This commit is contained in:
@@ -104,6 +104,105 @@
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-325120</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue affects PAN-OS 11.2.11</tt>
|
||||
</div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-12-known-and-addressed-issues/pan-os-11-2-12-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 11.2.12 Addressed Issues</a
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div dir="ltr" class="p">
|
||||
On PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms, certain
|
||||
PAN-OS versions may cause intermittent connectivity issues on Eth1/1
|
||||
SFP/RJ45 data port. Additionally, devices onboarded or managed via
|
||||
Eth1/1 lose call-home connectivity post-upgrade. The dedicated
|
||||
management port SFP or RJ45 are not affected.
|
||||
</div>
|
||||
<b class="ph b">Workaround</b>: Move the Eth1/1 connection to any other
|
||||
dataport (Eth1/2 to 1/9). Devices managed via Eth1/1 require an on-site
|
||||
administrator to manually move the connection from Eth1/1 to the
|
||||
dedicated management port. Devices managed via Eth1/1 require an on-site
|
||||
administrator to manually move the connection from Eth1/1 to the
|
||||
dedicated management port.
|
||||
<div dir="ltr" class="p">
|
||||
On the following platforms, PoE ports will not supply power. Ethernet
|
||||
traffic on PoE ports continues to function for devices that do not
|
||||
require inline power.
|
||||
</div>
|
||||
<ul id="panos-known-issues-11.2.11_ul-nhq_f3r_gjc" class="ul">
|
||||
<li dir="ltr" class="li">
|
||||
<div dir="ltr" class="p">
|
||||
Affected PoE ports on PA-415, PA-415-5G, PA-445: Eth1/6–Eth1/9
|
||||
</div>
|
||||
</li>
|
||||
<li dir="ltr" class="li">
|
||||
<div dir="ltr" class="p">
|
||||
Affected PoE ports on PA-455, PA-455-5G: Eth1/5–Eth1/8
|
||||
</div>
|
||||
</li>
|
||||
</ul>
|
||||
<b class="ph b">Workaround</b>: If power is needed from impacted PoE
|
||||
ports, downgrade to an unaffected PAN-OS version. See the
|
||||
<a
|
||||
class="xref"
|
||||
href="http://security.paloaltonetworks.com"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>May Security Advisory</a
|
||||
>
|
||||
for additional mitigations.
|
||||
<div class="p"><b class="ph b">All Affected PAN-OS Versions: </b></div>
|
||||
<ul id="panos-known-issues-11.2.11_ul-n5c_kjr_gjc" class="ul">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<b class="ph b">11.1: </b>11.1.10-h23, 11.1.10-h24, 11.1.10-h25,
|
||||
11.1.13-h4, 11.1.13-h5, 11.1.14
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<b class="ph b">11.2: </b>11.2.7-h12, 11.2.7-h13, 11.2.7-h14,
|
||||
11.2.10-h5, 11.2.10-h6, 11.2.10-h7, 11.2.11
|
||||
</li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-317755</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A selective push from Panorama to managed firewalls fail when plugin
|
||||
configurations reference certain Panorama settings, such as
|
||||
log-collector groups or access domains.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Perform a full push instead of a
|
||||
selective push as a temporary measure. Note that selective push
|
||||
attempts will continue to fail until you upgrade to the release that
|
||||
includes the fix.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
@@ -298,32 +397,6 @@
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254236</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
|
||||
Edge browsers results in dropped Client Hello packets when SSL/TLS
|
||||
handshake inspection is enabled.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Disable
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/inspect-ssl-tls-handshakes"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>SSL/TLS handshake inspection</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254108</b></div>
|
||||
@@ -433,6 +506,19 @@
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247728</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-1-known-and-addressed-issues/pan-os-11-2-1-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 11.2.1 Addressed Issues</a
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
@@ -678,7 +764,7 @@
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs">admin></span><span class="ph userinput hljs sql"> <span class="hljs-keyword">show</span> panorama-<span class="hljs-keyword">status</span></span></div></pre>
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
|
||||
<div class="p">
|
||||
Verify the <span class="ph systemoutput">Connected</span> status
|
||||
is <span class="ph systemoutput">no</span>.
|
||||
@@ -694,7 +780,7 @@
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs">admin></span><span class="ph userinput hljs nginx"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
|
||||
Reference in New Issue
Block a user