+
+
PAN-207629
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, selective push fails to managed + firewalls if the managed firewalls are enabled with multiple vsys and + the Push Scope contains shared objects in device groups. +
+
+
PAN-206268
+
+
+ On the Panorama management server, the Auth Key field was erroneously + displayed when you configure the Panorama Settings (DeviceSetupManagement) as part of a template or template stack configuration. +
+
+
PAN-206253
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ For PA-3400 Series firewalls, the default log rate is set too low and + the max configurable log rate is incorrectly capped resulting in the + firewall not generating more than 6,826 logs per second. +
+
+
PAN-206243
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ The PA-220 firewall reaches the maximum disk usage capacity multiple a + day that requires a disk cleanup. A critical system log (MonitorLogsSystem) is generated each time the firewall reaches maximum disk usage + capacity. +
+
+
PAN-205187
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ ElasticSearch may not start properly when a newly installed Panorama + virtual appliance powers on for the first time, resulting in the + Panorama virtual appliance being unable to query logs forwarded from + the managed firewall to a Log Collector. +
+
+ Workaround: + Log in to the Panorama CLI + and start the PAN-OS software. +
+ +
+
admin>request restart software
+
+
+
PAN-204663
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, you are unable to Context Switch + from one managed firewall to another. +
+
+ Workaround: After you Context Switch to a managed + firewall, you must first Context Switch back to Panorama before you + can continue to Context Switch to a different managed firewall. +
+
+
PAN-201855
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the Panorama management server, cloning any template (PanoramaTemplates) corrupts certificates (DeviceCertificate ManagementCertificates) with the + Block Private Key Export setting + enabled across all templates. This results in managed firewalls + experiencing issues wherever the corrupted certificate is referenced. +
+
+ For example, you have template A, B, and C where templates A and B + have certificates with the + Block Private Key Export setting + enabled. Cloning template C corrupts the certificates with + Block Private Key Export setting + enabled in templates A and B. +
+
+ Workaround: After cloning a template, delete and + re-import the corrupted certificates. +
+
+
PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On M-600 appliances in an Active/Passive high availability (HA) + configuration, the + configd process restarts due to a + memory leak on the + Active Panorama HA peer. This + causes the Panorama web interface and CLI to become unresponsive. +
+
+ Workaround: Manually reboot the + Active Panorama HA peer. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-194826
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ (WF-500 appliance only) System log forwarding + does not work over a TLS connection. +
+
+
PAN-194708
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ URL filtering logs (MonitorLogsURL Filtering) erroneously truncate a 16KB Header value and do not display the + Header values that follow the truncated 16KB header. +
+
+ For example, a URL filtering log has 5 Headers. The second Header has + a 16KB value. In the URL filtering log, the first header and the value + are displayed, second Header value is truncated, and remaining three + headers are not displayed. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-193251
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ If SAML is configured as the authentication method for GlobalProtect, + authentication on the Portal page is not successful in the browser. +
+
+ Workaround: Use the GlobalProtect app installed on + the endpoint to authenticate. +
+
+
PAN-192403
+
+
+ (PA-5450 firewall only) There is no commit + warning in the web interface when configuring the management interface + and logging interface in the same subnetwork. Having both interfaces + in the same subnetwork can cause routing and connectivity issues. +
+
+
PAN-190735
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ Certain webpages that use chunked-encoded data transfers might not + load properly when analyzed by Advanced URL Filtering cloud inline + categorization. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-190435
+
+
+ When you Commit a configuration + change, the Task Manager commit + Status goes directly from + 0% to + Completed and does accurately + reflect the commit job progress. +
+
+
PAN-189425
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, + Export Panorama and devices config bundle + (PanoramaSetupOperations) fails to export. When the export fails, you are redirected to a new + window and the following error is displayed: +
+
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log + (Permission denied) +
+
+
PAN-189395
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ Running any version of PAN-OS 10.2.1 on a PA-400 Series firewall can + cause the dataplane process to restart unexpectedly and trigger a + crash. +
+
+
PAN-189380
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ After you successfully upgrade a PA-3000 Series firewall to PAN-OS + 10.2.0 or later release and Enterprise data loss prevention (DLP) + plugin 3.0.0 or later release, the first configuration push from the + Panorama management server causes the firewall dataplane to crash. +
+
+ Workaround: Restart the firewall to restore + dataplane functionality. +
+
    +
  1. + Log in to the firewall CLI. +
  2. +
  3. +
    + Restart the firewall. +
    +
    admin> request restart system
    +
    +
    +
  4. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-189057
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ On the Panorama management server, Panorama enters a + non-functional state due to + php.debug.log life taking up too + much space. +
+
+ Workaround: Disable the debug flag for Panorama. +
+
    +
  1. + Log in to the Panorama web interface. +
  2. +
  3. +
    + In the same browser you are logged into the Panorama web + interface, enter the following URL. +
    +
    + https://<panorama_ip>/debug +
    +
  4. +
  5. + Uncheck (disable) Debug or + Clear Debug. +
  6. +
  7. + (HA configuration) Repeat this step on each + Panorama high availability (HA) peer if Panorama is in a HA + configuration. +
  8. +
+
+
PAN-188904
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Certain web pages and web page contents might not properly load when + cloud inline categorization is enabled on the firewall. +
+
+
PAN-188489
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ On the Panorama management server, dynamic content updates are not + automatically pushed to VM-Series firewalls licensed using the + Panorama Software Firewall License plugin when + Automatically push content when software device registers to + Panorama + (PanoramaTemplatesAdd Stack) is enabled. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-188064
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ The SCP Server Profile configuration (DevicesServer ProfilesSCP + are not automatically deleted after downgrade from PAN-OS 10.2.0 to + PAN-OS 10.1 or earlier release. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187429
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ On PA-3400 & PA-5400 series firewalls (minus the PA-5450), the CLI + and SNMP MIB walk do not display the Model and Serial-number of the + Fan tray and PSUs. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-187234
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ Certain web pages submitted for analysis by Advanced URL Filtering + cloud inline categorization might experience high latency. +
+
+
PAN-186913
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ On the Panorama management server, + Validate Device Group (CommitCommit and Push + erroneously issues a CommitAll operation instead of a ValidateAll + operation when multiple device groups are included in the push and + results in no configuration validation. +
+
+ Workaround: Validate device group configurations + using one of the following methods. +
+
    +
  • + Select only one device group when you + Validate Device Group for a + Commit and Push to managed + firewalls. +
  • +
  • + To validate multiple device groups, select + CommitCommit to Panorama + first. After the device group configuration is committed to + Panorama, select + CommitPush to Devices + and Validate Device Group to + validate multiple device groups. +
  • +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-186262
+
+
+ The Panorama management server in Panorama or Log Collector mode may + become unresponsive as Elasticsearch accumulates internal connections + related to logging processes. The chances Panorama becomes + unresponsive increases the longer Panorama remains powered on. +
+
+ Workaround: Reboot Panorama if it becomes + unresponsive. +
+
+
PAN-186134
+
+
+ On the Panorama management server, performing a + Commit and Push (Commit > Commit and Push) may intermittently not push the committed configuration changes to + managed firewalls. +
+
+ Workaround: Select + Commit > Push to Devices to push + the committed configuration changes to your managed firewalls. +
+
+
PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ (PA-5400 Series firewalls only) On the Panorama + management server, the device health resources (PanoramaManaged DevicesHealth) do not populate. +
+
+
PAN-184708
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184702
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ On the Panorama management server, an M-700 appliance in Log Collector + mode fails to connect to Panorama when added as a managed collector + (Panorama > Managed Collectors). +
+ +
+
PAN-184474
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ When the firewall has Advanced Routing enabled, a static route stays + active after the interface goes down. +
+
+ Workaround: For firewalls that support + Bidirectional Forwarding Detection (BFD), configure BFD for the static + route. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-182734
+
+ This issue is now resolved. See + PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel + configuration, BGP flaps. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues. +
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-176156
+
+ This issue is now resolved. See PAN-OS 10.2.2 Addressed Issues +
+
+
+ Executing + show running resource-monitor with + the ingress-backlogs option produces + the following server error: + Dataplane is not up or invalid target-dp(*.dp*). +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-172132
+
+ This issue is now resolved by PAN-189643. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ QoS fails to run on a tunnel interface (for example, tunnel.1). +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/10.2.10.html b/reference/PAN-OS/known/10.2.10.html new file mode 100644 index 0000000..b533618 --- /dev/null +++ b/reference/PAN-OS/known/10.2.10.html @@ -0,0 +1,2237 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as + unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-280196
+
+
+ After generating hipmatch/userid logs, the hipmatch logs written + counter is missing from + debug log-receiver statistics. This causes the firewall to match a HIP object but not on the HIP + profile that contained the object. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-292344
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the + firewall reboots repeatedly and enters maintenance mode. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+ This issue affects PAN-OS 10.2.10-h2 +
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286255
+
+ This issue affects PAN-OS 10.2.10-h17 +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions , NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-282236
+
+
+ The firewall doesn't reassemble IPv6 packets correctly after they are + fragmented. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-279746
+
+
+ An SSL/TLS Client Hello may not be sent if the Client Hello arrives at + the firewall in multiple TCP segments and the traffic is not subject + to SSL decryption. +
+
+
PAN-275077
+
(PAN-OS 10.2.10-h9 only)
+
+
+ DNS Security intermittently logs malicious domain URLs as alert + instead of taking a sinkhole action, + even when configured to sinkhole malicious DNS domains. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
+ PAN-270549 (PAN-OS 10.2.10-h2 through PAN-OS 10.2.10-h12) +
+
+ This issue is now resolved. See + PAN-OS 10.2.10-h14 Addressed Issues. +
+
+
+ Some TLS connections are not handled correctly leading to an + instability in the dataplane of PAN-OS. +
+
+
+ PAN-269106 (PAN-OS 10.2.10-h9 only) +
+
+
+ When using a cloud-based ML detection engine (MICA), the + wifclient might crash during + server cert verification for MICA gRPC connections and cause the + dataplane to restart. On certain platforms, this might cause the + firewall to reboot. +
+
+ Workaround: Disable CRL using the following CLI + command:debug iot eal key-value PAN_ICD_SERVER_CERT_USE_CRL=False +
+
+
+ PAN-269052 (PAN-OS 10.2.10-h9 only) +
+
+
+ Traffic might be blocked by a URL Filtering profile that isn't + associated with the Security policy rule that the traffic matches. +
+
+
+ PAN-268823 (PAN-OS 10.2.10-h9 only) +
+
+ This issue is now resolved. See PAN-OS 10.2.10-h10 Addressed Issues. +
+
+
+ (PA-5250 firewall only) Applying filters under + MonitorLog Display + either causes the logs to load slowly or not load at all. +
+
+
+ PAN-268815 (PAN-OS 10.2.10-h9 only) +
+
+ This issue is now resolved. See PAN-OS 10.2.13-h5 Addressed Issues. +
+
+
+ When using IoT Security, the + wifclient might exit multiple + times causing the firewall to reboot. +
+
+ Workaround: Uninstall the IoT Security license and + disable + Enable enhanced application logging + (DeviceManagementCloud LoggingCloud Logging Settings). +
+
+
+ PAN-268260 (PAN-OS 10.2.10-h9 only) +
+
+
+ On hardware firewalls where, when SSL decryption was enabled on layer + 2, vwire, TAP, VLAN deployments, and Client Hello messages spanned + multiple TCP segments, some SSL decryption sessions failed. +
+
+
PAN-267671
+
(PAN-OS 10.2.10-h9 only)
+
+
+ Exporting reports in PDF or CSV format and processing hourly scheduled + report results can potentially trigger memory leaks. As a result, this + can lead to process crashes and firewall reboots. +
+
+ PAN-266900 (PAN-OS 10.2.10-h9 only) + +
+ In Panorama, the OK button does not + work when trying to install configurations to a managed firewall from + the + Managed DevicesSummaryInstall + section, even after selecting the update type and file from the + drop-down menu and choosing the firewall. +
+
+ PAN-263226 (PAN-OS 10.2.10-h2 and 10.2.10-h3 only) + +
+ When SSL decryption is enabled and Client Hello messages span multiple + TCP segments, elements from the proxy_l2info memory pool may not be + freed properly. Memory leaks in this pool cause some SSL decryption + sessions to fail. +
+
+ Workaround: Disable Client Hello accumulation + using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
+
+
PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues. +
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues +
+
+
+ The command + show auth radius-require-msg-authentic + might return no output. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-259997
+
+ This issue is now resolved. See PAN-OS 10.2.10-h3 Addressed Issues. +
+
+
+ On PA-3410, PA-3420, and PA-3430 firewalls, the install fails when + upgrading from PAN-OS 10.2.3-h3 and later 10.2 releases to PAN-OS + 10.2.10 due the number of configured vsys zones exceeding the zone + limit in PAN-OS 10.2.10. +
+
+ Workaround: Before installing PAN-OS 10.2.10, + reduce the number of security zones to 40 zones or fewer for PA-3410 + and PA-3420 firewalls, and to 100 zones or fewer for PA-3430 + firewalls. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-259733
+
+ This issue is now resolved. See PAN-OS 10.2.10-h2 Addressed Issues. +
+
+
+ Custom reports created in PAN-OS are not deleted as expected, + resulting in high memory use by the + reportd + process. This can lead to issues, such as out-of-memory conditions, + content installation failures, and unexpected firewall reboots. +
+
+
PAN-259344
+
+ This issue is now resolved. See PAN-OS 10.2.10-h3 Addressed Issues. +
+
+
+ Performing a configuration commit on a firewall, either locally or + from Panorama, causes a memory leak by the + configd + process and results in an out-of-memory (OOM) condition. +
+
+
PAN-258570
+ (PAN-OS 10.2.10-h9 only) +
+ This issue is now resolved. See + PAN-OS 10.2.13 Addressed Issues. +
+
+
+ The + varrcvr + process might progressively use more memory resulting in unexpected + reboots when WildFire file forwarding is handling PE files. +
+
+
PAN-257957
+
+ This issue is now resolved. See PAN-OS 10.2.12 Addressed Issues.Affects 10.2.10-h3 and later 10.2 releases. +
+
+
+ If you enable FIPS-CC mode and use the PAP or CHAP authentication + methods for your RADIUS server, the authd process may restart + unexpectedly. To avoid this issue, use one of the following + workarounds: +
+
    +
  • + If you use PAN-OS 10.2.10-h3, 10.2.11, or an earlier version, + configure the RADIUS server so that it does not send the message + authenticator back to client. +
  • +
  • + Use other protocols, such as LDAP, Kerberos, TACACS+, SAML, RADIUS + EAP, instead of RADIUS PAP or CHAP. +
  • +
  • Change from FIPS mode to normal mode.
  • +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-226361
+
+ This issue is now resolved. See PAN-OS 10.2.10-h7 Addressed Issues. +
+
+
+ Sessions might end unexpectedly with the error + resources-unavailable when the + firewall incorrectly interprets the Content and Threat Detection (CTD) + global packet queue as being full. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.11.html b/reference/PAN-OS/known/10.2.11.html new file mode 100644 index 0000000..7b861b9 --- /dev/null +++ b/reference/PAN-OS/known/10.2.11.html @@ -0,0 +1,1864 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-292344
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the + firewall reboots repeatedly and enters maintenance mode. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
PAN-279746 +
+ An SSL/TLS Client Hello may not be sent if the Client Hello arrives at + the firewall in multiple TCP segments and the traffic is not subject + to SSL decryption. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-265336
+
+ This issue is now resolved. See PAN-OS 10.2.11-h2 Addressed Issues. +
+
+
+ Copper ports flap when generating a technical support file, executing + telemetry, or retrieving port status using a Management Data + Input/Output (MDIO) read. +
+
+
PAN-264680
+
+ This issue is now resolved. See PAN-OS 10.2.11-h3 Addressed Issues. +
+
+
+ (PA-220 firewalls only) + DeviceSetup + is not displayed when the Enterprise Data Loss Prevention (E-DLP) + plugin is installed. +
+
+ Workaround: Uninstall the Enterprise DLP plugin. +
+
    +
  1. Log in to the firewall web interface.
  2. +
  3. +
    + Select + DevicePlugins. +
    +
  4. +
  5. +
    + Search for dlp. +
    +
  6. +
  7. +
    Uninstall.
    +
  8. +
+
+
PAN-264580
+
+
+ (PA-3400 Series firewalls only) Upgrading to + PAN-OS 10.2.11 results in the following error: + Target image validation failed with error invalid literal for int() + with base 10. +
+
PAN-263226 +
+ When SSL decryption is enabled and Client Hello messages span multiple + TCP segments, elements from the proxy_l2info memory pool may not be + freed properly. Memory leaks in this pool cause some SSL decryption + sessions to fail. +
+
+ Workaround: Disable Client Hello accumulation + using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
+
+
PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues. +
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues +
+
+
+ The command + show auth radius-require-msg-authentic + might return no output. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-257957
+
+ This issue is now resolved. See PAN-OS 10.2.12 Addressed Issues.Affects 10.2.11-h1 and later 10.2 releases. +
+
+
+ If you enable FIPS-CC mode and use the PAP or CHAP authentication + methods for your RADIUS server, the authd process may restart + unexpectedly. To avoid this issue, use one of the following + workarounds: +
+
    +
  • + If you use PAN-OS 10.2.10-h3, 10.2.11, or an earlier version, + configure the RADIUS server so that it does not send the message + authenticator back to client. +
  • +
  • + Use other protocols, such as LDAP, Kerberos, TACACS+, SAML, RADIUS + EAP, instead of RADIUS PAP or CHAP. +
  • +
  • Change from FIPS mode to normal mode.
