Add known issue reference files
Test and deploy / deploy (push) Successful in 38s

This commit is contained in:
2026-07-31 10:41:53 -05:00
parent a538c8959d
commit 5591362740
35 changed files with 56332 additions and 28 deletions
+38
View File
@@ -0,0 +1,38 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242777</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where running debug online diagnostics run on a 5G
supported PA-400 firewall models reported "Missing device on I2C bus"
errors and did not execute cellular modem diagnostic tests. This
occurred because the diagnostics script used an incorrect I2C device
list for the 5G supported PA-400 hardware variants and did not
recognize it as a cellular-capable platform. With this fix, the I2C
scan correctly reflects the 5G supported PA-400 hardware configuration
and cellular modem tests run as expected.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+840
View File
@@ -0,0 +1,840 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 34%" />
<col style="width: 66%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317755</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/pan-os/11-1/pan-os-release-notes/pan-os-11-1-16-known-and-addressed-issues/pan-os-11-1-16-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 11.1.16 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
A selective push from Panorama to managed firewalls fail when plugin
configurations reference certain Panorama settings, such as
log-collector groups or access domains.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314624</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/pan-os/11-1/pan-os-release-notes/pan-os-11-1-16-known-and-addressed-issues/pan-os-11-1-16-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 11.1.16 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
The
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process restarts when you attempt to dump the Host Information Profile
(HIP) database using the
<span class="ph codeph">debug user-id dump hip-profile-database</span>
command. This occurs while the firewall is actively processing HIP
reports, such as logouts or updates. The command initially hangs and
times out before the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process restarts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303959</b></div>
</td>
<td class="entry relcol">
<div class="p">
Traffic that is incorrectly identified as unknown-tcp/unknown-udp
eventually drops due to an App-ID resource limitation issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292202</b></div>
</td>
<td class="entry relcol">
<div class="p">
The system logs repeatedly displayed the alert
<span class="ph systemoutput"
>Clearing snmpd.log due to log overflow</span
>
due to the SNMP counters rolling over. This is a benign message and
does not impact device functionality.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289432 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Generating a certificate with the
<span class="ph codeph">block-private-key yes</span> command on
Panorama fails with the error:
</div>
<div class="p">
<span class="ph codeph"
>Could not get parameters for double encryption.</span
>
This occurred when the certificate was signed by an external
Certificate Authority (CA).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286848</b></div>
</td>
<td class="entry relcol">
<div class="p">
ECMP incorrectly balances sessions across links based on the
configured metric, which leads to an imbalance in traffic distribution
and results in traffic assignment shifting disproportionately to
routes with lower metrics.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286496</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
continue selections will function like a general URL-block action.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285894</b></div>
</td>
<td class="entry relcol">
<div class="p">
If the Preserve Pre-NAT feature is enabled, dataplane crashes may
occur, which could result in firewall reboots.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Disable the Preserve Pre-NAT feature
using the
<span class="ph userinput"
>set deviceconfig setting preserve-prenat-feature no</span
>
CLI command.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283429</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use custom certificates for the connection between Panorama
and a log collector, the automated renewal for the predefined
ElasticSearch certificates gets disrupted.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Remove the custom certificates before
the ElasticSearch certificates expire. This allows the system to
correctly identify and renew the predefined ElasticSearch
certificates. After the renewal is complete, re-install the custom
certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279415</b></div>
</td>
<td class="entry relcol">
<div class="p">
Service routes configured for a data plane interface might incorrectly
route traffic through the management plane interface instead. This
issue impacts Syslog and CRL status traffic when the service route
lacks a specific destination custom service route.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275047</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) After an upgrade,
the firewall is unable to send logs to the Strata Logging Service
(SLS) when using a specific proxy server, and the SSL connection
status displays as failed when attempting to forward logs through the
web proxy.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262556</b></div>
</td>
<td class="entry relcol">
<div class="p">
The ElasticSearch cluster health status might continue to remain
yellow for an extended period after upgrading to PAN-OS 11.1
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260851</b></div>
</td>
<td class="entry relcol">
<div class="p">
From the NGFW or Panorama CLI, you can override the existing
application tag even if Disable Override is enabled for the
application (<span class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Applications</span></span
>) tag.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254240</b></div>
</td>
<td class="entry relcol">