  • +
+
+
PAN-257601
+
+ Fixed in + PAN-OS 10.2.11. Affects 10.2.11-h2 and later 10.2 releases. +
+
+
+ (PA-5450 firewalls only) Networking cards can + experience an internal link fault, causing path monitoring failure on + the Dataplane Processing Card (DPC). +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in Traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-226361
+
+ This issue is now resolved. See PAN-OS 10.2.11-h4 Addressed Issues. +
+
+
+ Sessions might end unexpectedly with the error + resources-unavailable when the + firewall incorrectly interprets the Content and Threat Detection (CTD) + global packet queue as being full. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling the + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a JavaScript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on an M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to an M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 Series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific websites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (high availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the Traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the Advanced URL Filtering license, your license + entitlements for PAN-DB and Advanced URL Filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.12.html b/reference/PAN-OS/known/10.2.12.html new file mode 100644 index 0000000..b8160da --- /dev/null +++ b/reference/PAN-OS/known/10.2.12.html @@ -0,0 +1,1668 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-292344
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the + firewall reboots repeatedly and enters maintenance mode. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
PAN-279746 +
+ An SSL/TLS Client Hello may not be sent if the Client Hello arrives at + the firewall in multiple TCP segments and the traffic is not subject + to SSL decryption. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues. +
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues +
+
+
+ The command + show auth radius-require-msg-authentic + might return no output. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-257601
+
+ Fixed in + PAN-OS 10.2.11. Affects 10.2.11-h2 and later 10.2 releases. +
+
+
+ (PA-5450 firewalls only) Networking cards can + experience an internal link fault, causing path monitoring failure on + the Dataplane Processing Card (DPC). +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.13.html b/reference/PAN-OS/known/10.2.13.html new file mode 100644 index 0000000..d8b6f63 --- /dev/null +++ b/reference/PAN-OS/known/10.2.13.html @@ -0,0 +1,2245 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as + unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-297775
+
+
+ The wrong vsys is referenced under Visible Virtual System after every + local firewall commit (auto-commit, commit, content install) if the + display name of the vsys matches another vsys ID (for example, the + vsys2 display name is vsys1). The incorrect vsys reference causes + inter-vsys routing to fail. +
+
+ Workaround: Change the vsys display name so that + it doesn't reference an existing vsys ID. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-293673
+
+
+ When the firewall generates a high volume of logs and attempts to + export these logs to an FTP server, it may consume excessive memory + leading to all PAN-OS processes crashing. +
+
+
PAN-292344
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the + firewall reboots repeatedly and enters maintenance mode. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289102
+
+ (This issue affects PAN-OS 10.2.13-h7) +
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, + PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and + CN-Series firewalls only) A race condition issue leads to a dataplane restart when a predict + session is hit at the moment when it's timing out. +
+
+
PAN-288930
+
(PAN-OS 10.2.13-h7 only)
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues +
+
+
+ When ACE (App-ID Cloud Engine) is enabled, traffic from cloud + applications might intermittently match an incorrect + cloud-apps policy rule. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286255
+
+ This issue affects PAN-OS 10.2.13-h5 +
+
+ This issue is now resolved. See + PAN-OS 10.2.13-h7 Addressed Issues. +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions , NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
+ PAN-285941This issue is now resolved. See PAN-OS 10.2.16 Addressed Issues +
+
+
+ When netflow is enabled, the + logrcvr process might get stuck, + resulting in the local logging and log forwarding to stop functioning. + Running + debug log-receiver queue-stats on the + CLI will show the + "Logs discarded (queue full)" field + incrementing over time. +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-284066
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ After an upgrade, the + IF-MIB::ifInErrors SNMP polled + values display errors that don't match the results from the + show interface CLI command. +
+
+
PAN-283467
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues +
+
+
+ (PA-3400 Series firewalls only) The firewall + might unexpectedly reboot and enter maintenance mode due to a + ctd-agent + out-of-memory (OOM) condition when undergoing advanced services load + testing with a high volume of IoT EAL log forwarding. +
+
+ Workaround: Limit the number of EAL logs generated + by the firewall using the following CLI command: + debug iot eal key-value EAL_PENDING_BYTES=1000. +
+
+
PAN-283331
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ Selective pushes to managed devices fail when the + User ID Master Device is configured. +
+
+
PAN-282236
+
+
+ The firewall doesn't reassemble IPv6 packets correctly after they are + fragmented. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-279901
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+
+ PAN-279746 (PAN-OS 10.2.13-h1 through PAN-OS 10.2.13-h4) +
+
+ This issue is now resolved. See + PAN-OS 10.2.13-h5 Addressed Issues. +
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if + the Client Hello arrives in multiple TCP segments and the traffic is + not subject to SSL decryption (for example, SMTP over SSL). +
+
+
PAN-279604
+
(PAN-OS 10.2.13-h3 only)
+
+ This issue is now resolved. See PAN-OS 10.2.13-h4 Addressed Issues. +
+
+
+ The scheduled SaaS application usage reports are incorrectly generated + and only the login page appears instead of the intended report + content. +
+
+
PAN-275077
+
(PAN-OS 10.2.13-h4 only)
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ DNS Security intermittently logs malicious domain URLs as alert + instead of taking a sinkhole action, + even when configured to sinkhole malicious DNS domains. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-270849
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ The configd process leaks a small + amount of memory in every commit. +
+
+
+ PAN-269106 (PAN-OS 10.2.13-h4 only) +
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ When using a cloud-based ML detection engine (MICA), the + wifclient might crash during + server cert verification for MICA gRPC connections and cause the + dataplane to restart. On certain platforms, this might cause the + firewall to reboot. +
+
+ Workaround: Disable CRL using the following CLI + command:debug iot eal key-value PAN_ICD_SERVER_CERT_USE_CRL=False +
+
+
+ PAN-269052 (PAN-OS 10.2.13-h4 and later 10.2.13 releases) +
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ Traffic might be blocked by a URL Filtering profile that isn't + associated with the Security policy rule that the traffic matches. +
+
+
+ PAN-268815 (PAN-OS 10.2.13-h4 only) +
+
+ This issue is now resolved. See PAN-OS 10.2.13-h5 Addressed Issues. +
+
+
+ When using IoT Security, the + wifclient might exit multiple + times causing the firewall to reboot. +
+
+ Workaround: Uninstall the IoT Security license and + disable + Enable enhanced application logging + (DeviceManagementCloud LoggingCloud Logging Settings). +
+
PAN-266900 +
+ In Panorama, the OK button does not + work when trying to install configurations to a managed firewall from + the + Managed DevicesSummaryInstall + section, even after selecting the update type and file from the + drop-down menu and choosing the firewall. +
+
+
PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues. +
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues +
+
+
+ The command + show auth radius-require-msg-authentic + might return no output. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset. +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.14.html b/reference/PAN-OS/known/10.2.14.html new file mode 100644 index 0000000..694ffc5 --- /dev/null +++ b/reference/PAN-OS/known/10.2.14.html @@ -0,0 +1,1785 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-292344
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the + firewall reboots repeatedly and enters maintenance mode. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289102
+
+ This issue is now resolved. See + PAN-OS 10.2.16 Addressed Issues +
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, + PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and + CN-Series firewalls only) A race condition issue leads to a dataplane restart when a predict + session is hit at the moment when it's timing out. +
+
+
PAN-288930
+
+ This issue is now resolved. See + PAN-OS 10.2.15 Addressed Issues. +
+
+
+ When ACE (App-ID Cloud Engine) is enabled, traffic from cloud + applications might intermittently match an incorrect + cloud-apps policy rule. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286255
+
+ This issue is now resolved. See + PAN-OS 10.2.14-h1 Addressed Issues. +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions , NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285941
+
(PAN-OS 10.2.13-h7 only)
+
+
+ When netflow is enabled, the + logrcvr process might get stuck, + resulting in the local logging and log forwarding to stop functioning. + Running + debug log-receiver queue-stats on the + CLI will show the + "Logs discarded (queue full)" field + incrementing over time. +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-284066
+
+
+ After an upgrade, the + IF-MIB::ifInErrors SNMP polled + values display errors that don't match the results from the + show interface CLI command. +
+
+
PAN-283331
+
+
+ Selective pushes to managed devices fail when the + User ID Master Device is configured. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-279901
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
PAN-266900 +
+ In Panorama, the OK button does not + work when trying to install configurations to a managed firewall from + the + Managed DevicesSummaryInstall + section, even after selecting the update type and file from the + drop-down menu and choosing the firewall. +
+
+
PAN-261429
+
+ This issue is now resolved. See PAN-OS 10.2.15 Addressed Issues +
+
+
+ The command + show auth radius-require-msg-authentic + might return no output. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-259769
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset. +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.15.html b/reference/PAN-OS/known/10.2.15.html new file mode 100644 index 0000000..42cbf3d --- /dev/null +++ b/reference/PAN-OS/known/10.2.15.html @@ -0,0 +1,1715 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-292344
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the + firewall reboots repeatedly and enters maintenance mode. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289102
+
+ This issue is now resolved. See + PAN-OS 10.2.16 Addressed Issues +
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, + PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and + CN-Series firewalls only) A race condition issue leads to a dataplane restart when a predict + session is hit at the moment when it's timing out. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285941
+
(PAN-OS 10.2.13-h7 only)
+
+ This issue is now resolved. See + PAN-OS 10.2.16 Addressed Issues +
+
+
+ When netflow is enabled, the + logrcvr process might get stuck, + resulting in the local logging and log forwarding to stop functioning. + Running + debug log-receiver queue-stats on the + CLI will show the + "Logs discarded (queue full)" field + incrementing over time. +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-284066
+
+ This issue is now resolved. See + PAN-OS 10.2.16 Addressed Issues +
+
+
+ After an upgrade, the + IF-MIB::ifInErrors SNMP polled + values display errors that don't match the results from the + show interface CLI command. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-279901
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
PAN-266900 +
+ In Panorama, the OK button does not + work when trying to install configurations to a managed firewall from + the + Managed DevicesSummaryInstall + section, even after selecting the update type and file from the + drop-down menu and choosing the firewall. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-259769
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset. +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.16.html b/reference/PAN-OS/known/10.2.16.html new file mode 100644 index 0000000..b3f28d3 --- /dev/null +++ b/reference/PAN-OS/known/10.2.16.html @@ -0,0 +1,1283 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as + unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-297775
+
+
+ The wrong vsys is referenced under Visible Virtual System after every + local firewall commit (auto-commit, commit, content install) if the + display name of the vsys matches another vsys ID (for example, the + vsys2 display name is vsys1). The incorrect vsys reference causes + inter-vsys routing to fail. +
+
+ Workaround: Change the vsys display name so that + it doesn't reference an existing vsys ID. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-293673
+
+ This issue is now resolved. See PAN-OS 10.2.16-h4 Addressed Issues +
+
+
+ When the firewall generates a high volume of logs and attempts to + export these logs to an FTP server, it may consume excessive memory + leading to all PAN-OS processes crashing. +
+
+
PAN-292344
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the + firewall reboots repeatedly and enters maintenance mode. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See + PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-279901
+
+ (PAN-OS 10.2.16 and PAN-OS 10.2.16-h1) +
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.17.html b/reference/PAN-OS/known/10.2.17.html new file mode 100644 index 0000000..2bd6ab0 --- /dev/null +++ b/reference/PAN-OS/known/10.2.17.html @@ -0,0 +1,1405 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-317466
+
+
+ SIP sessions over TCP stop progressing when the firewall receives SIP + packets that are fragmented at a header field boundary. The firewall + fails to correctly handle the fragmented SIP header, causing the + session to stall and the SIP endpoint (phone) to reset the session, + resulting in dropped calls or failed call setup. +
+
+ Workaround: Configure an App Override policy to + bypass application inspection for all SIP traffic destined to the call + manager. Clear existing SIP sessions after applying the policy. This + prevents the firewall from reassembling fragmented SIP packets and + eliminates the stalled session behavior. +
+
+
PAN-308990
+
+
+ On firewalls where the management interface and a dataplane interface + are in the same broadcast domain, ARP replies for IP addresses + configured on the dataplane interfaces are incorrectly sent using the + management interface's MAC address. This causes + Received conflicting ARP messages to appear + continuously in the system logs. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as + unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
PAN-266900 +
+ In Panorama, the OK button does not + work when trying to install configurations to a managed firewall from + the + Managed DevicesSummaryInstall + section, even after selecting the update type and file from the + drop-down menu and choosing the firewall. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-259769
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset. +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.18.html b/reference/PAN-OS/known/10.2.18.html new file mode 100644 index 0000000..7067273 --- /dev/null +++ b/reference/PAN-OS/known/10.2.18.html @@ -0,0 +1,1377 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-317466
+
+
+ SIP sessions over TCP stop progressing when the firewall receives SIP + packets that are fragmented at a header field boundary. The firewall + fails to correctly handle the fragmented SIP header, causing the + session to stall and the SIP endpoint (phone) to reset the session, + resulting in dropped calls or failed call setup. +
+
+ Workaround: Configure an App Override policy to + bypass application inspection for all SIP traffic destined to the call + manager. Clear existing SIP sessions after applying the policy. This + prevents the firewall from reassembling fragmented SIP packets and + eliminates the stalled session behavior. +
+
+
PAN-308990
+
+
+ On firewalls where the management interface and a dataplane interface + are in the same broadcast domain, ARP replies for IP addresses + configured on the dataplane interfaces are incorrectly sent using the + management interface's MAC address. This causes + Received conflicting ARP messages to appear + continuously in the system logs. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as + unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
PAN-297295 +
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-287803
+
+
+ Users might be unable to access some URLs due to issues involving the + accumulation proxy and the Path Maximum Transmission Unit (MTU). +
+
+ To address this issue, use one of the following workarounds: +
+
    +
  • +
    + Configure the + Adjust TCP MSS option for the + egress interface to the unreachable server. The amount to adjust + the maximum segment size depends on the path to the server. +
    +
  • +
  • +
    + Disable the accumulation proxy using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
    +
  • +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
PAN-266900 +
+ In Panorama, the OK button does not + work when trying to install configurations to a managed firewall from + the + Managed DevicesSummaryInstall + section, even after selecting the update type and file from the + drop-down menu and choosing the firewall. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-259769
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset. +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
diff --git a/reference/PAN-OS/known/10.2.2.html b/reference/PAN-OS/known/10.2.2.html new file mode 100644 index 0000000..304486e --- /dev/null +++ b/reference/PAN-OS/known/10.2.2.html @@ -0,0 +1,3127 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223488
+
+ This issue is now resolved. See + PAN-OS 10.2.7 Addressed Issues. +
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series + and virtual appliance. This causes the ElasticSearch shard purging to + not work as expected, resulting in high disk usage. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests + for /config fail with the + following error due to exceeding the + total configuration size + supported on the M-600 appliance. +
+ +
+
504 Gateway timeout
+
+
+
PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-210366
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues. +
+
+
+ On the Panorama management server in a high availability (HA) + configuration, the primary HA peer may enter a + primary-non-functional state and + generate a system log (MonitorLogsSystem) with the following message: +
+
+ High root partition usage: going to state Non-Functional +
+
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ The following NextGen firewalls and Panorama management server models + are unable to automatically renew the device certificate (DeviceSetupManagement + or + PanoramaSetupManagement). +
+
    +
  • M-300 and M-700
  • +
  • PA-410 Firewall
  • +
  • +
    PA-440, PA-450, and PA-460 Firewalls
    +
  • +
  • PA-3400 Series
  • +
  • +
    PA-5410, PA-5420, and PA-5430 Firewalls
    +
  • +
  • PA-5450 Firewall
  • +
+
+ Workaround: Log in to the + firewall CLI + or + Panorama CLI + and fetch the device certificate. +
+ +
+
admin>request certificate fetch
+
+
+
PAN-207629
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, selective push fails to managed + firewalls if the managed firewalls are enabled with multiple vsys and + the Push Scope contains shared objects in device groups. +
+
+
PAN-206268
+
+
+ On the Panorama management server, the Auth Key field was erroneously + displayed when you configure the Panorama Settings (DeviceSetupManagement) as part of a template or template stack configuration. +
+
+
PAN-206253
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ For PA-3400 Series firewalls, the default log rate is set too low and + the max configurable log rate is incorrectly capped resulting in the + firewall not generating more than 6,826 logs per second. +
+
+
PAN-206243
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ The PA-220 firewall reaches the maximum disk usage capacity multiple a + day that requires a disk cleanup. A critical system log (MonitorLogsSystem) is generated each time the firewall reaches maximum disk usage + capacity. +
+
+
PAN-205187
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ ElasticSearch may not start properly when a newly installed Panorama + virtual appliance powers on for the first time, resulting in the + Panorama virtual appliance being unable to query logs forwarded from + the managed firewall to a Log Collector. +
+
+ Workaround: + Log in to the Panorama CLI + and start the PAN-OS software. +
+ +
+
admin>request restart software
+
+
+
PAN-204663
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, you are unable to Context Switch + from one managed firewall to another. +
+
+ Workaround: After you Context Switch to a managed + firewall, you must first Context Switch back to Panorama before you + can continue to Context Switch to a different managed firewall. +
+
+
PAN-201855
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the Panorama management server, cloning any template (PanoramaTemplates) corrupts certificates (DeviceCertificate ManagementCertificates) with the + Block Private Key Export setting + enabled across all templates. This results in managed firewalls + experiencing issues wherever the corrupted certificate is referenced. +
+
+ For example, you have template A, B, and C where templates A and B + have certificates with the + Block Private Key Export setting + enabled. Cloning template C corrupts the certificates with + Block Private Key Export setting + enabled in templates A and B. +
+
+ Workaround: After cloning a template, delete and + re-import the corrupted certificates. +
+
+
PAN-200019
+
+ PAN-OS 10.2.2-h1 and later releases. +
+
+
+ On the Panorama management server, the Virtual Routers (NetworkVirtual Routers) setting is not available when configuring a custom Panorama admin + role (PanoramaAdmin Roles). +
+
+
PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On M-600 appliances in an Active/Passive high availability (HA) + configuration, the + configd process restarts due to a + memory leak on the + Active Panorama HA peer. This + causes the Panorama web interface and CLI to become unresponsive. +
+
+ Workaround: Manually reboot the + Active Panorama HA peer. +
+
+
PAN-199099
+
+
+ When decryption is enabled, Safari and Google Chrome browsers on Mac + computers running macOS Monterey or later reject the server + certificates firewalls present. The browsers cannot validate the chain + of trust for the certificates because the Authority Key Identifier + (AKID) of the server certificates and the Subject Key Identifier + (SKID) of the forward trust certificate do not match. +
+
+ Workaround: Use a forward trust certificate that + does not contain AKID or SKID extensions. +
+
+
PAN-198174
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ When viewing traffic or threat logs from the firewall ACC or Monitor, + performing a reverse DNS lookup, for example, when resolving IP + addresses to domain names using the + Resolve Hostname feature, can cause + the appliance to crash and restart if DNS server settings have not + been configured. +
+
+ Workaround: Provide a DNS server setting for the + firewall (DeviceDNS SetupServices). If you cannot reference a valid DNS server, you can add a dummy + address. +
+
+
PAN-197097
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196784
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ Palo Alto Networks® Next-Gen firewalls experience a logs per second + (LPS) degradation after upgrade to PAN-OS 10.2.2. +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-195541
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ When a DNS request is submitted to the DNS Security service for + inspection, the dataplane pan-task process (all_pktproc) might fail + during the DNS request process, or when the dataplane cache is reset, + or if the cache output is generated through the CLI, resulting in + firewall crashes or the inability/reduced capability to process + network traffic. +
+
+ The following CLI commands can trigger a crash of the all_pktproc + process: +
+
    +
  • + +
    +
    debug dataplane reset dns-cache all
    +
    +
  • +
  • + +
    +
    debug dataplane show dns-cache print
    +
    +
  • +
  • + +
    +
    show dns-proxy dns-signature cache
    +
    +
  • +
  • + +
    +
    clear dns-proxy dns-signature cache
    +
    +
  • +
+
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194925
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, when making changes in the Service Connection + and Remote Networks area, the configuration changes do not display in + the Push Scope during a commit. +
+
+ Workaround: For service connection changes, make + sure that Service Setup is selected in the Push Scope before you + commit. For remote network changes, make sure that Remote Networks is + selected in the Push Scope before you commit. +
+
+
PAN-194859
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, after migrating from a single tenant to a + multi-tenant Prisma Access deployment and making configuration + changes, the Cloud Services plugin shows + No pending changes to commit when + you hover over the Commit tab, even though there are pending changes + to commit. +
+
+ Workaround: The status shown when hovering over + the Commit tab is a cosmetic issue. Commit the pending changes, if + required. +
+
+
PAN-194826
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ (WF-500 and WF-500-B appliance only) System log + forwarding does not work over a TLS connection. +
+
+
PAN-194708
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ URL filtering logs (MonitorLogsURL Filtering) erroneously truncate a 16KB Header value and do not display the + Header values that follow the truncated 16KB header. +
+
+ For example, a URL filtering log has 5 Headers. The second Header has + a 16KB value. In the URL filtering log, the first header and the value + are displayed, second Header value is truncated, and remaining three + headers are not displayed. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-193251
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ If SAML is configured as the authentication method for GlobalProtect, + authentication on the Portal page is not successful in the browser. +
+
+ Workaround: Use the GlobalProtect app installed on + the endpoint to authenticate. +
+
+
PAN-190735
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ Certain webpages that use chunked-encoded data transfers might not + load properly when analyzed by Advanced URL Filtering cloud inline + categorization. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-190435
+
+
+ When you Commit a configuration + change, the Task Manager commit + Status goes directly from + 0% to + Completed and does accurately + reflect the commit job progress. +
+
+
PAN-189425
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, + Export Panorama and devices config bundle + (PanoramaSetupOperations) fails to export. When the export fails, you are redirected to a new + window and the following error is displayed: +
+
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log + (Permission denied) +
+
+
PAN-189380
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ After you successfully upgrade a PA-3000 Series firewall to PAN-OS + 10.2.0 or later release and Enterprise data loss prevention (DLP) + plugin 3.0.0 or later release, the first configuration push from the + Panorama management server causes the firewall dataplane to crash. +
+
+ Workaround: Restart the firewall to restore + dataplane functionality. +
+
    +
  1. + Log in to the firewall CLI. +
  2. +
  3. +
    + Restart the firewall. +
    +
    admin> request restart system
    +
    +
    +
  4. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188904
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Certain web pages and web page contents might not properly load when + cloud inline categorization is enabled on the firewall. +
+
+
PAN-188489
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ On the Panorama management server, dynamic content updates are not + automatically pushed to VM-Series firewalls licensed using the + Panorama Software Firewall License plugin when + Automatically push content when software device registers to + Panorama + (PanoramaTemplatesAdd Stack) is enabled. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-188064
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ The SCP Server Profile configuration (DevicesServer ProfilesSCP + are not automatically deleted after downgrade from PAN-OS 10.2.0 to + PAN-OS 10.1 or earlier release. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-187234
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ Certain web pages submitted for analysis by Advanced URL Filtering + cloud inline categorization might experience high latency. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-186134
+
+
+ On the Panorama management server, performing a + Commit and Push (Commit > Commit and Push) may intermittently not push the committed configuration changes to + managed firewalls. +
+
+ Workaround: Select + Commit > Push to Devices to push + the committed configuration changes to your managed firewalls. +
+
+
PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ (PA-5400 Series firewalls only) On the Panorama + management server, the device health resources (PanoramaManaged DevicesHealth) do not populate. +
+
+
PAN-184708
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184702
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ On the Panorama management server, an M-700 appliance in Log Collector + mode fails to connect to Panorama when added as a managed collector + (Panorama > Managed Collectors). +
+ +
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-182734
+
+ This issue is now resolved. See + PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel + configuration, BGP flaps. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+ This issue is now resolved. See PAN-OS 10.2.3 Addressed Issues. +
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-172132
+
+ This issue is now resolved by PAN-189643. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ QoS fails to run on a tunnel interface (for example, tunnel.1). +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/10.2.3.html b/reference/PAN-OS/known/10.2.3.html new file mode 100644 index 0000000..021a5c2 --- /dev/null +++ b/reference/PAN-OS/known/10.2.3.html @@ -0,0 +1,2731 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223488
+
+ This issue is now resolved. See + PAN-OS 10.2.7 Addressed Issues. +
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series + and virtual appliance. This causes the ElasticSearch shard purging to + not work as expected, resulting in high disk usage. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests + for /config fail with the + following error due to exceeding the + total configuration size + supported on the M-600 appliance. +
+ +
+
504 Gateway timeout
+
+
+
PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212978
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues. +
+
+
+ The Palo Alto Networks firewall stops responding when executing an + SD-WAN debug operational CLI command. +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-210366
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues. +
+
+
+ On the Panorama management server in a high availability (HA) + configuration, the primary HA peer may enter a + primary-non-functional state and + generate a system log (MonitorLogsSystem) with the following message: +
+
+ High root partition usage: going to state Non-Functional +
+
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ The following NextGen firewalls and Panorama management server models + are unable to automatically renew the device certificate (DeviceSetupManagement + or + PanoramaSetupManagement). +
+
    +
  • M-300 and M-700
  • +
  • PA-410 Firewall
  • +
  • +
    PA-440, PA-450, and PA-460 Firewalls
    +
  • +
  • PA-3400 Series
  • +
  • +
    PA-5410, PA-5420, and PA-5430 Firewalls
    +
  • +
  • PA-5450 Firewall
  • +
+
+ Workaround: Log in to the + firewall CLI + or + Panorama CLI + and fetch the device certificate. +
+ +
+
admin>request certificate fetch
+
+
+
PAN-208189
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Traffic fails to match and reach all destinations if a Security policy + rule includes FQDN objects that resolve to two or more IP addresses. +
+
+
PAN-207629
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, selective push fails to managed + firewalls if the managed firewalls are enabled with multiple vsys and + the Push Scope contains shared objects in device groups. +
+
+
PAN-206253
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ For PA-3400 Series firewalls, the default log rate is set too low and + the max configurable log rate is incorrectly capped resulting in the + firewall not generating more than 6,826 logs per second. +
+
+
PAN-206243
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ The PA-220 firewall reaches the maximum disk usage capacity multiple a + day that requires a disk cleanup. A critical system log (MonitorLogsSystem) is generated each time the firewall reaches maximum disk usage + capacity. +
+
+
PAN-206005
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ (PA-3400 Series firewalls only) The I7_misc + memory pool on this platform is undersized and can cause a loss of + connectivity when reaching the limit of the memory pool. Certain + features, like using a decryption profile with Strip ALPN disabled, + can lead to depleting the memory pool and causing a connection loss. +
+
+ Workaround: Disable HTTP2 by enabling Strip ALPN + in the decryption profile or avoid usage of the I7_misc memory pool. +
+
+
PAN-205187
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ ElasticSearch may not start properly when a newly installed Panorama + virtual appliance powers on for the first time, resulting in the + Panorama virtual appliance being unable to query logs forwarded from + the managed firewall to a Log Collector. +
+
+ Workaround: + Log in to the Panorama CLI + and start the PAN-OS software. +
+ +
+
admin>request restart software
+
+
+
PAN-204663
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, you are unable to Context Switch + from one managed firewall to another. +
+
+ Workaround: After you Context Switch to a managed + firewall, you must first Context Switch back to Panorama before you + can continue to Context Switch to a different managed firewall. +
+
+
PAN-201855
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the Panorama management server, cloning any template (PanoramaTemplates) corrupts certificates (DeviceCertificate ManagementCertificates) with the + Block Private Key Export setting + enabled across all templates. This results in managed firewalls + experiencing issues wherever the corrupted certificate is referenced. +
+
+ For example, you have template A, B, and C where templates A and B + have certificates with the + Block Private Key Export setting + enabled. Cloning template C corrupts the certificates with + Block Private Key Export setting + enabled in templates A and B. +
+
+ Workaround: After cloning a template, delete and + re-import the corrupted certificates. +
+
+
PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On M-600 appliances in an Active/Passive high availability (HA) + configuration, the + configd process restarts due to a + memory leak on the + Active Panorama HA peer. This + causes the Panorama web interface and CLI to become unresponsive. +
+
+ Workaround: Manually reboot the + Active Panorama HA peer. +
+
+
PAN-198708
+
+
+ On the Panorama management server, the + File Type field does not display + any data when you view the Detailed Log View in the Data Filtering log + (MonitorLogsData Filtering<select log>DLP). +
+
+
PAN-198174
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ When viewing traffic or threat logs from the firewall ACC or Monitor, + performing a reverse DNS lookup, for example, when resolving IP + addresses to domain names using the + Resolve Hostname feature, can cause + the appliance to crash and restart if DNS server settings have not + been configured. +
+
+ Workaround: Provide a DNS server setting for the + firewall (DeviceDNS SetupServices). If you cannot reference a valid DNS server, you can add a dummy + address. +
+
+
PAN-197097
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-195541
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ When a DNS request is submitted to the DNS Security service for + inspection, the dataplane pan-task process (all_pktproc) might fail + during the DNS request process, or when the dataplane cache is reset, + or if the cache output is generated through the CLI, resulting in + firewall crashes or the inability/reduced capability to process + network traffic. +
+
+ The following CLI commands can trigger a crash of the all_pktproc + process: +
+
    +
  • + +
    +
    debug dataplane reset dns-cache all
    +
    +
  • +
  • + +
    +
    debug dataplane show dns-cache print
    +
    +
  • +
  • + +
    +
    show dns-proxy dns-signature cache
    +
    +
  • +
  • + +
    +
    clear dns-proxy dns-signature cache
    +
    +
  • +
+
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-190435
+
+
+ When you Commit a configuration + change, the Task Manager commit + Status goes directly from + 0% to + Completed and does accurately + reflect the commit job progress. +
+
+
PAN-189425
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ On the Panorama management server, + Export Panorama and devices config bundle + (PanoramaSetupOperations) fails to export. When the export fails, you are redirected to a new + window and the following error is displayed: +
+
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log + (Permission denied) +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188904
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Certain web pages and web page contents might not properly load when + cloud inline categorization is enabled on the firewall. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-186134
+
+
+ On the Panorama management server, performing a + Commit and Push (Commit > Commit and Push) may intermittently not push the committed configuration changes to + managed firewalls. +
+
+ Workaround: Select + Commit > Push to Devices to push + the committed configuration changes to your managed firewalls. +
+
+
PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ (PA-5400 Series firewalls only) On the Panorama + management server, the device health resources (PanoramaManaged DevicesHealth) do not populate. +
+
+
PAN-184708
+
+ This issue is now resolved. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-182734
+
+ This issue is now resolved. See + PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel + configuration, BGP flaps. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-172132
+
+ This issue is now resolved by PAN-189643. See PAN-OS 10.2.4 Addressed Issues. +
+
+
+ QoS fails to run on a tunnel interface (for example, tunnel.1). +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/10.2.4.html b/reference/PAN-OS/known/10.2.4.html new file mode 100644 index 0000000..dfec35c --- /dev/null +++ b/reference/PAN-OS/known/10.2.4.html @@ -0,0 +1,2366 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-227342
+
+
+ (PA-7000 Series firewalls only) In an + Active/Active High Availability (HA) setup, enabling hardware offload + can result in web traffic being blocked. +
+
+
PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223488
+
+ This issue is now resolved. See + PAN-OS 10.2.7 Addressed Issues. +
+
+ Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. +
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-220180
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-216821
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ The reportd process crashes after + you successfully upgrade an M-200 appliance to PAN-OS 10.2.4. +
+
+
PAN-215778
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests + for /config fail with the + following error due to exceeding the + total configuration size + supported on the M-600 appliance. +
+ +
+
504 Gateway timeout
+
+
+
PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212978
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues. +
+
+
+ The Palo Alto Networks firewall stops responding when executing an + SD-WAN debug operational CLI command. +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-210366
+
+ This issue is now resolved. See PAN-OS 10.2.4-h3 Addressed Issues +
+
+
+ On the Panorama management server in a high availability (HA) + configuration, the primary HA peer may enter a + primary-non-functional state and + generate a system log (MonitorLogsSystem) with the following message: +
+
+ High root partition usage: going to state Non-Functional +
+
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-208325
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ The following NextGen firewalls and Panorama management server models + are unable to automatically renew the device certificate (DeviceSetupManagement + or + PanoramaSetupManagement). +
+
    +
  • M-300 and M-700
  • +
  • PA-410 Firewall
  • +
  • +
    PA-440, PA-450, and PA-460 Firewalls
    +
  • +
  • PA-3400 Series
  • +
  • +
    PA-5410, PA-5420, and PA-5430 Firewalls
    +
  • +
  • PA-5450 Firewall
  • +
+
+ Workaround: Log in to the + firewall CLI + or + Panorama CLI + and fetch the device certificate. +
+ +
+
admin>request certificate fetch
+
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-201855
+
+
+ On the Panorama management server, cloning any template (PanoramaTemplates) corrupts certificates (DeviceCertificate ManagementCertificates) with the + Block Private Key Export setting + enabled across all templates. This results in managed firewalls + experiencing issues wherever the corrupted certificate is referenced. +
+
+ For example, you have template A, B, and C where templates A and B + have certificates with the + Block Private Key Export setting + enabled. Cloning template C corrupts the certificates with + Block Private Key Export setting + enabled in templates A and B. +
+
+ Workaround: After cloning a template, delete and + re-import the corrupted certificates. +
+
+
PAN-199557
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On M-600 appliances in an Active/Passive high availability (HA) + configuration, the + configd process restarts due to a + memory leak on the + Active Panorama HA peer. This + causes the Panorama web interface and CLI to become unresponsive. +
+
+ Workaround: Manually reboot the + Active Panorama HA peer. +
+
+
PAN-198708
+
+
+ On the Panorama management server, the + File Type field does not display + any data when you view the Detailed Log View in the Data Filtering log + (MonitorLogsData Filtering<select log>DLP). +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-190435
+
+
+ When you Commit a configuration + change, the Task Manager commit + Status goes directly from + 0% to + Completed and does accurately + reflect the commit job progress. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ (PA-5400 Series firewalls only) On the Panorama + management server, the device health resources (PanoramaManaged DevicesHealth) do not populate. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-182734
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel + configuration, BGP flaps. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
+
PAN-160633
+
+ This issue is now resolved. See PAN-OS 10.2.5 Addressed Issues. +
+
+
+ (PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls + only) The dataplane restarts repeatedly due to internal path monitoring + failures until a power cycle. +
+
diff --git a/reference/PAN-OS/known/10.2.5.html b/reference/PAN-OS/known/10.2.5.html new file mode 100644 index 0000000..1e8ccc0 --- /dev/null +++ b/reference/PAN-OS/known/10.2.5.html @@ -0,0 +1,2334 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-227368
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The GlobalProtect app cannot connect to a portal or gateway and + GlobalProtect Clientless VPN users cannot access applications if + authentication takes longer than 20 seconds. +
+
+ Workaround: Increase the TCP handshake timeout to + the maximum value of 60 seconds. +
+
+
PAN-229865
+
+ This issue is now resolved. See PAN-OS 10.2.6 Addressed Issues. +
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-226768
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ When the GlobalProtect app is installed on iOS endpoints and the + gateway is configured to accept cookies, the app stays in + Connecting stage after + authentication and the GlobalProtect log displays the error message, + User is not in allow list. This + happens when the app is restarted or when the app tries to reconnect + after disconnection. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-223488
+
+ This issue is now resolved. See + PAN-OS 10.2.7 Addressed Issues. +
+
+ Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. +
+
PAN-223457
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ If the number of group queries exceeds the Okta rate limit threshold, + the firewall clears the cache for the groups. To avoid encountering + this issue, disable the Okta rate limit. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222418
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The firewall intermittently records a reconnection message to the + authentication server as a error, even if no disconnection occurs. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-221857
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Users are unable to log in to the GlobalProtect app using SAML + authentication after the app is upgraded to 10.2.3-h4 and the + GlobalProtect logs display the following error message: + Username from SAML SSO response is different from the input.. +
+
+
PAN-221126
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ Email server profiles (DeviceServer ProfilesEmail + and + PanoramaServer ProfilesEmail) to forward logs as email notifications are not forwarded in a + readable format. +
+
+ Workaround: Use a + Custom Log Format to forward logs as + email notifications in a readable format. +
+
+
PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-220180
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-216214
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability + (HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA firewalls triggers an + HA config sync on the peer firewall. This causes the HA peer + configuration to go Out of Sync. +
+
+
PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-198708
+
+
+ On the Panorama management server, the + File Type field does not display + any data when you view the Detailed Log View in the Data Filtering log + (MonitorLogsData Filtering<select log>DLP). +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-193004
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The Panorama management server fails to delete old IP Tag data. This + causes the /opt/pancfg partition + to reach maximum capacity which impacts Panorama performance. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ (PA-5400 Series firewalls only) On the Panorama + management server, the device health resources (PanoramaManaged DevicesHealth) do not populate. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/10.2.6.html b/reference/PAN-OS/known/10.2.6.html new file mode 100644 index 0000000..cd90569 --- /dev/null +++ b/reference/PAN-OS/known/10.2.6.html @@ -0,0 +1,2362 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-244648
+
+
+ (PA-5200 Series firewalls only) After a factory + reset, the firewall may get stuck in maintenance mode and be unable to + load the boot image. The firewall fails to enable FIPS-CC mode during + this time. +
+
+ Workaround: The following workaround allows the + firewall to boot in normal mode but does not apply to FIPS-CC mode. + Attempting to enable FIPS-CC mode after using this workaround will + cause the firewall to reboot and re-enter maintenace mode. +
+
    +
  1. Enter maintenance mode.
  2. +
  3. + Select + Disk ImageAdvanced Options. +
  4. +
  5. + Select Bootstrap with the options + panos-10.2.8, + maint, and + maint. +
  6. +
  7. + Select Bootstrap with the options + panos-10.2.8, + sysroot0, and + panos. +