<div class="p">
In the event of an HSCI flap on an NGFW cluster node, traffic
reconvergence takes three to four seconds.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253963</b></div>
</td>
<td class="entry relcol">
<div class="p">
The auto commit job may take longer than expected to complete when the
Panorama management server is in Panorama or Log Collector mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251551</b></div>
</td>
<td class="entry relcol">
<div class="p">
When an NGFW cluster agent crashes and doesn't recover, leader
election will take approximately 45 seconds to begin and traffic
failover will occur during that time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250903</b></div>
</td>
<td class="entry relcol">
<div class="p">
In a congestion scenario on an HSCI port of an NGFW cluster node, the
QoS priorities of cross node traffic streams might be reversed if
you're using the default QoS profile with class1 to class8 set as high
to low.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247974</b></div>
</td>
<td class="entry relcol">
<div class="p">
LACP flap is expected during a device failover in an NGFW cluster due
to an L2 ctrld restart on the new leader node.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234015</b></div>
</td>
<td class="entry relcol">
<div class="p">
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224502</b></div>
</td>
<td class="entry relcol">
<div class="p">
The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
might take longer than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220180</b></div>
</td>
<td class="entry relcol">
<div class="p">
Configured botnet reports (<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">Botnet</span></span
>) are not generated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207733</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a DHCPv6 client is configured on HA Active/Passive firewalls, if
the DHCPv6 server goes down, after the lease time expires, the DHCPv6
client should enter SOLICIT state on both the Active and Passive
firewalls. Instead, the client is stuck in BOUND state with an IPv6
address having lease time 0 on the Passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207611</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a DHCPv6 client is configured on HA Active/Passive firewalls, the
Passive firewall sometimes crashes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207442</b></div>
</td>
<td class="entry relcol">
<div class="p">
For M-700 appliances in an active/passive high availability (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">High Availability</span></span
>) configuration, the
<span class="ph systemoutput">active-primary</span> HA peer
configuration sync to the
<span class="ph systemoutput">secondary-passive</span> HA peer may
fail. When the config sync fails, the job Results is
<span class="ph systemoutput">Successful</span>
(<span class="ph uicontrol">Tasks</span>), however the sync status on
the <span class="ph uicontrol">Dashboard</span> displays as
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Perform a local commit on the
<span class="ph systemoutput">active-primary</span> HA peer and then
synchronize the HA configuration.
</div>
<ol id="panos-known-issues-11.1.14_ol_aqy_kbp_qxb" class="ol">
<li class="li">
<div class="p">
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Log in to the Panorama web interface</a
>
of the <span class="ph systemoutput">active-primary</span> HA
peer.
</div>
</li>
<li class="li">
<div class="p">
Select <span class="ph uicontrol">Commit</span> and
<span class="ph uicontrol">Commit to Panorama</span>.
</div>
</li>
<li class="li">
<div class="p">
In the <span class="ph systemoutput">active-primary</span> HA peer
<span class="ph uicontrol">Dashboard</span>, click
<span class="ph uicontrol">Sync to Peer</span> in the High
Availability widget.
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207040</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you disable Advanced Routing, remove logical routers, and downgrade
from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
commits fail and SD-WAN devices on Panorama have no Virtual Router
name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206913</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a DHCPv6 client is configured on HA Active/Passive firewalls,
releasing the IPv6 address from the client (using Release in the UI or
using the
<span class="ph systemoutput"
>request dhcp client ipv6 release all</span
>
CLI command) releases the IPv6 address from the Active firewall, but
not the Passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206909</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Dedicated Log Collector is unable to reconnect to the Panorama
management server if the <span class="ph systemoutput">configd</span>
process crashes. This results in the Dedicated Log Collector losing
connectivity to Panorama despite the managed collector connection
<span class="ph systemoutput">Status</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Managed Collector</span></span
>) displaying <span class="ph systemoutput">connected</span> and the
managed colletor <span class="ph systemoutput">Health</span> status
displaying as healthy.
</div>
<div class="p">
This results in the local Panorama config and system logs not being
forwarded to the Dedicated Log Collector. Firewall log forwarding to
the disconnected Dedicated Log Collector is not impacted.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Restart the
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
Log Collector.
</div>
<ol id="panos-known-issues-11.1.14_ol_pdy_4bm_lvb" class="ol">
<li class="li">
<div class="p">
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Log in to the Dedicated Log Collector CLI</a
>.
</div>
</li>
<li class="li">
<div class="p">
Confirm the Dedicated Log Collector is disconnected from Panorama.
</div>
<!-- FM Dita Overlay for Code -->
<div class="code-wrap">
<pre
class="pre codeblock"
data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
<div class="p">
Verify the <span class="ph systemoutput">Connected</span> status
is <span class="ph systemoutput">no</span>.