  8. +
  9. + Select Bootstrap with the option + sysroot0. +
  10. +
  11. Select Reboot.
  12. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-234929
+
+ This issue is now resolved. See PAN-OS 10.2.7-h3 Addressed Issues. +
+
+
+ The tabs in the ACC, such as + Network Activity, + Threat Activity, and + Blocked Activity, may not display + any data when you apply a Time filter for the Last 15 minutes, Last + Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter, + the data displayed may not be accurate. Additionally, reports run + against summary logs may not display accurate results. +
+
+
PAN-228515
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log + Collector mode. This causes logs to not display on the Panorama + management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. +
+
+
PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225337
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-227368
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The GlobalProtect app cannot connect to a portal or gateway and + GlobalProtect Clientless VPN users cannot access applications if + authentication takes longer than 20 seconds. +
+
+ Workaround: Increase the TCP handshake timeout to + the maximum value of 60 seconds. +
+
+
PAN-226768
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ When the GlobalProtect app is installed on iOS endpoints and the + gateway is configured to accept cookies, the app stays in + Connecting stage after + authentication and the GlobalProtect log displays the error message, + User is not in allow list. This + happens when the app is restarted or when the app tries to reconnect + after disconnection. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-223488
+
+ This issue is now resolved. See + PAN-OS 10.2.7 Addressed Issues. +
+
+ Closed ElasticSearch shards are not deleted from a Panorama M-Series or + virtual appliance. This causes the ElasticSearch shard purging to not + work as expected, resulting in high disk usage. +
+
PAN-223457
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ If the number of group queries exceeds the Okta rate limit threshold, + the firewall clears the cache for the groups. To avoid encountering + this issue, disable the Okta rate limit. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222418
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The firewall intermittently records a reconnection message to the + authentication server as a error, even if no disconnection occurs. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-221857
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Users are unable to log in to the GlobalProtect app using SAML + authentication after the app is upgraded to 10.2.3-h4 and the + GlobalProtect logs display the following error message: + Username from SAML SSO response is different from the input.. +
+
+
PAN-221126
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ Email server profiles (DeviceServer ProfilesEmail + and + PanoramaServer ProfilesEmail) to forward logs as email notifications are not forwarded in a + readable format. +
+
+ Workaround: Use a + Custom Log Format to forward logs as + email notifications in a readable format. +
+
+
PAN-221015
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-220180
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-193004
+
+ This issue is now resolved. See PAN-OS 10.2.7 Addressed Issues. +
+
+
+ The Panorama management server fails to delete old IP Tag data. This + causes the /opt/pancfg partition + to reach maximum capacity which impacts Panorama performance. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ (PA-5400 Series firewalls only) On the Panorama + management server, the device health resources (PanoramaManaged DevicesHealth) do not populate. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/10.2.7.html b/reference/PAN-OS/known/10.2.7.html new file mode 100644 index 0000000..44f8d15 --- /dev/null +++ b/reference/PAN-OS/known/10.2.7.html @@ -0,0 +1,2207 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273730
+
+
+ (PA-7000 Series only) The web interface is + unresponsive after upgrading to PAN-OS 10.2.7-h18. The following error + is generated: + PHP Fatal error: require(): Failed opening required +
+
+ Workaround: Use the CLI to downgrade or upgrade to + another version. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-262263
+
+
+ (PA-3400 and PA-5400 Series firewalls) The + links on the firewall's RJ-45 ports may go up and down additional + times during a reboot, causing unexpected downtime. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-244673
+
+
+ Upgrading a flexible-vCPU VM-Series firewall HA deployment from 10.1.x + directly to 10.2.3 or later causes the active HA peer to become + unresponsive. In this scenario, the upgraded firewall then becomes the + active peer. +
+
+ Workaround: Upgrade the VM-Series firewalls to + PAN-OS 10.2.2 before upgrading to the latest PAN-OS 10.2.x version. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-242910
+
+ PAN-OS 10.2.7, 10.2.7-h1, and 10.2.7-h3 only +
+
+
+ On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled are + unable to push configuration changes to managed firewalls when + Managed Devices and + Push For Other Admins are disabled. +
+
+
PAN-242837
+
+
+ Default login credentials and SSH fail after enabling FIPS-CC Mode on + a firewall or Panorama after converting through the Maintenance + Recovery Tool (MRT). The firewall or Panorama becomes stuck and + requires a factory reset to recover. +
+
+
PAN-242561
+
+
+ On the PAN-OS 10.2.7-h3 version, GlobalProtect tunnel might disconnect + shortly after being established when SSL is used as a transport + protocol. +
+
+ Workaround: Disable Internet Protocol version 6 + (TCP/IPv6) on the PANGP Virtual Network Adapter. +
+
+
PAN-238769
+
+
+ FIPS-CC VM only. Upgrading to 10.1.10-h2 or 10.1.11 will change all + locally created security Policy actions to Deny. Re-load the back-up + config taken before upgrading or the last version to get the previous + config back. Also, Unable to login to FIPSCC Mode devices with default + credentials after converting the mode for 10.1.12 release , 10.2.7 + release , 11.1.0 , 11.1.1, 11.0.3 versions. +
+
+
PAN-234929
+
+ This issue is now resolved. See PAN-OS 10.2.7-h3 Addressed Issues. +
+
+
+ The tabs in the ACC, such as + Network Activity, + Threat Activity, and + Blocked Activity, may not display + any data when you apply a Time filter for the Last 15 minutes, Last + Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter, + the data displayed may not be accurate. Additionally, reports run + against summary logs may not display accurate results. +
+
+
PAN-228515
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log + Collector mode. This causes logs to not display on the Panorama + management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. +
+
+
PAN-228273
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-226768
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ When the GlobalProtect app is installed on iOS endpoints and the + gateway is configured to accept cookies, the app stays in + Connecting stage after + authentication and the GlobalProtect log displays the error message, + User is not in allow list. This + happens when the app is restarted or when the app tries to reconnect + after disconnection. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-223457
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ If the number of group queries exceeds the Okta rate limit threshold, + the firewall clears the cache for the groups. To avoid encountering + this issue, disable the Okta rate limit. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222418
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The firewall intermittently records a reconnection message to the + authentication server as a error, even if no disconnection occurs. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-221857
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Users are unable to log in to the GlobalProtect app using SAML + authentication after the app is upgraded to 10.2.3-h4 and the + GlobalProtect logs display the following error message: + Username from SAML SSO response is different from the input.. +
+
+
PAN-221033
+
+ This issue is now resolved. See + PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The firewall is responding to an ARP request for an IP address in the + firewall's NAT address pool when that IP address isn't in the same + subnet as the IP address of the ingress interface. +
+
+
PAN-220180
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-215082
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-185286
+
+ This issue is now resolved. See PAN-OS 10.2.8 Addressed Issues. +
+
+
+ (PA-5400 Series firewalls only) On the Panorama + management server, the device health resources (PanoramaManaged DevicesHealth) do not populate. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/10.2.8.html b/reference/PAN-OS/known/10.2.8.html new file mode 100644 index 0000000..2c87576 --- /dev/null +++ b/reference/PAN-OS/known/10.2.8.html @@ -0,0 +1,1916 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+ This issue affects PAN-OS 10.2.8-h10 +
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues. +
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-255868
+
+
+ (PA-3400 Series firewalls only) After enabling + kernel data collection during a silent reboot, the firewall fails and + reboots to maintenance mode. +
+
+ Workaround: To recover the firewall, initiate a + reboot from maintenance mode. +
+
+
PAN-251895
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ When Inline Cloud Analysis features are enabled, the firewall + experiences a slow packet buffer leak, resulting in poor performance + and dropped traffic. +
+
+ Workaround: Disable WildFire Inline Cloud Analysis + and Advanced Threat Prevention Inline Cloud Analysis on the firewall. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-242910
+
+
+ On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled are + unable to push configuration changes to managed firewalls when + Managed Devices and + Push For Other Admins are disabled. +
+
+
PAN-242627
+
+ On the Panorama management server, selective configuration pushes fail + with the following error message even when a full configuration push + from Panorama was previously performed:Failed to generate selective push + configuration. Schema validation failed. Please try a full push +
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-228515
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log + Collector mode. This causes logs to not display on the Panorama + management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. +
+
+
PAN-226361
+
+ This issue is now resolved. See PAN-OS 10.2.8-h13 Addressed Issues. +
+
+
+ Sessions might end unexpectedly with the error + resources-unavailable when the + firewall incorrectly interprets the Content and Threat Detection (CTD) + global packet queue as being full. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/10.2.9.html b/reference/PAN-OS/known/10.2.9.html new file mode 100644 index 0000000..8e6db0e --- /dev/null +++ b/reference/PAN-OS/known/10.2.9.html @@ -0,0 +1,1789 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5854
+
+
+ The WildFire analysis report on the firewall log viewer (MonitoringWildFire Submissions) does not display the following data fields: File Type, SHA-256, + MD-5, and File Size". +
+
+ Workaround: Download and open the WildFire + analysis report in the PDF format using the link in the upper + right-hand corner of the + Detailed Log View. +
+
+
WF500-5843
+
+
+ In a WildFire appliance cluster, issuing the + show cluster-all peers CLI command + when a node within the cluster is being rebooted generates the + following error: + Server error : An error occured. +
+
+
WF500-5840
+
+
+ The sample analysis statistics that are returned when issuing the + show wildfire local statistics CLI + command in WildFire appliance cluster deployments may not accurately + reflect the number of samples that have been processed. +
+
+
WF500-5823
+
+
+ The following WildFire appliance CLI command does not return a + signature generation status as expected: + show wildfire global signature-status. This does not corrupt or otherwise prevent the WildFire appliance + from analyzing a sample. +
+
+
WF500-5781
+
+
+ The WildFire appliance might erroneously generate and log the + following device certification error: + Device certificate is missing or invalid. It cannot be + renewed. +
+
+
WF500-5754
+
+
+ In WildFire appliance clusters, issuing the + show cluster controller CLI command + generates an error when an IPv6 address is configured for the + management interface but not for the cluster interface. +
+
+ Workaround: Ensure all WildFire appliance + interfaces that are enabled use matching protocols (all IPv4 or all + IPv6). +
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-306555
+
+ This issue is now resolved. See PAN-OS 10.2.18-h8 Addressed Issues. +
+
+
+ A race condition may cause the dataplane to restart unexpectedly when + a zip decompression offload result is returned for a session that has + already closed. The session state is not validated before processing + the result because the offload result does not follow the fastpath + where these checks are normally performed. +
+
+ Workaround: Disable zip hardware offloading (may + cause higher CPU usage). +
+
+
PAN-304756
+ +
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push may + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-297610
+
+
+ A firewall may become unresponsive after an upgrade due to the + fsck command scanning drive + partitions in parallel with the root partition, causing the process to + take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) After upgrading to an affected release, the firewall restarts + continuously because the + brdagent + process restarts multiple times and exhausts its restart limit, + resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-295803
+
+
+ A configd memory leak occurs post + commit (during Panorama connectivity check), potentially leading to + OOM (out of memory condition) and device reboot. +
+
+
PAN-295255
+
+
+ Palo Alto Networks next-generation firewalls may experience service + disruptions due to all_task process + crashes when deployed in environments having non-uniform MTU and are + terminating IPSec tunnels. +
+
+
PAN-292344
+
+ This issue affects PAN-OS 10.2.9-h7 +
+
+
+ When upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.13-h5, the + firewall reboots repeatedly and enters maintenance mode. +
+
+
PAN-291716
+
+ This issue is now resolved. See PAN-OS 10.2.17 Addressed Issues. +
+
+
+ During a commit, the firewall experiences an out-of-memory (OOM) + condition due to a memory leak and displays an error message. This + issue causes the device to crash and reboot unexpectedly. +
+
+
PAN-291288
+
+ This issue is now resolved. See PAN-OS 10.2.16-h6 Addressed Issues +
+
+
+ A memory leak in the configd process + might lead to an active firewall to reboot due to an Out-of-Memory + (OOM) condition. This issue is observed when specific status commands, + such as + request log-collector forwarding status + are executed at high frequencies. +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 10.2.16-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290088
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-288097
+
+ This issue is now resolved. See PAN-OS 10.2.18 Addressed Issues +
+
+
+ (Firewalls in HA configurations only) Routed + process may stop responding after changing MTU or any link parameters + when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+ This issue affects PAN-OS 10.2.9-h9 +
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+ This issue is now resolved. See PAN-OS 10.2.13-h10 Addressed Issues +
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-284073
+
+
+ The firewall web interface becomes inaccessible and commits fail. +
+
+
PAN-284067
+
+
+ A cumulative memory leak in the + devsrvr + process gets progressively worse whenever the CLI command + show running application statistics + is issued. This memory leak will gradually consume system memory and + produce an out-of-memory (OOM) condition, leading to an eventual + firewall reboot. +
+
+ Workaround: Avoid using the CLI command: + show running application statistics. +
+
+
PAN-281370
+
+
+ The Advanced WildFire Inline ML models + OOXML and + Mach-O erroneously display as being + available from the CLI; however, they are only available on PAN-OS + 11.1.3 and later releases. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-262287
+
+ This issue is now resolved. See PAN-OS 10.2.13 Addressed Issues. +
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+ PAN-263226 (PAN-OS 10.2.9-h9 only) + +
+ When SSL decryption is enabled and Client Hello messages span multiple + TCP segments, elements from the proxy_l2info memory pool may not be + freed properly. Memory leaks in this pool cause some SSL decryption + sessions to fail. +
+
+ Workaround: Disable Client Hello accumulation + using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
PAN-259769 +
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-251895
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ When Inline Cloud Analysis features are enabled, the firewall + experiences a slow packet buffer leak, resulting in poor performance + and dropped traffic. +
+
+ Workaround: Disable WildFire Inline Cloud Analysis + and Advanced Threat Prevention Inline Cloud Analysis on the firewall. +
+
+
PAN-251639
+
+ This issue is now resolved. See. + PAN-OS 10.2.9-h9 Addressed Issues. +
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ An out of memory condition might occur due to a memory leak in the + varrcvr + process when a Wildfire Analysis security profile is enabled. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-223365
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-229865
+
+
+ Upgrading a PA-220 firewall running a PAN-OS 10.1 release fails when + the target PAN-OS upgrade version is PAN-OS 10.2.5. +
+
+ Workaround: On your upgrade path to PAN-OS 10.2.5, + first upgrade to PAN-OS 10.2.4 and then upgrade to PAN-OS 10.2.5. +
+
+
PAN-226361
+
+ This issue is now resolved. See PAN-OS 10.2.9-h14 Addressed Issues. +
+
+
+ Sessions might end unexpectedly with the error + resources-unavailable when the + firewall incorrectly interprets the Content and Threat Detection (CTD) + global packet queue as being full. +
+
+
PAN-223677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, and PA-5430 + firewalls) By enabling + Lockless QoS + feature, a slight degradation in App-ID and Threat performance is + expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, and PA-5430 firewalls, the Filter dropdown menus, + Forward Methods, and Built-In Actions for Correlation Log settings + (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-221775
+
+
+ A Malformed Request error is + displayed when you + Test Connection for an email server + profile (DeviceServer ProfilesEmail) using SMTP over TLS and the + Password includes an ampersand + (&). +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 10.2.11 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+ This issue is now resolved. See + PAN-OS 10.2.14 Addressed Issues +
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209288
+
+
+ Certificates are not successfully generated using SCEP (DeviceCertificate ManagementSCEP). +
+
+
PAN-208622
+
+
+ A file upload to Box.com exceeding 6 files gets stuck and fails to + upload if you specify an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles + with the Action set to Block to a + Security policy rule (PoliciesSecurity). +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 10.2.4, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196504
+
+ License deactivation fails for VM-Series firewalls licensed using PA-VM + Bundle 3 (BND3). +
+
PAN-194996
+
+
+ When using a 10.2.2 Panorama to manage a Panorama Managed Prisma + Access 3.1.2 deployment, allocating bandwidth for a remote network + deployment fails (the OK button is grayed out). +
+
+ Workaround: Retry the operation. +
+
+
PAN-194519
+
+
+ (PA-5450 firewall only) Trying to configure a + custom payload format under + DeviceServer ProfilesHTTP + yields a Javascript error. +
+
+
PAN-194515
+
+
+ (PA-5450 firewall only) The Panorama web + interface does not display any predefined template stack variables in + the dropdown menu under + DeviceSetupLog InterfaceIP Address. +
+
+ Workaround: Configure the log interface IP address + on the individual firewall web interface instead of on Panorama. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-194202
+
+
+ (PA-5450 firewall only) If the management + interface and logging interface are configured on the same subnetwork, + the firewall conducts log forwarding using the management interface + instead of the logging interface. +
+
+
PAN-190727
+
+
+ (PA-5450 firewall only) Documentation for + configuring the log interface is unavailable on the web interface and + in the PAN-OS Administrator’s Guide. +
+
+
PAN-189111
+
+
+ After deleting an MP pod and it comes up, the + show routing command output + appears empty and traffic stops working. +
+
+
PAN-189076
+
+
+ On a firewall with Advanced Routing enabled, OSPFv3 peers using a + broadcast link and a designated router (DR) priority of 0 (zero) are + stuck in a two-way state after HA failover. +
+
+ Workaround: Configure at least one OSPFv3 neighbor + with a non-zero priority setting in the same broadcast domain. +
+
+
PAN-188358
+
+
+ After triggering a soft reboot on a M-700 appliance, the Management + port LEDs do not light up when a 10G Ethernet cable is plugged in. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187643
+
+
+ If you enable SCTP security using a Panorama template when + SCTP INIT Flood Protection is + enabled in the Zone Protection profile using Panorama and you commit + all changes, the commit is successful but the + SCTP INIT option is not available in + the Zone Protection profile. +
+
+ Workaround: Log out of the firewall and log in + again to make the SCIT INIT option + available on the web interface. +
+
+
PAN-187612
+
+
+ On the Panorama management server, not all data profiles (ObjectsDLP Data Filtering Profiles) are displayed after you: +
+
    +
  • +
    + Upgrade Panorama to PAN-OS 10.2 and upgrade the Enterprise DLP + plugin to version 3.0. +
    +
  • +
  • +
    + Downgrade Panorama to PAN-OS 10.1 and downgrade the Enterprise DLP + plugin to version 1.0. +
    +
  • +
+
+ Workaround: Log in to the Panorama CLI and reset + the DLP plugin. +
+ admin > request plugins dlp reset +
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-187370
+
+
+ On a firewall with Advanced Routing enabled, if there is also a + logical router instance that uses the default configuration and has no + interfaces assigned to it, this will result in terminating the + management daemon and main routing daemon in the firewall during + commit. +
+
+ Workaround: Do not use a logical router instance + with no interfaces bound to it. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-186282
+
+
+ On HA deployments on AWS and Azure, Panorama fails to populate match + criteria automatically when adding dynamic address groups. +
+
+ Workaround: Reboot the Panorama HA pair. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-181823
+
+
+ On a PA-5400 Series firewall (minus the PA-5450), setting the peer + port to forced 10M or 100M speed causes any multi-gigabit RJ-45 ports + on the firewall to go down if they are set to Auto. +
+
+
PAN-180661
+
+
+ On the Panorama management server, pushing an unsupported Minimum + Password Complexity (DeviceSetupManagement) to a managed firewall erroneously displays + commit time out as the reason the + commit failed. +
+
+
PAN-180104
+
+
+ When upgrading a CN-Series as a DaemonSet deployment to PAN-OS 10.2, + CN-NGFW pods fail to connect to CN-MGMT pod if the Kubernetes cluster + previously had a CN-Series as a DaemonSet deployment running PAN-OS + 10.0 or 10.1. +
+
+ Workaround: Reboot the worker nodes before + upgrading to PAN-OS 10.2. +
+
+
PAN-178194
+
+
+ A user interface issue in PAN-OS renders the contents of the + Inline ML tab in the + URL Filtering Profile inaccessible + on firewalls licensed for Advanced URL Filtering. Additionally, a + message indicating that a + License required for URL filtering to function + is unavailable displays at the bottom of the UI. These errors do not + affect the operation of Advanced URL Filtering or URL Filtering Inline + ML. +
+
+ Workaround: Configuration settings for URL + Filtering Inline ML must be applied through the CLI. The following + configuration commands are available: +
+
    +
  • +
    + Define URL exceptions for specific web sites— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-category-exception
    +
    +
    +
  • +
+
    +
  • +
    + Configuration settings for each inline ML model— +
    +
    admin# set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled
    +
    +
    +
  • +
+
+
PAN-177455
+
+
+ PAN-OS 10.2.0 is not supported on PA-7000 Series firewalls with HA + (High Availability) clustering enabled and using an HA4 communication + link. Attempting to load PAN-OS 10.2.0 on the firewall causes the + PA-7000 100G NPC to go offline. As a result, the firewall fails to + boot normally and enters maintenance mode. HA Pairs of Active-Passive + and Active-Active firewalls are not affected. +
+
+
PAN-175915
+
+
+ When the firewall is deployed on N3 and N11 interfaces in 5G networks + and 5G-HTTP/2 traffic inspection is enabled in the Mobile Network + Protection Profile, the traffic logs do not display network slice SST + and SD values. +
+
+
PAN-174982
+
+
+ In HA active/active configurations where, when interfaces that were + associated with a virtual router were deleted, the configuration + change did not sync. +
+
+
PAN-172274
+
+
+ When you activate the advanced URL filtering license, your license + entitlements for PAN-DB and advanced URL filtering might not display + correctly on the firewall — this is a display anomaly, not a licensing + issue, and does not affect access to the services. +
+
+ Workaround: Issue the following command to + retrieve and update the licenses: + license request fetch. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 10.2.10 Addressed Issues. +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.0.0.html b/reference/PAN-OS/known/11.0.0.html new file mode 100644 index 0000000..46d38ea --- /dev/null +++ b/reference/PAN-OS/known/11.0.0.html @@ -0,0 +1,1971 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-242910
+
+
+ On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled are + unable to push configuration changes to managed firewalls when + Managed Devices and + Push For Other Admins are disabled. +
+
+
PAN-241041
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-229702
+
+
+ After upgrading a Panorama HA pair to PAN-OS 11.1, the ElasticSearch + connectivity might fail to establish. The issue occurs because the + client certificate on one of the Panorama devices does not have the + necessary Extended Key Usage (EKU) set for server authentication, + which is required for secure TLS communication. +
+
+ Workaround:Contact Customer Support to renew the + root client certificate. +
+
+
PAN-228515
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log + Collector mode. This causes logs to not display on the Panorama + management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. +
+
+
PAN-228273
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225886
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent + errors and unexpected TCP reconnections may occur. +
+
+
PAN-225337
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223488
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series + and virtual appliance. This causes the ElasticSearch shard purging to + not work as expected, resulting in high disk usage. +
+
+
PAN-223365
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues. +
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter + dropdown menus, Forward Methods, and Built-In Actions for Correlation + Log settings (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221015
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-220180
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-216214
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability + (HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA firewalls triggers an + HA config sync on the peer firewall. This causes the HA peer + configuration to go Out of Sync. +
+
+
PAN-215778
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests + for /config fail with the + following error due to exceeding the + total configuration size + supported on the M-600 appliance. +
+ +
+
504 Gateway timeout
+
+
+
PAN-215082
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-212533
+
+
+ Modifying the Administrator Type for + an existing administrator (DeviceAdministrators + or + PanoramaAdministrators) from Superuser to a + Role-Based custom admin, or vice + versa, does not modify the access privileges of the administrator. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209937
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues. +
+
+
+ Certificate-based authentication for administrator accounts may be + unable to log into the Panorama or firewall web interface with the + following error: +
+
+ Bad Request - Your browser sent a request that this server could + not understand +
+
+
PAN-208325
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues. +
+
+
+ The following NextGen firewalls and Panorama management server models + are unable to automatically renew the device certificate (DeviceSetupManagement + or + PanoramaSetupManagement). +
+
    +
  • M-300 and M-700
  • +
  • PA-410 Firewall
  • +
  • PA-415 and PA-445 Firewalls
  • +
  • +
    PA-440, PA-450, and PA-460 Firewalls
    +
  • +
  • PA-1400 Series
  • +
  • PA-3400 Series
  • +
  • +
    PA-5410, PA-5420, and PA-5430 Firewalls
    +
  • +
  • PA-5440 Firewall
  • +
  • PA-5450 Firewall
  • +
+
+ Workaround: Log in to the + firewall CLI + or + Panorama CLI + and fetch the device certificate. +
+ +
+
admin>request certificate fetch
+
+
+
PAN-208189
+
+ This issue is now resolved. See PAN-OS 11.0.1-h2 Addressed Issues. +
+
+
+ Traffic fails to match and reach all destinations if a Security policy + rule includes FQDN objects that resolve to two or more IP addresses. +
+
+
PAN-207770
+
+
+ Data filtering logs (MonitorLogsData Filtering) incorrectly display the traffic Direction as + server-to-client instead of + client-to-server for upload + traffic that matches Enterprise data loss prevention (DLP) data + patterns (ObjectsDLPData Filtering Patterns) in an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles). +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207629
+
+
+ On the Panorama management server, selective push fails to managed + firewalls if the managed firewalls are enabled with multiple vsys and + the Push Scope contains shared objects in device groups. +
+
+
PAN-207616
+
+
+ On the Panorama management server, after selecting managed firewalls + and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are automatically unselected and any new tag + created is applied to the managed firewalls for which you initially + created the new tag. +
+
+ Workaround: Select and then unselect the managed + firewalls for which you created a new tag. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the + configd process crashes. This + results in the Dedicated Log Collector losing connectivity to Panorama + despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-206416
+
+
+ On the Panorama management server, no data filtering log (MonitorLogsData Filtering) is generated when the managed firewall loses connectivity to the + following cloud services, and as a result fails to forward matched + traffic for inspection. +
+
    +
  • DLP cloud service
  • +
  • +
    + Advanced Threat Protection inline cloud analysis service +
    +
  • +
  • +
    Advanced URL Filtering cloud service
    +
  • +
+
+
PAN-206315
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show session info CLI command + shows that the passive firewall has packet rate and throughput values. + The packet rate and throughput of the passive firewall should be zero + since it is not processing traffic. +
+
+
PAN-206253
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues. +
+
+
+ For PA-1400 and PA-3400 Series firewalls, the default log rate is set + too low and the max configurable log rate is incorrectly capped + resulting in the firewall not generating more than 6,826 logs per + second. +
+
+
PAN-206005
+
+ This issue is now resolved. See PAN-OS 11.0.1 Addressed Issues. +
+
+
+ (PA-1400 Series, PA-3400 Series, and PA-5440 firewalls only) The I7_misc memory pool on these platforms is undersized and can + cause a loss of connectivity when reaching the limit of the memory + pool. Certain features, like using a decryption profile with Strip + ALPN disabled, can lead to depleting the memory pool and causing a + connection loss. +
+
+ Workaround: Disable HTTP2 by enabling Strip ALPN + in the decryption profile or avoid usage of the I7_misc memory pool. +
+
+
PAN-205255
+
+ This issue is now resolved. See PAN-OS 11.0.1 Addressed Issues. +
+
+
+ There is a rare PAN-OS issue that causes the dataplane to restart + unexpectedly. +
+
+
PAN-205187
+
+
+ ElasticSearch may not start properly when a newly installed Panorama + virtual appliance powers on for the first time, resulting in the + Panorama virtual appliance being unable to query logs forwarded from + the managed firewall to a Log Collector. +
+
+ Workaround: + Log in to the Panorama CLI + and start the PAN-OS software. +
+ +
+
admin>request restart software
+
+
+
PAN-205009
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show interface all, + show-high availability interface ha2, and + show high-availability all CLI + commands display the HSCI port state as unknown on both the active and + passive firewalls. +
+
+
PAN-204615
+
+ This issue is now resolved. See PAN-OS 11.0.0 Known Issues. +
+
+
+ BGP sessions can flap even when an unrelated configuration is + committed. This results in the BGP session going down and getting + established again. As a result, BGP routes get exchanged again, which + can lead to momentary traffic disruption if BGP routes were in use for + establishing traffic. +
+
+
PAN-201910
+
+
+ PAN-OS security profiles might consume a large amount of memory + depending on the profile configuration and quantity. In some cases, + this might reduce the number of supported security profiles below the + stated maximum for a given platform. +
+
+
PAN-201855
+
+
+ On the Panorama management server, cloning any template (PanoramaTemplates) corrupts certificates (DeviceCertificate ManagementCertificates) with the + Block Private Key Export setting + enabled across all templates. This results in managed firewalls + experiencing issues wherever the corrupted certificate is referenced. +
+
+ For example, you have template A, B, and C where templates A and B + have certificates with the + Block Private Key Export setting + enabled. Cloning template C corrupts the certificates with + Block Private Key Export setting + enabled in templates A and B. +
+
+ Workaround: After cloning a template, delete and + re-import the corrupted certificates. +
+
+
PAN-199557
+
+
+ On M-600 appliances in an Active/Passive high availability (HA) + configuration, the + configd process restarts due to a + memory leak on the + Active Panorama HA peer. This + causes the Panorama web interface and CLI to become unresponsive. +
+
+ Workaround: Manually reboot the + Active Panorama HA peer. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
PAN-195568 +
+ When PAN-OS 11.0 is installed on multiple data plane platforms, users + are unable to connect to the GlobalProtect portal or gateway. +
+
+
PAN-195342
+
+
+ On the Panorama management server, Context Switch fails when you try + to Context Switch from a managed firewall running PAN-OS 10.1.7 or + earlier release back to Panorama and the following error is displayed: +
+
+ Could not find start token '@start@' +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-192282
+
+ This issue is now resolved. See PAN-OS 11.0.1 Addressed Issues. +
+
+
+ (PA-415 and PA-445 firewalls only) In 1G mode, + the MGT and Ethernet 1/1 port LEDs glow amber instead of green. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-182734
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues. +
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel + configuration, BGP flaps. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.0.1.html b/reference/PAN-OS/known/11.0.1.html new file mode 100644 index 0000000..e10b669 --- /dev/null +++ b/reference/PAN-OS/known/11.0.1.html @@ -0,0 +1,1874 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-242910
+
+
+ On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled are + unable to push configuration changes to managed firewalls when + Managed Devices and + Push For Other Admins are disabled. +
+
+
PAN-241041
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-228515
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log + Collector mode. This causes logs to not display on the Panorama + management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. +
+
+
PAN-228273
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225886
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent + errors and unexpected TCP reconnections may occur. +
+
+
PAN-225337
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223488
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series + and virtual appliance. This causes the ElasticSearch shard purging to + not work as expected, resulting in high disk usage. +
+
+
PAN-223365
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues. +
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter + dropdown menus, Forward Methods, and Built-In Actions for Correlation + Log settings (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221126
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Email server profiles (DeviceServer ProfilesEmail + and + PanoramaServer ProfilesEmail) to forward logs as email notifications are not forwarded in a + readable format. +
+
+ Workaround: Use a + Custom Log Format to forward logs as + email notifications in a readable format. +
+
+
PAN-221015
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-220180
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-220176
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process + crashes might occur with VoIP traffic when NAT is enabled with + Persistent Dynamic IP and Port settings. +
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-216821
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues. +
+
+
+ The reportd process crashes after + you successfully upgrade an M-200 appliance to PAN-OS 10.2.4. +
+
+
PAN-216314
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, + offloaded application traffic sessions may disconnect after a period + of time even if a session is active. The disconnect occurs after the + application's default session timeout value is exceeded. This behavior + affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9 + and 10.1.9-h1, please use the following workaround. If you have + already upgraded or downgraded to another PAN-OS version, use the + following workaround in that version. +
+
+ Workaround: Run the CLI command + debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis + value 0 + to set the value to zero (0). +
+
+
PAN-216214
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability + (HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA firewalls triggers an + HA config sync on the peer firewall. This causes the HA peer + configuration to go Out of Sync. +
+
+
PAN-215778
+
+
+ On the M-600 appliance in Management Only mode, XML API Get requests + for /config fail with the + following error due to exceeding the + total configuration size + supported on the M-600 appliance. +
+ +
+
504 Gateway timeout
+
+
+
PAN-215082
+
+
+ M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage limits are + reached. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-209937
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues. +
+
+
+ Certificate-based authentication for administrator accounts may be + unable to log into the Panorama or firewall web interface with the + following error: +
+
+ Bad Request - Your browser sent a request that this server could + not understand +
+
+
PAN-208325
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues. +
+
+
+ The following NextGen firewalls and Panorama management server models + are unable to automatically renew the device certificate (DeviceSetupManagement + or + PanoramaSetupManagement). +
+
    +
  • M-300 and M-700
  • +
  • PA-410 Firewall
  • +
  • PA-415 and PA-445 Firewalls
  • +
  • +
    PA-440, PA-450, and PA-460 Firewalls
    +
  • +
  • PA-1400 Series
  • +
  • PA-3400 Series
  • +
  • +
    PA-5410, PA-5420, and PA-5430 Firewalls
    +
  • +
  • PA-5440 Firewall
  • +
  • PA-5450 Firewall
  • +
+
+ Workaround: Log in to the + firewall CLI + or + Panorama CLI + and fetch the device certificate. +
+ +
+
admin>request certificate fetch
+
+
+
PAN-208189
+
+ This issue is now resolved. See PAN-OS 11.0.1-h2 Addressed Issues. +
+
+
+ Traffic fails to match and reach all destinations if a Security policy + rule includes FQDN objects that resolve to two or more IP addresses. +
+
+
PAN-207770
+
+
+ Data filtering logs (MonitorLogsData Filtering) incorrectly display the traffic Direction as + server-to-client instead of + client-to-server for upload + traffic that matches Enterprise data loss prevention (DLP) data + patterns (ObjectsDLPData Filtering Patterns) in an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles). +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207616
+
+
+ On the Panorama management server, after selecting managed firewalls + and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are automatically unselected and any new tag + created is applied to the managed firewalls for which you initially + created the new tag. +
+
+ Workaround: Select and then unselect the managed + firewalls for which you created a new tag. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the + configd process crashes. This + results in the Dedicated Log Collector losing connectivity to Panorama + despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-206416
+
+
+ On the Panorama management server, no data filtering log (MonitorLogsData Filtering) is generated when the managed firewall loses connectivity to the + following cloud services, and as a result fails to forward matched + traffic for inspection. +
+
    +
  • DLP cloud service
  • +
  • +
    + Advanced Threat Protection inline cloud analysis service +
    +
  • +
  • +
    Advanced URL Filtering cloud service
    +
  • +
+
+
PAN-206315
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show session info CLI command + shows that the passive firewall has packet rate and throughput values. + The packet rate and throughput of the passive firewall should be zero + since it is not processing traffic. +
+
+
PAN-205009
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show interface all, + show-high availability interface ha2, and + show high-availability all CLI + commands display the HSCI port state as unknown on both the active and + passive firewalls. +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-201910
+
+
+ PAN-OS security profiles might consume a large amount of memory + depending on the profile configuration and quantity. In some cases, + this might reduce the number of supported security profiles below the + stated maximum for a given platform. +
+
+
PAN-199557
+
+
+ On M-600 appliances in an Active/Passive high availability (HA) + configuration, the + configd process restarts due to a + memory leak on the + Active Panorama HA peer. This + causes the Panorama web interface and CLI to become unresponsive. +
+
+ Workaround: Manually reboot the + Active Panorama HA peer. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-195342
+
+
+ On the Panorama management server, Context Switch fails when you try + to Context Switch from a managed firewall running PAN-OS 10.1.7 or + earlier release back to Panorama and the following error is displayed: +
+
+ Could not find start token '@start@' +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-182734
+
+ This issue is now resolved. See PAN-OS 11.0.2 Addressed Issues. +
+
+
+ On an Advanced Routing Engine, if you change the IPSec tunnel + configuration, BGP flaps. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.0.2.html b/reference/PAN-OS/known/11.0.2.html new file mode 100644 index 0000000..7edd0ff --- /dev/null +++ b/reference/PAN-OS/known/11.0.2.html @@ -0,0 +1,1712 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-242910
+
+
+ On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled are + unable to push configuration changes to managed firewalls when + Managed Devices and + Push For Other Admins are disabled. +
+
+
PAN-241041
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-231507
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On PA-1400 Series firewalls only, when an HSCI interface is used as an + HA2 interface, HA2 packets are intermittently dropped on the passive + device, which can cause the HA2 connection to flap due to missing HA2 + keepalive messages. Workaround: use data ports configured as HA2 + interface. +
+
+
PAN-228515
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log + Collector mode. This causes logs to not display on the Panorama + management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. +
+
+
PAN-228273
+
+
+ On the Panorama management server in FIPS-CC mode, the ElasticSearch + cluster fails to come up and the + show log-collector-es-cluster health + command displays the status is + red. This results in log + ingestion issues for Panorama in Panorama only or Log Collector mode. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225886
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent + errors and unexpected TCP reconnections may occur. +
+
+
PAN-225337
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-223488
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Closed ElasticSearch shards are not deleted from the Panorama M-Series + and virtual appliance. This causes the ElasticSearch shard purging to + not work as expected, resulting in high disk usage. +
+
+
PAN-223365
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues. +
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-227368
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues. +
+
+
+ The GlobalProtect app cannot connect to a portal or gateway and + GlobalProtect Clientless VPN users cannot access applications if + authentication takes longer than 20 seconds. +
+
+ Workaround: Increase the TCP handshake timeout to + the maximum value of 60 seconds. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter + dropdown menus, Forward Methods, and Built-In Actions for Correlation + Log settings (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221126
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Email server profiles (DeviceServer ProfilesEmail + and + PanoramaServer ProfilesEmail) to forward logs as email notifications are not forwarded in a + readable format. +
+
+ Workaround: Use a + Custom Log Format to forward logs as + email notifications in a readable format. +
+
+
PAN-221015
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-220180
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-220176
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process + crashes might occur with VoIP traffic when NAT is enabled with + Persistent Dynamic IP and Port settings. +
+
+
PAN-219644
+
+ This issue is now resolved. See PAN-OS 11.0.3 Addressed Issues. +
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-216314
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, + offloaded application traffic sessions may disconnect after a period + of time even if a session is active. The disconnect occurs after the + application's default session timeout value is exceeded. This behavior + affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9 + and 10.1.9-h1, please use the following workaround. If you have + already upgraded or downgraded to another PAN-OS version, use the + following workaround in that version. +
+
+ Workaround: Run the CLI command + debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis + value 0 + to set the value to zero (0). +
+
+
PAN-216214
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability + (HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA firewalls triggers an + HA config sync on the peer firewall. This causes the HA peer + configuration to go Out of Sync. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212978
+
+
+ The Palo Alto Networks firewall stops responding when executing an + SD-WAN debug operational CLI command. +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-207770
+
+
+ Data filtering logs (MonitorLogsData Filtering) incorrectly display the traffic Direction as + server-to-client instead of + client-to-server for upload + traffic that matches Enterprise data loss prevention (DLP) data + patterns (ObjectsDLPData Filtering Patterns) in an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles). +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207616
+
+
+ On the Panorama management server, after selecting managed firewalls + and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are automatically unselected and any new tag + created is applied to the managed firewalls for which you initially + created the new tag. +
+
+ Workaround: Select and then unselect the managed + firewalls for which you created a new tag. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the + configd process crashes. This + results in the Dedicated Log Collector losing connectivity to Panorama + despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-206416
+
+
+ On the Panorama management server, no data filtering log (MonitorLogsData Filtering) is generated when the managed firewall loses connectivity to the + following cloud services, and as a result fails to forward matched + traffic for inspection. +
+
    +
  • DLP cloud service
  • +
  • +
    + Advanced Threat Protection inline cloud analysis service +
    +
  • +
  • +
    Advanced URL Filtering cloud service
    +
  • +
+
+
PAN-206315
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show session info CLI command + shows that the passive firewall has packet rate and throughput values. + The packet rate and throughput of the passive firewall should be zero + since it is not processing traffic. +
+
+
PAN-205009
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show interface all, + show-high availability interface ha2, and + show high-availability all CLI + commands display the HSCI port state as unknown on both the active and + passive firewalls. +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-201910
+
+
+ PAN-OS security profiles might consume a large amount of memory + depending on the profile configuration and quantity. In some cases, + this might reduce the number of supported security profiles below the + stated maximum for a given platform. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-195342
+
+
+ On the Panorama management server, Context Switch fails when you try + to Context Switch from a managed firewall running PAN-OS 10.1.7 or + earlier release back to Panorama and the following error is displayed: +
+
+ Could not find start token '@start@' +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-193004
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ The Panorama management server fails to delete old IP Tag data. This + causes the /opt/pancfg partition + to reach maximum capacity which impacts Panorama performance. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.0.3.html b/reference/PAN-OS/known/11.0.3.html new file mode 100644 index 0000000..b24f586 --- /dev/null +++ b/reference/PAN-OS/known/11.0.3.html @@ -0,0 +1,1668 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-241536
+
+
+ On the Panorama management server, a user with an Admin Role is unable + to modify or add filters to profiles under + PanoramaNetworkRoutingRouting ProfilesFilters, despite having the necessary read and write privileges. +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-242910
+
+ PAN-OS 11.0.3, 11.0.3-h1, 11.0.3-h3, and 11.0.3-h5 +
+
+
+ On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled are + unable to push configuration changes to managed firewalls when + Managed Devices and + Push For Other Admins are disabled. +
+
+
PAN-242837
+
+
+ Default login credentials and SSH fail after enabling FIPS-CC Mode on + a firewall or Panorama after converting through the Maintenance + Recovery Tool (MRT). The firewall or Panorama becomes stuck and + requires a factory reset to recover. +
+
+
PAN-241041
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-238769
+
+
+ FIPS-CC VM only. Upgrading to 10.1.10-h2 or 10.1.11 will change all + locally created security Policy actions to Deny. Re-load the back-up + config taken before upgrading or the last version to get the previous + config back. Also, Unable to login to FIPSCC Mode devices with default + credentials after converting the mode for 10.1.12 release , 10.2.7 + release , 11.1.0 , 11.1.1, 11.0.3 versions. +
+
+
PAN-234929
+
+
+ The tabs in the ACC, such as + Network Activity, + Threat Activity, and + Blocked Activity, may not display + any data when you apply a Time filter for the Last 15 minutes, Last + Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter, + the data displayed may not be accurate. Additionally, reports run + against summary logs may not display accurate results. +
+
+
PAN-231507
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On PA-1400 Series firewalls only, when an HSCI interface is used as an + HA2 interface, HA2 packets are intermittently dropped on the passive + device, which can cause the HA2 connection to flap due to missing HA2 + keepalive messages. Workaround: use data ports configured as HA2 + interface. +
+
+
PAN-228515
+
+
+ The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log + Collector mode. This causes logs to not display on the Panorama + management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. +
+
+
PAN-227344
+
+
+ On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined reports are included + in the summary report. +
+
+
PAN-225886
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent + errors and unexpected TCP reconnections may occur. +
+
+
PAN-225337
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-233677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and + PA-5440 firewalls) By enabling + Lockless QoS feature, a slight degradation in App-ID and Threat performance is expected. +
+
+
PAN-223365
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues. +
+
+
+ The Panorama management server is unable to query any logs if the + ElasticSearch health status for any Log Collector (PanoramaManaged Collector + is degraded. +
+
+ Workaround: + Log in to the Log Collector CLI + and restart ElasticSearch. +
+ +
+
admindebug elasticsearch es-restart all
+
+
+
PAN-227368
+
+ This issue is now resolved. See PAN-OS 11.0.4 Addressed Issues. +
+
+
+ The GlobalProtect app cannot connect to a portal or gateway and + GlobalProtect Clientless VPN users cannot access applications if + authentication takes longer than 20 seconds. +
+
+ Workaround: Increase the TCP handshake timeout to + the maximum value of 60 seconds. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter + dropdown menus, Forward Methods, and Built-In Actions for Correlation + Log settings (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221015
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ On M-600 appliances in Panorama or Log Collector mode, the + es-1 and + es-2 ElasticSearch processes fail + to restart when the M-600 appliance is rebooted. The results in the + Managed Collector ES health + status (PanoramaManaged CollectorsHealth Status) to be degraded. +
+
+ Workaround: + Log in to the Panorama or Log Collector CLI + experiencing degraded ElasticSearch health and restart all + ElasticSearch processes. +
+ +
+
admin>debug elasticsearch es-restart optional all
Code copied to clipboard
Unable to copy due to lack of browser support.
+
+
+
PAN-220176
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process + crashes might occur with VoIP traffic when NAT is enabled with + Persistent Dynamic IP and Port settings. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-217307
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-216314
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, + offloaded application traffic sessions may disconnect after a period + of time even if a session is active. The disconnect occurs after the + application's default session timeout value is exceeded. This behavior + affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9 + and 10.1.9-h1, please use the following workaround. If you have + already upgraded or downgraded to another PAN-OS version, use the + following workaround in that version. +
+
+ Workaround: Run the CLI command + debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis + value 0 + to set the value to zero (0). +
+
+
PAN-216214
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability + (HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA firewalls triggers an + HA config sync on the peer firewall. This causes the HA peer + configuration to go Out of Sync. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212978
+
+
+ The Palo Alto Networks firewall stops responding when executing an + SD-WAN debug operational CLI command. +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-207770
+
+
+ Data filtering logs (MonitorLogsData Filtering) incorrectly display the traffic Direction as + server-to-client instead of + client-to-server for upload + traffic that matches Enterprise data loss prevention (DLP) data + patterns (ObjectsDLPData Filtering Patterns) in an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles). +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207616
+
+
+ On the Panorama management server, after selecting managed firewalls + and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are automatically unselected and any new tag + created is applied to the managed firewalls for which you initially + created the new tag. +
+
+ Workaround: Select and then unselect the managed + firewalls for which you created a new tag. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the + configd process crashes. This + results in the Dedicated Log Collector losing connectivity to Panorama + despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-206416
+
+
+ On the Panorama management server, no data filtering log (MonitorLogsData Filtering) is generated when the managed firewall loses connectivity to the + following cloud services, and as a result fails to forward matched + traffic for inspection. +
+
    +
  • DLP cloud service
  • +
  • +
    + Advanced Threat Protection inline cloud analysis service +
    +
  • +
  • +
    Advanced URL Filtering cloud service
    +
  • +
+
+
PAN-206315
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show session info CLI command + shows that the passive firewall has packet rate and throughput values. + The packet rate and throughput of the passive firewall should be zero + since it is not processing traffic. +
+
+
PAN-205009
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show interface all, + show-high availability interface ha2, and + show high-availability all CLI + commands display the HSCI port state as unknown on both the active and + passive firewalls. +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-201910
+
+
+ PAN-OS security profiles might consume a large amount of memory + depending on the profile configuration and quantity. In some cases, + this might reduce the number of supported security profiles below the + stated maximum for a given platform. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-195342
+
+
+ On the Panorama management server, Context Switch fails when you try + to Context Switch from a managed firewall running PAN-OS 10.1.7 or + earlier release back to Panorama and the following error is displayed: +
+
+ Could not find start token '@start@' +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-193004
+
+ This issue is now resolved. See + PAN-OS 11.0.4 Addressed Issues. +
+
+
+ The Panorama management server fails to delete old IP Tag data. This + causes the /opt/pancfg partition + to reach maximum capacity which impacts Panorama performance. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.0.4.html b/reference/PAN-OS/known/11.0.4.html new file mode 100644 index 0000000..07b6c03 --- /dev/null +++ b/reference/PAN-OS/known/11.0.4.html @@ -0,0 +1,1146 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-252744
+
+
+ After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series + firewalls that are equipped with OCTEON 7x00 dataplane chips to PAN-OS + 11.0.4 or 11.0.4-h1, the firewall might see continuous crashes, reboot + repeatedly, and/or go into a non-functional state. +
+
+ Workaround: If you have already upgraded to one of + those releases, downgrade to an earlier release or upgrade to PAN-OS + 11.0.4-h2. +
+
+
PAN-241041
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-234929
+
+
+ The tabs in the ACC, such as + Network Activity, + Threat Activity, and + Blocked Activity, may not display + any data when you apply a Time filter for the Last 15 minutes, Last + Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter, + the data displayed may not be accurate. Additionally, reports run + against summary logs may not display accurate results. +
+
+
PAN-225886
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent + errors and unexpected TCP reconnections may occur. +
+
+
PAN-233677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and + PA-5440 firewalls) By enabling + Lockless QoS feature, a slight degradation in App-ID and Threat performance is expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter + dropdown menus, Forward Methods, and Built-In Actions for Correlation + Log settings (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-222253
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ On the Panorama management server, policy rulebase reordering when you + View Rulebase by Groups (Policy<policy-rulebase>) does not persist if you reorder the policy rulebase by dragging and + dropping individual policy rules and then moving the entire tag group. +
+
+
PAN-221033
+
+
+ The firewall is responding to an ARP request for an IP address in the + firewall's NAT address pool when that IP address isn't in the same + subnet as the IP address of the ingress interface. +
+
+
PAN-220176
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process + crashes might occur with VoIP traffic when NAT is enabled with + Persistent Dynamic IP and Port settings. +
+
+
PAN-218521
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The ElasticSearch process on the M-600 appliance in Log Collector mode + may enter a continuous reboot cycle. This results in the M-600 + appliance becoming unresponsive, consuming logging disk space, and + preventing new log ingestion. +
+
+
PAN-216314
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, + offloaded application traffic sessions may disconnect after a period + of time even if a session is active. The disconnect occurs after the + application's default session timeout value is exceeded. This behavior + affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9 + and 10.1.9-h1, please use the following workaround. If you have + already upgraded or downgraded to another PAN-OS version, use the + following workaround in that version. +
+
+ Workaround: Run the CLI command + debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis + value 0 + to set the value to zero (0). +
+
+
PAN-216214
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability + (HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA firewalls triggers an + HA config sync on the peer firewall. This causes the HA peer + configuration to go Out of Sync. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212978
+
+
+ The Palo Alto Networks firewall stops responding when executing an + SD-WAN debug operational CLI command. +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-207770
+
+
+ Data filtering logs (MonitorLogsData Filtering) incorrectly display the traffic Direction as + server-to-client instead of + client-to-server for upload + traffic that matches Enterprise data loss prevention (DLP) data + patterns (ObjectsDLPData Filtering Patterns) in an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles). +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207616
+
+
+ On the Panorama management server, after selecting managed firewalls + and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are automatically unselected and any new tag + created is applied to the managed firewalls for which you initially + created the new tag. +
+
+ Workaround: Select and then unselect the managed + firewalls for which you created a new tag. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the + configd process crashes. This + results in the Dedicated Log Collector losing connectivity to Panorama + despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-206416
+
+
+ On the Panorama management server, no data filtering log (MonitorLogsData Filtering) is generated when the managed firewall loses connectivity to the + following cloud services, and as a result fails to forward matched + traffic for inspection. +
+
    +
  • DLP cloud service
  • +
  • +
    + Advanced Threat Protection inline cloud analysis service +
    +
  • +
  • +
    Advanced URL Filtering cloud service
    +
  • +
+
+
PAN-206315
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show session info CLI command + shows that the passive firewall has packet rate and throughput values. + The packet rate and throughput of the passive firewall should be zero + since it is not processing traffic. +
+
+
PAN-205009
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show interface all, + show-high availability interface ha2, and + show high-availability all CLI + commands display the HSCI port state as unknown on both the active and + passive firewalls. +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-201910
+
+
+ PAN-OS security profiles might consume a large amount of memory + depending on the profile configuration and quantity. In some cases, + this might reduce the number of supported security profiles below the + stated maximum for a given platform. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-196146
+
+ This issue is now resolved. See PAN-OS 11.0.5 Addressed Issues. +
+
+
+ The VM-Series firewall on Azure does not boot up with a hostname + (specified in an init-cgf.txt or user data) when bootstrapped. +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-195342
+
+
+ On the Panorama management server, Context Switch fails when you try + to Context Switch from a managed firewall running PAN-OS 10.1.7 or + earlier release back to Panorama and the following error is displayed: +
+
+ Could not find start token '@start@' +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.0.5.html b/reference/PAN-OS/known/11.0.5.html new file mode 100644 index 0000000..45675cb --- /dev/null +++ b/reference/PAN-OS/known/11.0.5.html @@ -0,0 +1,1063 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-252744
+
+
+ After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series + firewalls that are equipped with OCTEON 7x00 dataplane chips to PAN-OS + 11.0.4 or 11.0.4-h1, the firewall might see continuous crashes, reboot + repeatedly, and/or go into a non-functional state. +
+
+ Workaround: If you have already upgraded to one of + those releases, downgrade to an earlier release or upgrade to PAN-OS + 11.0.4-h2. +
+
+
PAN-241041
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-234929
+
+
+ The tabs in the ACC, such as + Network Activity, + Threat Activity, and + Blocked Activity, may not display + any data when you apply a Time filter for the Last 15 minutes, Last + Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter, + the data displayed may not be accurate. Additionally, reports run + against summary logs may not display accurate results. +
+
+
PAN-225886
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent + errors and unexpected TCP reconnections may occur. +
+
+
PAN-233677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and + PA-5440 firewalls) By enabling + Lockless QoS feature, a slight degradation in App-ID and Threat performance is expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter + dropdown menus, Forward Methods, and Built-In Actions for Correlation + Log settings (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-220176
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process + crashes might occur with VoIP traffic when NAT is enabled with + Persistent Dynamic IP and Port settings. +
+
+
PAN-216314
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, + offloaded application traffic sessions may disconnect after a period + of time even if a session is active. The disconnect occurs after the + application's default session timeout value is exceeded. This behavior + affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9 + and 10.1.9-h1, please use the following workaround. If you have + already upgraded or downgraded to another PAN-OS version, use the + following workaround in that version. +
+
+ Workaround: Run the CLI command + debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis + value 0 + to set the value to zero (0). +
+
+
PAN-216214
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability + (HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA firewalls triggers an + HA config sync on the peer firewall. This causes the HA peer + configuration to go Out of Sync. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212978
+
+
+ The Palo Alto Networks firewall stops responding when executing an + SD-WAN debug operational CLI command. +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-207770
+
+
+ Data filtering logs (MonitorLogsData Filtering) incorrectly display the traffic Direction as + server-to-client instead of + client-to-server for upload + traffic that matches Enterprise data loss prevention (DLP) data + patterns (ObjectsDLPData Filtering Patterns) in an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles). +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207616
+
+
+ On the Panorama management server, after selecting managed firewalls + and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are automatically unselected and any new tag + created is applied to the managed firewalls for which you initially + created the new tag. +
+
+ Workaround: Select and then unselect the managed + firewalls for which you created a new tag. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the + configd process crashes. This + results in the Dedicated Log Collector losing connectivity to Panorama + despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-206416
+
+
+ On the Panorama management server, no data filtering log (MonitorLogsData Filtering) is generated when the managed firewall loses connectivity to the + following cloud services, and as a result fails to forward matched + traffic for inspection. +
+
    +
  • DLP cloud service
  • +
  • +
    + Advanced Threat Protection inline cloud analysis service +
    +
  • +
  • +
    Advanced URL Filtering cloud service
    +
  • +
+
+
PAN-206315
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show session info CLI command + shows that the passive firewall has packet rate and throughput values. + The packet rate and throughput of the passive firewall should be zero + since it is not processing traffic. +
+
+
PAN-205009
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show interface all, + show-high availability interface ha2, and + show high-availability all CLI + commands display the HSCI port state as unknown on both the active and + passive firewalls. +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-201910
+
+
+ PAN-OS security profiles might consume a large amount of memory + depending on the profile configuration and quantity. In some cases, + this might reduce the number of supported security profiles below the + stated maximum for a given platform. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-195342
+
+
+ On the Panorama management server, Context Switch fails when you try + to Context Switch from a managed firewall running PAN-OS 10.1.7 or + earlier release back to Panorama and the following error is displayed: +
+
+ Could not find start token '@start@' +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.0.6.html b/reference/PAN-OS/known/11.0.6.html new file mode 100644 index 0000000..3f5db03 --- /dev/null +++ b/reference/PAN-OS/known/11.0.6.html @@ -0,0 +1,1063 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5632
+
+
+ The number of registered WildFire appliances reported in Panorama + (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the current status of connected + WildFire appliances. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-252744
+
+
+ After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series + firewalls that are equipped with OCTEON 7x00 dataplane chips to PAN-OS + 11.0.4 or 11.0.4-h1, the firewall might see continuous crashes, reboot + repeatedly, and/or go into a non-functional state. +
+
+ Workaround: If you have already upgraded to one of + those releases, downgrade to an earlier release or upgrade to PAN-OS + 11.0.4-h2. +
+
+
PAN-241041
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-234929
+
+
+ The tabs in the ACC, such as + Network Activity, + Threat Activity, and + Blocked Activity, may not display + any data when you apply a Time filter for the Last 15 minutes, Last + Hour, Last 6 Hours, or Last 12 Hours. With the Last 24 Hours filter, + the data displayed may not be accurate. Additionally, reports run + against summary logs may not display accurate results. +
+
+
PAN-225886
+
+
+ If you enable explicit proxy mode for the web proxy, intermittent + errors and unexpected TCP reconnections may occur. +
+
+
PAN-233677
+
+
+ (PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and + PA-5440 firewalls) By enabling + Lockless QoS feature, a slight degradation in App-ID and Threat performance is expected. +
+
+
PAN-222586
+
+
+ On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter + dropdown menus, Forward Methods, and Built-In Actions for Correlation + Log settings (DeviceLog Settings) are not displayed and cannot be configured. +
+
+
PAN-220176
+
+
+ (PAN-OS 11.0.1-h2 hotfix) System process + crashes might occur with VoIP traffic when NAT is enabled with + Persistent Dynamic IP and Port settings. +
+
+
PAN-216314
+
+
+ Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, + offloaded application traffic sessions may disconnect after a period + of time even if a session is active. The disconnect occurs after the + application's default session timeout value is exceeded. This behavior + affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9 + and 10.1.9-h1, please use the following workaround. If you have + already upgraded or downgraded to another PAN-OS version, use the + following workaround in that version. +
+
+ Workaround: Run the CLI command + debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis + value 0 + to set the value to zero (0). +
+
+
PAN-216214
+
+
+ For Panorama-managed firewalls in an Active/Active High Availability + (HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA firewalls triggers an + HA config sync on the peer firewall. This causes the HA peer + configuration to go Out of Sync. +
+
+
PAN-213746
+
+
+ On the Panorama management server, the + Hostkey displayed as + undefined undefined if you + override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template Stack. +
+
+
PAN-213119
+
+
+ PA-5410 and PA-5420 firewalls display the following error when you + view the Block IP list (MonitorBlock IP): +
+
+ show -> dis-block-table is unexpected +
+
+
PAN-212978
+
+
+ The Palo Alto Networks firewall stops responding when executing an + SD-WAN debug operational CLI command. +
+
+
PAN-212889
+
+
+ On the Panorama management server, different threat names are used + when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the ACC + displaying + no data to display when you are + redirected to the ACC after clicking a threat name in the Threat + Monitor and filtering the same threat name in the Global Filters. +
+
+
PAN-211531
+
+ On the Panorama management server, admins can still perform a selective + push to managed firewalls when + Push All Changes and + Push for Other Admins are disabled in + the admin role profile (PanoramaAdmin Roles). +
+
PAN-207770
+
+
+ Data filtering logs (MonitorLogsData Filtering) incorrectly display the traffic Direction as + server-to-client instead of + client-to-server for upload + traffic that matches Enterprise data loss prevention (DLP) data + patterns (ObjectsDLPData Filtering Patterns) in an Enterprise DLP data filtering profile (ObjectsDLPData Filtering Profiles). +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207616
+
+
+ On the Panorama management server, after selecting managed firewalls + and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are automatically unselected and any new tag + created is applied to the managed firewalls for which you initially + created the new tag. +
+
+ Workaround: Select and then unselect the managed + firewalls for which you created a new tag. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the + configd process crashes. This + results in the Dedicated Log Collector losing connectivity to Panorama + despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-206416
+
+
+ On the Panorama management server, no data filtering log (MonitorLogsData Filtering) is generated when the managed firewall loses connectivity to the + following cloud services, and as a result fails to forward matched + traffic for inspection. +
+
    +
  • DLP cloud service
  • +
  • +
    + Advanced Threat Protection inline cloud analysis service +
    +
  • +
  • +
    Advanced URL Filtering cloud service
    +
  • +
+
+
PAN-206315
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show session info CLI command + shows that the passive firewall has packet rate and throughput values. + The packet rate and throughput of the passive firewall should be zero + since it is not processing traffic. +
+
+
PAN-205009
+
+
+ (PA-1420 firewall only) In an active/passive + high availability (HA) configuration, the + show interface all, + show-high availability interface ha2, and + show high-availability all CLI + commands display the HSCI port state as unknown on both the active and + passive firewalls. +
+
+
PAN-204689
+
+
+ Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do + not work: +
+
    +
  • + Allow user to disconnect GlobalProtect AppAllow with Passcode +
  • +
  • + Allow user to Disable GlobalProtect AppAllow with Passcode +
  • +
  • + Allow User to Uninstall GlobalProtect AppAllow with Password +
  • +
+
+
PAN-201910
+
+
+ PAN-OS security profiles might consume a large amount of memory + depending on the profile configuration and quantity. In some cases, + this might reduce the number of supported security profiles below the + stated maximum for a given platform. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-197097
+
+
+ Large Scale VPN (LSVPN) does not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-195342
+
+
+ On the Panorama management server, Context Switch fails when you try + to Context Switch from a managed firewall running PAN-OS 10.1.7 or + earlier release back to Panorama and the following error is displayed: +
+
+ Could not find start token '@start@' +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-194424
+
+
+ (PA-5450 firewall only) Upgrading to PAN-OS + 10.2.2 while having a log interface configured can cause both the log + interface and the management interface to remain connected to the log + collector. +
+
+ Workaround: Restart the log receiver service by + running the following CLI command: + +
+
debug software restart process log-receiver
+
+
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-171938
+
+
+ No results are displayed when you + Show Application Filter for a + Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). +
+
+
PAN-164885
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.1.15.html b/reference/PAN-OS/known/11.1.15.html new file mode 100644 index 0000000..89f3b6c --- /dev/null +++ b/reference/PAN-OS/known/11.1.15.html @@ -0,0 +1,840 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-317755
+
+ This issue is now resolved. See PAN-OS 11.1.16 Addressed Issues. +
+
+
+ A selective push from Panorama to managed firewalls fail when plugin + configurations reference certain Panorama settings, such as + log-collector groups or access domains. +
+
+
PAN-314624
+
+ This issue is now resolved. See PAN-OS 11.1.16 Addressed Issues. +
+
+
+ The + useridd + process restarts when you attempt to dump the Host Information Profile + (HIP) database using the + debug user-id dump hip-profile-database + command. This occurs while the firewall is actively processing HIP + reports, such as logouts or updates. The command initially hangs and + times out before the + useridd + process restarts. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert + Clearing snmpd.log due to log overflow + due to the SNMP counters rolling over. This is a benign message and + does not impact device functionality. +
+
+
PAN-289432
+
+
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-279415
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-251551
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
+
+
PAN-250903
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
+
+
PAN-247974
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.1.16.html b/reference/PAN-OS/known/11.1.16.html new file mode 100644 index 0000000..00121ef --- /dev/null +++ b/reference/PAN-OS/known/11.1.16.html @@ -0,0 +1,763 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert + Clearing snmpd.log due to log overflow + due to the SNMP counters rolling over. This is a benign message and + does not impact device functionality. +
+
+
PAN-289432
+
+
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-279415
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-251551
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
+
+
PAN-250903
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
+
+
PAN-247974
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.2.11.html b/reference/PAN-OS/known/11.2.11.html index e9fbfda..e838122 100644 --- a/reference/PAN-OS/known/11.2.11.html +++ b/reference/PAN-OS/known/11.2.11.html @@ -104,6 +104,105 @@ + + +
PAN-325120
+
+ This issue affects PAN-OS 11.2.11 +
+
+ This issue is now resolved. See PAN-OS 11.2.12 Addressed Issues +
+ + +
+ On PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms, certain + PAN-OS versions may cause intermittent connectivity issues on Eth1/1 + SFP/RJ45 data port. Additionally, devices onboarded or managed via + Eth1/1 lose call-home connectivity post-upgrade. The dedicated + management port SFP or RJ45 are not affected. +
+ Workaround: Move the Eth1/1 connection to any other + dataport (Eth1/2 to 1/9). Devices managed via Eth1/1 require an on-site + administrator to manually move the connection from Eth1/1 to the + dedicated management port. Devices managed via Eth1/1 require an on-site + administrator to manually move the connection from Eth1/1 to the + dedicated management port. +
+ On the following platforms, PoE ports will not supply power. Ethernet + traffic on PoE ports continues to function for devices that do not + require inline power. +
+ + Workaround: If power is needed from impacted PoE + ports, downgrade to an unaffected PAN-OS version. See the + May Security Advisory + for additional mitigations. +
All Affected PAN-OS Versions:
+ + + + + + +
PAN-317755
+ + +
+ A selective push from Panorama to managed firewalls fail when plugin + configurations reference certain Panorama settings, such as + log-collector groups or access domains. +
+
+ Workaround: Perform a full push instead of a + selective push as a temporary measure. Note that selective push + attempts will continue to fail until you upgrade to the release that + includes the fix. +
+ + +
PAN-308564
@@ -298,32 +397,6 @@ - - -
PAN-254236
- - -
- TLSv1.3 hybridized Kyber support in the latest versions of Chrome and - Edge browsers results in dropped Client Hello packets when SSL/TLS - handshake inspection is enabled. -
-
- Workaround: Disable - SSL/TLS handshake inspection. -
- - -
PAN-254108
@@ -433,6 +506,19 @@
PAN-247728
+
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues +
@@ -678,7 +764,7 @@
admin> show panorama-status
+ >
admin> show panorama-status
Verify the Connected status is no. @@ -694,7 +780,7 @@
admin> debug software restart process management-server
+ >
admin> debug software restart process management-server
diff --git a/reference/PAN-OS/known/11.2.12.html b/reference/PAN-OS/known/11.2.12.html new file mode 100644 index 0000000..01009c3 --- /dev/null +++ b/reference/PAN-OS/known/11.2.12.html @@ -0,0 +1,880 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-6271
+
+
+ A WildFire cluster node that has been configured with an IPv6 + management port might not display the signature status when using the + following CLI: + show wildfire global signature-status sha256 equal + <SHA_256_Value> +
+
+ Workaround: Gracefully restart the affected + Wildfire cluster nodes. +
+
+
WF500-6259
+
+
+ When a WildFire cluster node configured as a server or worker node is + rebooted, issuing the CLI command, + global sample-status does not update + the samples processed list on the active controller and non-server + worker nodes. +
+
+ Workaround: Gracefully restart the affected + WildFire active controller and passive controller in the cluster. +
+
+
WF500-6270
+
+
+ The WildFire cluster server and worker nodes might disconnect from the + Wildfire cluster management network, resulting in a notifier process + exit on WildFire cluster controllers. +
+
+ Workaround: Gracefully restart the WildFire + cluster node where the process exit occurred. +
+
+
WF500-6222
+
+
+ When WildFire secure cluster communication is enabled using a custom + DNS, the cluster formation might fail due to cluster management + communication issues. +
+
+ Workaround: Do not configure a custom DNS when + WildFire secure cluster communication is enabled. +
+
+
WF500-6176
+
+
+ When Panorama is used to manage a WildFire cluster, switchover + functionality for active and passive controller roles is not + available. +
+
+
PAN-317755
+
+
+ A selective push from Panorama to managed firewalls fail when plugin + configurations reference certain Panorama settings, such as + log-collector groups or access domains. +
+
+ Workaround: Perform a full push instead of a + selective push as a temporary measure. Note that selective push + attempts will continue to fail until you upgrade to the release that + includes the fix. +
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
PAN-308507
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently + show as inactive. When checking the status of log-forwarding + connections, one or more streams are reported as inactive. Restarting + the log-receiver process temporarily + resolves the issue, but the streams become inactive again after + approximately 1-2 hours. This intermittent inactivity results in log + loss. +
+
+
PAN-295645
+
+
+ When a WildFire cluster is configured centrally using Panorama, it + initiates a series of processes, including a software install and + reboot, in an order that will leave the resulting WildFire cluster in + an unusable state. +
+
+
PAN-288525
+
+
+ When the Enterprise DLP data filtering profile is configured with a + Block action and is used in + conjunction with Advanced Threat Prevention, which is configured with + an action of reset-both, + reset-server, + reset-client, or + drop for the + HTTP Command and Control detector, + Dropbox file uploads that exceed the maximum configured file size + action will fail. +
+
+ Workaround: Configure the Advanced Threat + Prevention Inline Cloud analysis (ObjectsSecurity ProfilesAnti-Spyware) action for the HTTP Command and Control detector to + alert. +
+
+
PAN-285061
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail + when 100 continue response is received from the server during file + uploads. +
+
+
PAN-284700
+
+
+ File downloads for content encoded with zstd (Zstandard), such as + specific content from box.com, fail when using Enterprise DLP because + zstd decompression is not supported in PAN-OS. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-260212
+
+
+ When viewing Applications (ObjectsApplications), child App-IDs may be listed under the incorrect container App-ID. +
+
+
PAN-259853
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error + message is not properly displayed when + Any is selected as the source + interface in the service router configuration ( + DeviceSetupServiceService Router Configuration). +
+
+
PAN-259423
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP + servers on the GlobalProtect gateway, the gpsvc gets stuck during + renewal and after HA failover. +
+
+
PAN-254108
+
+
+ when upgrading or downgrading a Panorama management server (PanoramaSoftware), managed device (PanoramaDevice DeploymentSoftware), or standalone firewall (DeviceSoftware), Base Releases and + Preferred Releases settings are + checked (enabled) by default and cause no PAN-OS software images to + display. +
+
+ Workaround: Uncheck (disable) + Base Releases or + Preferred Releases to display either + the available base PAN-OS or preferred PAN-OS releases available to + download and install. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-252661
+
+
+ If you change the service route of gp-ip-mgmt in + Device > Setup > Services > Service Features > + gp-ip-mgmt + and Commit, the change won’t take effect. + gp-ip-mgmt continues to use the last committed service route. +
+
+ Workaround: After you change the service route + interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or + gateway, click OK to save the configuration, and + Commit the changes. This commit will include the + service route change. +
+
+
PAN-250246
+
+
+ Panorama and the firewall display inconsistent IP addresses for + dynamic address group members after manually syncing. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-248836
+
+
+ The Advanced DNS Security trial license and trial license information + cannot be activated and viewed, respectively, on a managed firewall + (with expired or active status) from Panorama. These tasks can only be + performed on the firewall. +
+
+
PAN-247728
+
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues +
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An + upcoming version will provide support for this feature. Customers who + have multicast configured or who plan to deploy multicast routing + should not upgrade to 11.2.0. Additionally, when Advanced Routing is + enabled, the BGP dampening configuration isn't applied to any peers or + peer group; the configuration is preserved but has no effect on BGP. + Customers can use BGP even if they have applied a Dampening profile to + a specific set of peers. The issue doesn't affect any other BGP + features. +
+
+
PAN-241994
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi + and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards. + Palo Alto Networks recommends that you upgrade your ESXi version if it + is less than 6.7 U2. For more information, see the + compatibility matrix. +
+
+
PAN-239612
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is + enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay + agent doesn't work. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-236649
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or + PPPoEv6 client, old routes from the Forwarding Information Base (FIB) + and route table for an inherited configuration with dynamic-identifier + or client remain visible. Old routes also remain visible for an + inherited interface when you execute the CLI command, + show interface all. +
+
+ Workaround: Unconfigure and configure the + Inherited Interface. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.2.13.html b/reference/PAN-OS/known/11.2.13.html new file mode 100644 index 0000000..1d7d240 --- /dev/null +++ b/reference/PAN-OS/known/11.2.13.html @@ -0,0 +1,880 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-6271
+
+
+ A WildFire cluster node that has been configured with an IPv6 + management port might not display the signature status when using the + following CLI: + show wildfire global signature-status sha256 equal + <SHA_256_Value> +
+
+ Workaround: Gracefully restart the affected + Wildfire cluster nodes. +
+
+
WF500-6259
+
+
+ When a WildFire cluster node configured as a server or worker node is + rebooted, issuing the CLI command, + global sample-status does not update + the samples processed list on the active controller and non-server + worker nodes. +
+
+ Workaround: Gracefully restart the affected + WildFire active controller and passive controller in the cluster. +
+
+
WF500-6270
+
+
+ The WildFire cluster server and worker nodes might disconnect from the + Wildfire cluster management network, resulting in a notifier process + exit on WildFire cluster controllers. +
+
+ Workaround: Gracefully restart the WildFire + cluster node where the process exit occurred. +
+
+
WF500-6222
+
+
+ When WildFire secure cluster communication is enabled using a custom + DNS, the cluster formation might fail due to cluster management + communication issues. +
+
+ Workaround: Do not configure a custom DNS when + WildFire secure cluster communication is enabled. +
+
+
WF500-6176
+
+
+ When Panorama is used to manage a WildFire cluster, switchover + functionality for active and passive controller roles is not + available. +
+
+
PAN-317755
+
+
+ A selective push from Panorama to managed firewalls fail when plugin + configurations reference certain Panorama settings, such as + log-collector groups or access domains. +
+
+ Workaround: Perform a full push instead of a + selective push as a temporary measure. Note that selective push + attempts will continue to fail until you upgrade to the release that + includes the fix. +
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
PAN-308507
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently + show as inactive. When checking the status of log-forwarding + connections, one or more streams are reported as inactive. Restarting + the log-receiver process temporarily + resolves the issue, but the streams become inactive again after + approximately 1-2 hours. This intermittent inactivity results in log + loss. +
+
+
PAN-295645
+
+
+ When a WildFire cluster is configured centrally using Panorama, it + initiates a series of processes, including a software install and + reboot, in an order that will leave the resulting WildFire cluster in + an unusable state. +
+
+
PAN-288525
+
+
+ When the Enterprise DLP data filtering profile is configured with a + Block action and is used in + conjunction with Advanced Threat Prevention, which is configured with + an action of reset-both, + reset-server, + reset-client, or + drop for the + HTTP Command and Control detector, + Dropbox file uploads that exceed the maximum configured file size + action will fail. +
+
+ Workaround: Configure the Advanced Threat + Prevention Inline Cloud analysis (ObjectsSecurity ProfilesAnti-Spyware) action for the HTTP Command and Control detector to + alert. +
+
+
PAN-285061
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail + when 100 continue response is received from the server during file + uploads. +
+
+
PAN-284700
+
+
+ File downloads for content encoded with zstd (Zstandard), such as + specific content from box.com, fail when using Enterprise DLP because + zstd decompression is not supported in PAN-OS. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-260212
+
+
+ When viewing Applications (ObjectsApplications), child App-IDs may be listed under the incorrect container App-ID. +
+
+
PAN-259853
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error + message is not properly displayed when + Any is selected as the source + interface in the service router configuration ( + DeviceSetupServiceService Router Configuration). +
+
+
PAN-259423
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP + servers on the GlobalProtect gateway, the gpsvc gets stuck during + renewal and after HA failover. +
+
+
PAN-254108
+
+
+ when upgrading or downgrading a Panorama management server (PanoramaSoftware), managed device (PanoramaDevice DeploymentSoftware), or standalone firewall (DeviceSoftware), Base Releases and + Preferred Releases settings are + checked (enabled) by default and cause no PAN-OS software images to + display. +
+
+ Workaround: Uncheck (disable) + Base Releases or + Preferred Releases to display either + the available base PAN-OS or preferred PAN-OS releases available to + download and install. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-252661
+
+
+ If you change the service route of gp-ip-mgmt in + Device > Setup > Services > Service Features > + gp-ip-mgmt + and Commit, the change won’t take effect. + gp-ip-mgmt continues to use the last committed service route. +
+
+ Workaround: After you change the service route + interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or + gateway, click OK to save the configuration, and + Commit the changes. This commit will include the + service route change. +
+
+
PAN-250246
+
+
+ Panorama and the firewall display inconsistent IP addresses for + dynamic address group members after manually syncing. +
+
+
PAN-250062
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-248836
+
+
+ The Advanced DNS Security trial license and trial license information + cannot be activated and viewed, respectively, on a managed firewall + (with expired or active status) from Panorama. These tasks can only be + performed on the firewall. +
+
+
PAN-247728
+
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues +
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An + upcoming version will provide support for this feature. Customers who + have multicast configured or who plan to deploy multicast routing + should not upgrade to 11.2.0. Additionally, when Advanced Routing is + enabled, the BGP dampening configuration isn't applied to any peers or + peer group; the configuration is preserved but has no effect on BGP. + Customers can use BGP even if they have applied a Dampening profile to + a specific set of peers. The issue doesn't affect any other BGP + features. +
+
+
PAN-241994
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi + and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards. + Palo Alto Networks recommends that you upgrade your ESXi version if it + is less than 6.7 U2. For more information, see the + compatibility matrix. +
+
+
PAN-239612
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is + enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay + agent doesn't work. +
+
+
PAN-237106
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-236649
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or + PPPoEv6 client, old routes from the Forwarding Information Base (FIB) + and route table for an inherited configuration with dynamic-identifier + or client remain visible. Old routes also remain visible for an + inherited interface when you execute the CLI command, + show interface all. +
+
+ Workaround: Unconfigure and configure the + Inherited Interface. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/12.1.7.html b/reference/PAN-OS/known/12.1.7.html new file mode 100644 index 0000000..929a8f9 --- /dev/null +++ b/reference/PAN-OS/known/12.1.7.html @@ -0,0 +1,254 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-330836
+
+
+ (VM-Series software firewalls with 16 GB of memory and 16 vCPUs + only) Starting in PAN-OS 12.1.5, memory usage increases to approximately + 6 GB for firewalls running a maximum configuration, compared to + approximately 5 GB in PAN-OS 12.1.2. This increase eliminates the + available memory buffer, leaving no capacity to absorb additional + memory demand during peak load. The firewall may become unstable or + unresponsive under high-load conditions. +
+
+ Firewalls operating with 12 dp cores, or processing more than 512K + sessions, are specifically at risk for memory issues. To ensure + continued stability for firewalls matching this criteria, Palo Alto + Networks recommends an increase of overall memory allocation by 2 GB. +
+
+
+ PAN-317755This issue is now resolved. See + PAN-OS 12.1.7-h1 Addressed Issues +
+
+
+ A selective push from Panorama to managed firewalls fail when plugin + configurations reference certain Panorama settings, such as + log-collector groups or access domains. +
+
+ Workaround: Perform a full push instead of a + selective push as a temporary measure. Note that selective push + attempts will continue to fail until you upgrade to the release that + includes the fix. +
+
+
PAN-312143
+
+
+ (Firewalls in active/passive high availability (HA) configurations + only) When attempting to synchronize the running configuration with an + HA peer, particularly during script runs involving different topology + builds (e.g., during a smoke runlist), the synchronization process + fails. This results in an error indicating that the running + configuration could not be synchronized with the HA peer. +
+
+
PAN-311601
+
+
+ If the node is seen stuck with fault "session clearing fault". Node + reboot is the workaround to get the node back in online state after + all other fault conditions are removed. +
+
+
PAN-310328
+
+
+ If the node is seen stuck with fault "session clearing fault". Node + reboot is the workaround to get the node back in online state after + all other fault conditions are removed. +
+
+
PAN-300667
+
+
+ Panorama cannot display Threat log entries (Monitor > Logs > + Threat) when the managed log collector is running a lower PAN-OS + release than Panorama. Workaround: Upgrade the log collectors to the + same version as Panorama. +
+
+
PAN-300230
+
+
+ (NGFW Cluster) In an NGFW cluster, your pings to the HSCI-B link might + fail, even when the link indicates it is up. In the event that the + HSCI-A link is brought down or unplugged, the cluster node will + transition to failed state, avoiding split brain as both HSCI links + are down in this case. Workaround: Reboot the cluster node to resolve + the HSCI-B ping issue. +
+
+
PAN-299562
+
+
+ When a client sends a Client Hello with Transport Layer Security (TLS) + 1.3 or TLS 1.2, using only the p-192 elliptic curve and some + non-perfect forward secrecy (PFS) ciphers, the firewall discards the + Client Hello. The firewall should allow the connection to proceed + using TLS 1.2, maintaining backward compatibility with previous + releases. +
+
+
PAN-298083
+
+
+ Draft for review: After you change the system mode on an M-700 + appliance from Panorama mode to PAN-DB private cloud mode, the snmpd + process fails to work. +
+
+
PAN-295946
+
+
+ When a Panorama appliance (running PAN-OS 12.1.2 or higher) manages + firewalls running PAN-OS versions lower than 12.1.2, and an NTP server + configuration template includes SHA256 or SHA512 as the authentication + mechanism, pushing this template to the firewalls running PAN-OS + versions lower than 12.1.2 will cause the commit operation to fail. + Workaround: Create two separate templates: one for firewalls running + PAN-OS 12.1.2 or higher (which can include SHA256/SHA512 + authentication) and another for firewalls running PAN-OS versions + lower than 12.1.2 (which should use other authentication algorithms + such as SHA1, MD5, or Autokey). Then, push the appropriate template to + the corresponding devices from Panorama. +
+
+
PAN-292601
+
+
+ PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS + configuration for an address object. If there are two address objects + with same FQDN, but one object has Load Balanced DNS enabled and other + object has Load Balanced DNS disabled, then the policy match for the + removed IP addresses doesn't work as expected. Workaround: Enable (or + disable) Load Balanced DNS consistently for an FQDN that is used with + multiple address objects. +
+
+
PAN-289524
+
+
+ In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved + IP addresses from a Load balanced DNS server and use them in a policy + match. However, this functionality does not work as intended when the + DNS cache reuse flag is enabled. When the DNS cache reuse flag is + enabled, the DNS resolution works as if the Load balanced DNS flag + (for an Address object) is disabled. +
+
+
PAN-283028
+
+
+ The following error is thrown when an existing template overrides the + SD-WAN configuration followed by the commit and push from Panorama to + the firewall. +
+
+ BGP is invalid. AS number does not fit in 2 byte AS format +
+
+ This issue occurs because different AS formats are present on the + Panorama and the firewall (the firewall configuration is generated by + the SD-WAN plugin). That is, both the hub and branch firewall must + have the same AS format in hub-and-spoke topology. In full mesh + topology, all the firewalls must have the same AS format. +
+
diff --git a/reference/PAN-OS/known/12.1.8.html b/reference/PAN-OS/known/12.1.8.html new file mode 100644 index 0000000..4226ae6 --- /dev/null +++ b/reference/PAN-OS/known/12.1.8.html @@ -0,0 +1,317 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-330995
+
+
+ Within GCP NSI environments, egress traffic logs fail to accurately + reflect the designated NAT IP addresses. +
+
+
PAN-330964
+
+
+ In PA-VM deployed on GCP instances, it is observed that the gVNIC + interfaces appear inactive after enabling jumbo frames. +
+
+
PAN-330906
+
+
+ On Panorama, the configuration Push Scope might not include the shared + Devices object entries, even though + these objects are visible in the staged configuration changes for the + specified administrator and device group. +
+
+
PAN-330902
+
+
+ After restarting MongoDB (mdb) on Panorama using the + request mongo set mongo-update-sort-limit + CLI command, push to devices (both full push and selective push) + fails. +
+
+ Workaround: Restart + configd on Panorama. +
+
+
PAN-330836
+
+
+ (VM-Series software firewalls with 16 GB of memory and 16 vCPUs + only) Starting in PAN-OS 12.1.5, memory usage increases to approximately + 6 GB for firewalls running a maximum configuration, compared to + approximately 5 GB in PAN-OS 12.1.2. This increase eliminates the + available memory buffer, leaving no capacity to absorb additional + memory demand during peak load. The firewall may become unstable or + unresponsive under high-load conditions. +
+
+ Firewalls operating with 12 dp cores, or processing more than 512K + sessions, are specifically at risk for memory issues. To ensure + continued stability for firewalls matching this criteria, Palo Alto + Networks recommends an increase of overall memory allocation by 2 GB. +
+
+
PAN-329146
+
+
+ Within GCP NSI environments, it is observed that the Prisma AIRS + license activates geneve parsing as a + default setting, permitting intraVPC traffic flow + regardless of NSI status. Hence, you will not be able to disable this + feature through CLI. +
+
PAN-313669
+
+ (PA-5500 Series firewalls in cluster configurations only) When a + firewall node is removed from a PA-5500 Series cluster, after the + cluster commit and reboot, the node starts in standalone mode with a + default virtual wire (vwire) configuration loaded. This default + configuration is missing zone assignments for ports eth1/1 and eth1/2, + which causes commit operations to fail. Even if zones are manually + assigned to these ports, subsequent commit attempts will fail with a + "no UUId for rule1" error. +
+
+ Workaround: To resolve this, either: +
+
    +
  • + Manually assign zone configurations to ports eth1/1 (e.g., untrust) + and eth1/2 (e.g., trust), then open and close security policy rule1 + without making changes, and + Commit. +
  • +
  • + Delete the default rule and the default virtual wire Ethernet + interfaces, then commit. +
  • +
+
PAN-312143
+
+ (Firewalls in active/passive high availability (HA) configurations + only) When attempting to synchronize the running configuration with an + HA peer, particularly during script runs involving different topology + builds (e.g., during a smoke runlist), the synchronization process + fails. This results in an error indicating that the running + configuration could not be synchronized with the HA peer. +
+
PAN-311601
+
+ If the node is seen stuck with fault "session clearing fault". Node + reboot is the workaround to get the node back in online state after + all other fault conditions are removed. +
+
PAN-310328
+
+ If the node is seen stuck with fault "session clearing fault". Node + reboot is the workaround to get the node back in online state after + all other fault conditions are removed. +
+
PAN-300667
+
+ Panorama cannot display Threat log entries (Monitor > Logs > + Threat) when the managed log collector is running a lower PAN-OS + release than Panorama. Workaround: Upgrade the log collectors to the + same version as Panorama. +
+
PAN-300230
+
+ (NGFW Cluster) In an NGFW cluster, your pings to the HSCI-B link might + fail, even when the link indicates it is up. In the event that the + HSCI-A link is brought down or unplugged, the cluster node will + transition to failed state, avoiding split brain as both HSCI links + are down in this case. Workaround: Reboot the cluster node to resolve + the HSCI-B ping issue. +
+
PAN-299562
+
+ When a client sends a Client Hello with Transport Layer Security (TLS) + 1.3 or TLS 1.2, using only the p-192 elliptic curve and some + non-perfect forward secrecy (PFS) ciphers, the firewall discards the + Client Hello. The firewall should allow the connection to proceed + using TLS 1.2, maintaining backward compatibility with previous + releases. +
+
PAN-298083
+
+ Draft for review: After you change the system mode on an M-700 + appliance from Panorama mode to PAN-DB private cloud mode, the snmpd + process fails to work. +
+
PAN-295946
+
+ When a Panorama appliance (running PAN-OS 12.1.2 or higher) manages + firewalls running PAN-OS versions lower than 12.1.2, and an NTP server + configuration template includes SHA256 or SHA512 as the authentication + mechanism, pushing this template to the firewalls running PAN-OS + versions lower than 12.1.2 will cause the commit operation to fail. + Workaround: Create two separate templates: one for firewalls running + PAN-OS 12.1.2 or higher (which can include SHA256/SHA512 + authentication) and another for firewalls running PAN-OS versions + lower than 12.1.2 (which should use other authentication algorithms + such as SHA1, MD5, or Autokey). Then, push the appropriate template to + the corresponding devices from Panorama. +
+
PAN-293718
+
+ Draft for review: When high speed logging is enabled on a PA-5560 + device, the expected warning message is not displayed on the web + interface. This prevents administrators from being notified that logs + can only be viewed from Panorama. +
+
PAN-292601
+
+ PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS + configuration for an address object. If there are two address objects + with same FQDN, but one object has Load Balanced DNS enabled and other + object has Load Balanced DNS disabled, then the policy match for the + removed IP addresses doesn't work as expected. Workaround: Enable (or + disable) Load Balanced DNS consistently for an FQDN that is used with + multiple address objects. +
+
PAN-289524
+
+ In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved + IP addresses from a Load balanced DNS server and use them in a policy + match. However, this functionality does not work as intended when the + DNS cache reuse flag is enabled. When the DNS cache reuse flag is + enabled, the DNS resolution works as if the Load balanced DNS flag + (for an Address object) is disabled. +
+
PAN-283028
+
+ The following error is thrown when an existing template overrides the + SD-WAN configuration followed by the commit and push from Panorama to + the firewall. +
+
+ BGP is invalid. AS number does not fit in 2 byte AS format +
+
+ This issue occurs because different AS formats are present on the + Panorama and the firewall (the firewall configuration is generated by + the SD-WAN plugin). That is, both the hub and branch firewall must + have the same AS format in hub-and-spoke topology. In full mesh + topology, all the firewalls must have the same AS format. +
+
diff --git a/reference/PAN-OS/known/12.2.2.html b/reference/PAN-OS/known/12.2.2.html new file mode 100644 index 0000000..a7e18ed --- /dev/null +++ b/reference/PAN-OS/known/12.2.2.html @@ -0,0 +1,573 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
PAN-332943 +
+ When you upgrade a PA-450R, PA-450R-5G, PA-410R, or PA-410R-5G + firewall to PAN-OS 12.2.2 from an earlier release with Fail-to-Wire + enabled, subsequent manual commits fail with the following validation + error: network -> interface -> fail-open is invalid. This occurs + because PAN-OS 12.2.2 introduced a configuration schema change for the + Fail-to-Wire feature that is not automatically migrated during + upgrade. Fail-to-Wire also does not function correctly after the + upgrade. +
+
+ Workaround:Remove and re-add the Fail-to-Wire + configuration. +
+
+ delete network interface fail-open +
+
commit
+
+ set network interface fail-open +
+
commit
+
PAN-332874 +
+ On 5G firewalls, Zero Touch Provisioning (ZTP) over cellular does not + complete when the cellular carrier MTU is 1428. During ZTP, the + firewall does not correctly account for cellular tunnel header + overhead when negotiating the TCP maximum segment size (MSS). The + firewall advertises an MSS value that is too large for the 1428 MTU + cellular link, causing the certificate server's response packets to + exceed the link MTU. The certificate fetch does not complete, and the + firewall does not finish provisioning. +
+
+ This issue occurs when using a cellular connection with a + carrier-negotiated MTU of 1428, which is the standard MTU for cellular + wireless. ZTP process will succeed when carrier provided Network MTU + is greater than or equal to 1500. +
+
PAN-332576 +
+ On HA pairs running PAN-OS 12.2.2, the useridd process may exhaust its + ID manager (type 17) when the passive firewall accumulates more than + 1,000,000 user entries. When this occurs, useridd consumes 100% CPU + and becomes unresponsive, causing commits to fail with the error + Management server failed to send phase 1 to client useridd or to stall + at 0%. +
+
PAN-332130 +
+ On firewalls with cellular interfaces configured with parent and + sub-interfaces, APN authentication fails on sub-interfaces when the + PDP type is set to both (IPv4 and IPv6). Data sessions on the parent + interface establish successfully for both IPv4 and IPv6, but + sub-interfaces fail to bring up their data sessions when using PAP or + CHAP authentication with PDP type both. +
+
+ Workaround: Set the PDP type to IPv4 only on + sub-interfaces. +
+
PAN-331987 +
+ (PA-5450, PA-5500, and PA-7500 firewalls with PAN-OS Shield enabled) + When connecting to GlobalProtect Portal or Gateway, users receive a + `Portal unreachable` error. GlobalProtect connections are frequently + unsuccessful, though they may connect successfully after multiple + attempts. +
+
+ Workaround: Change the session distribution policy + to Round-robin. +
+
PAN-331722 +
+ On PA-54R-POE (BH/Eagle) firewalls, the PAN-S-SFP-100BASE-FX + transceiver on fiber interfaces does not link up when the interface + link speed is explicitly set to 100 Mbps. The interface links up + correctly when the link speed is set to auto. +
+
+ Workaround: Set the interface link speed to auto. +
+
PAN-331659 +
+ Running the CLI command debug dataplane packet-path-test counter on + PAN-OS 12.2.2 returns a server error instead of counter output. +
+
PAN-330995 +
+ Within GCP NSI environments, egress traffic logs fail to accurately + reflect the designated NAT IP addresses. +
+
PAN-330974 +
+ If Azure hotplug events occur, the firewall may experience a crash and + data interfaces may transition to an unknown state, leading to traffic + disruption. +
+
PAN-330964 +
+ In PA-VM deployed on GCP instances, gVNIC interfaces appear inactive + after enabling jumbo frames. +
+
PAN-330381 +
+ When firewalls are configured in a cluster operating in default mode, + IP-Tag, User-Tag, and IP-Port mappings registered on the leader node + do not synchronize to the follower node. On the follower node, + commands such as `show object registered-ip all` and `show object + registered-user all` display no registered entries for these data + types, even though they are present on the leader. This prevents + Dynamic Address Group (DAG) and Dynamic User Group (DUG) based + security policies, which rely on these mappings, from functioning + correctly on the follower node. As a result, traffic routed through + the follower node does not match these policies, leading to an + inconsistent security posture across the cluster. +
+
+ Workaround: Configure the firewall cluster to + operate in ICD mode. This enables the correct synchronization of + IP-Tag, User-Tag, and IP-Port mappings between the leader and follower + nodes. +
+
PAN-329606 +
+ On PA-54R-POE (BH) firewalls, SCP export and import of cellular + firmware files fail from the CLI. Running + request cellular firmware scp-export or + request cellular firmware scp-import + returns a server error. +
+
PAN-329515 +
+ When scheduling cellular firmware downloads on Panorama (Device Deployment > Cellular Firmware > Schedule), the Files and Devices fields are not populated in the UI for + PA-54R-POE-5G (BH/Eagle) devices. As a result, scheduled Download Only + and Download and Install operations for cellular firmware cannot be + configured through Panorama. +
+
PAN-329146 +
+ Within GCP NSI environments, the Prisma® AIRS license activates geneve + parsing as a default setting, permitting intraVPC traffic flow + regardless of NSI status. You cannot disable this feature through CLI. +
+
PAN-328647 +
+ When you configure ML7-CUID in a multi-vsys environment on PAN-OS + 12.2.2, data upload only supports the hub vsys configuration. When a + publisher is configured on a non-hub vsys, data from that vsys is not + uploaded to the cloud. All vsys must share the same segment + configuration for data upload to function correctly in this release. +
+
+ Workaround: Configure the publisher on the hub + vsys and ensure all vsys use the same segment configuration. +
+
PAN-327958 +
+ (PA-5450 Firewalls only) Basic authentication for web proxy is not + supported in 12.2.2. +
+
PAN-326791 +
+ When a Hyperscale Security Fabric (HSF) cluster uses an offline + license, the system allows the removal of configuration and + uninstallation of the Security Fabric License (SFL) plugin. If the SFL + plugin is uninstalled under these conditions, subsequent undeploy + operations do not complete successfully. +
+
+ Workaround: To allow the undeploy operation to + complete, reinstall the Security Fabric License (SFL) plugin. +
+
PAN-316972 +
+ After downgrading a PA-520 firewall from PAN-OS 12.2.0 to 12.1.5 or + later 12.1.x releases, auto-commit repeatedly fails after the + downgrade completes, leaving the firewall unable to apply its + configuration automatically. +
+
PAN-314625 +
+ The `useridd` process restarts when you attempt to dump the Host + Information Profile (HIP) database using the `debug user-id dump + hip-profile-database` command. This occurs while the firewall is + actively processing HIP reports, such as logouts or updates. The + command initially hangs and times out before the `useridd` process + restarts. +
+
PAN-313669 +
+ (PA-5500 Series firewalls in cluster configurations only) When a + firewall node is removed from a PA-5500 Series cluster, after the + cluster commit and reboot, the node starts in standalone mode with a + default virtual wire (vwire) configuration loaded. This default + configuration is missing zone assignments for ports eth1/1 and eth1/2, + which causes commit operations to fail. Even if zones are manually + assigned to these ports, subsequent commit attempts fail with a "no + UUId for rule1" error. +
+
+ Workaround: Manually assign zone configurations to + ports eth1/1 (for example, untrust) and eth1/2 (for example, trust), + then open and close security policy rule1 without making changes, and + commit. Alternatively, delete the default rule and the default virtual + wire Ethernet interfaces, then commit. +
+
PAN-312143 +
+ (Firewalls in active/passive high availability (HA) configurations + only) When you synchronize the running configuration with an HA peer, + particularly during script runs involving different topology builds, + the synchronization process fails with an error indicating that the + running configuration could not be synchronized with the HA peer. +
+
PAN-311601 +
+ If a node is stuck with a "session clearing fault," reboot the node to + restore it to an online state after all other fault conditions are + removed. +
+
PAN-310328 +
+ If a node is stuck with a "session clearing fault," reboot the node to + restore it to an online state after all other fault conditions are + removed. +
+
PAN-309410 +
+ Subscriber Identity and Equipment Identity values are missing from URL + filtering and Data Filtering logs for GTP mobility traffic. +
+
PAN-305734 +
+ On firewalls with 5G cellular interfaces, the default auto MTU value + of 1428 bytes causes IP fragmentation errors and out-of-order packets, + resulting in degraded throughput performance on cellular connections. +
+
+ Workaround: Manually set the cellular interface + MTU to 1500 bytes instead of using the auto MTU default. +
+
PAN-300667 +
+ Panorama cannot display Threat log entries (Monitor > Logs > Threat) when the managed log collector is running a lower PAN-OS release + than Panorama. +
+
+ Workaround: Upgrade the log collectors to the same + version as Panorama. +
+
PAN-300230 +
+ (NGFW Cluster) In an NGFW cluster, pings to the HSCI-B link may fail + even when the link indicates it is up. If the HSCI-A link is brought + down or unplugged, the cluster node transitions to a failed state, + avoiding split brain because both HSCI links are down. +
+
+ Workaround: Reboot the cluster node to resolve the + HSCI-B ping issue. +
+
PAN-299562 +
+ When a client sends a Client Hello with TLS 1.3 or TLS 1.2 using only + the p-192 elliptic curve and some non-perfect forward secrecy (PFS) + ciphers, the firewall discards the Client Hello. The firewall should + allow the connection to proceed using TLS 1.2, maintaining backward + compatibility with previous releases. +
+
PAN-299286 +
+ When configuring a PIM6 neighbor filter, you must include both the + primary and secondary IPv6 addresses of each neighbor in the prefix + list. Filtering on the primary address alone is not sufficient because + PIM6 Hello messages (Option 5) advertise both addresses to peers. A + filter that allows only the primary address will prevent neighbor + adjacency from forming. +
+
PAN-298083 +
+ After you change the system mode on an M-700 appliance from Panorama + mode to PAN-DB private cloud mode, the snmpd process fails to work. +
+
PAN-295946 +
+ When a Panorama appliance running PAN-OS 12.1.2 or later manages + firewalls running earlier PAN-OS versions, and an NTP server + configuration template includes SHA256 or SHA512 as the authentication + mechanism, pushing the template to firewalls running PAN-OS versions + earlier than 12.1.2 causes the commit operation to fail. +
+
+ Workaround: Create two separate templates: one for + firewalls running PAN-OS 12.1.2 or later (which can include + SHA256/SHA512 authentication) and another for firewalls running + earlier PAN-OS versions (which should use SHA1, MD5, or Autokey). Push + the appropriate template to the corresponding devices from Panorama. +
+
PAN-294752 +
+ In any 15-second interval, if connectivity (CI or management) on a + GW-Node (not P-Node) changes more than once, with each change + occurring on a different node and affecting a different link, the + cluster loses its leader, all routing protocols fail, and traffic is + blackholed if route changes occur in the network. +
+
+ Workaround: Reboot nodes that are in a FAILED + state or suspend and unsuspend any online GW-Node (not P-Node). +
+
PAN-293718 +
+ When high-speed logging is enabled on a PA-5560 firewall, the expected + warning message does not appear on the web interface. This prevents + you from being notified that logs can only be viewed from Panorama. +
+
PAN-292601 +
+ PAN-OS 12.1.2 and later 12.1 releases support a load-balanced DNS + configuration for an address object. If two address objects share the + same FQDN but one has load-balanced DNS enabled and the other has it + disabled, the policy match for removed IP addresses does not work as + expected. +
+
+ Workaround: Enable or disable load-balanced DNS + consistently for any FQDN used with multiple address objects. +
+
PAN-289524 +
+ In PAN-OS 12.1.2 and later and PAN-OS 12.2.2 and later releases, + PAN-OS can obtain resolved IP addresses from a load-balanced DNS + server and use them in a policy match. However, this functionality + does not work as intended when the DNS cache reuse flag is enabled. + When the DNS cache reuse flag is enabled, the DNS resolution works as + if the load-balanced DNS flag (for an address object) is disabled. +
+
PAN-283028 +
+ When an existing template overrides the SD-WAN configuration followed + by a commit and push from Panorama to the firewall, the following + error occurs: BGP is invalid. AS number does not fit in 2 byte AS + format. This issue occurs because different AS formats are present on + Panorama and the firewall (the firewall configuration is generated by + the SD-WAN plugin). In hub-and-spoke topology, both the hub and branch + firewall must have the same AS format. In full mesh topology, all + firewalls must have the same AS format. +
+
PLUG-23656 +
+ In Software Firewall Licensed HSF environments, serial numbers linked + to stale entries can be manually released for reuse. This procedure + allows for the recovery of Software Firewall License credits when + virtual instances are deleted without being formally decommissioned. + For optimal resource management, it is recommended to utilize + Orchestration plugin workflows for VM operations rather than manual + intervention. +
+