</div>
</div>
</li>
<li class="li">
<div class="p">
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
</div>
<!-- FM Dita Overlay for Code -->
<div class="code-wrap">
<pre
class="pre codeblock"
data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197588</b></div>
</td>
<td class="entry relcol">
<div class="p">
The PAN-OS ACC (Application Command Center) does not display a widget
detailing statistics and data associated with vulnerability exploits
that have been detected using inline cloud analysis.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197419</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
<span class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">Interface</span
><span class="ph uicontrol">Ethernet</span></span
>, the power over Ethernet (PoE) ports do not display a
<span class="ph uicontrol">Tag</span> value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196758</b></div>
</td>
<td class="entry relcol">
<div class="p">
On the Panorama management server, pushing a configuration change to
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
configurations for SD-WAN as being edited or deleted despite no edits
or deletions being made when you
<span class="ph uicontrol">Preview Changes</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span
><span class="ph uicontrol">Edit Selections</span></span
>
or
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Commit and Push</span
><span class="ph uicontrol">Edit Selections</span></span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195968</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
prints an error depending on whether an interface type was selected on
the non-PoE port or not. If an interface type, such as tap, Layer 2,
or virtual wire, was selected before PoE was configured, the error
message will not include the interface name (eg. ethernet1/4). If an
interface type was not selected before PoE was configured, the error
message will include the interface name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194978</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
<span class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">Interface</span
><span class="ph uicontrol">Ethernet</span></span
>, hovering the mouse over a power over Ethernet (PoE)
<span class="ph uicontrol">Link State</span> icon does not display
link speed and link duplex details.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187685</b></div>
</td>
<td class="entry relcol">
<div class="p">
On the Panorama management server, the Template Status displays no
synchronization status (<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Managed Devices</span
><span class="ph uicontrol">Summary</span></span
>) after a bootstrapped firewall is successfully added to Panorama.
</div>
<div class="p">
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
successfully added to Panorama,
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>log in to the Panorama web interface</a
>
and select
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span></span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187407</b></div>
</td>
<td class="entry relcol">
<div class="p">
The configured Advanced Threat Prevention inline cloud analysis action
for a given model might not be honored under the following condition:
If the firewall is set to
<span class="ph uicontrol"
>Hold client request for category lookup </span
>and the action set to
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
been cleared, the first request for inline cloud analysis will be
bypassed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186283</b></div>
</td>
<td class="entry relcol">
<div class="p">
Templates appear out-of-sync on Panorama after successfully deploying
the CFT stack using the Panorama plugin for AWS.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Use
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span></span
>
to synchronize the templates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Scheduled report emails (<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">PDF Reports</span
><span class="ph uicontrol">Email Scheduler</span></span
>) are not emailed if:
</div>
<ul id="panos-known-issues-11.1.14_ul_bqh_5qx_rsb" class="ul">
<li class="li">
A scheduled report email contains a Report Group (<span
class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">PDF Reports</span
><span class="ph uicontrol">Report Group</span></span
>) which includes a SaaS Application Usage report.
</li>
<li class="li">
A scheduled report contains only a SaaS Application Usage Report.
</li>
</ul>
<div class="p">
<b class="ph b">Workaround:</b> To receive a scheduled report email
for all other PDF report types:
</div>
<ol id="panos-known-issues-11.1.14_ol_jgs_zqx_rsb" class="ol">
<li class="li">
Select
<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">PDF Reports</span
><span class="ph uicontrol">Report Groups</span></span
>
and remove all SaaS Application Usage reports from all Report
Groups.
</li>
<li class="li">
Select
<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">PDF Reports</span
><span class="ph uicontrol">Email Scheduler</span></span
>
and edit the scheduled report email that contains only a SaaS
Application Usage report. For the Recurrence, select
<span class="ph uicontrol">Disable</span> and click
<span class="ph uicontrol">OK</span>.
<div class="p">
Repeat this step for all scheduled report emails that contain only
a SaaS Application Usage report.
</div>
</li>
<li class="li">
<span class="ph uicontrol">Commit</span>.
<div class="p">
(<tt class="ph tt">Panorama managed firewalls</tt>) Select
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Commit and Push</span></span
>
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184406</b></div>
</td>
<td class="entry relcol">
<div class="p">
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
dmdb process to crash.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Contact customer support to stop the
dmdb process before adding a RAID disk pair to a M-700 appliance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Static IP addresses are not recognized when "and" operators are used
with IP CIDR range.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181933</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
all of the cards may not receive all of the updates and the mappings
for the clients may become out of sync, which causes the firewall to
not correctly populate the Source User column in the session logs.
</div>
</td>
</tr>
</tbody>
</table>
+763
View File
@@ -0,0 +1,763 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 34%" />
<col style="width: 66%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303959</b></div>
</td>
<td class="entry relcol">
<div class="p">
Traffic that is incorrectly identified as unknown-tcp/unknown-udp
eventually drops due to an App-ID resource limitation issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292202</b></div>
</td>
<td class="entry relcol">
<div class="p">
The system logs repeatedly displayed the alert
<span class="ph systemoutput"
>Clearing snmpd.log due to log overflow</span
>
due to the SNMP counters rolling over. This is a benign message and
does not impact device functionality.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289432 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Generating a certificate with the
<span class="ph codeph">block-private-key yes</span> command on
Panorama fails with the error:
</div>
<div class="p">
<span class="ph codeph"
>Could not get parameters for double encryption.</span
>
This occurred when the certificate was signed by an external
Certificate Authority (CA).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286848</b></div>
</td>
<td class="entry relcol">
<div class="p">
ECMP incorrectly balances sessions across links based on the
configured metric, which leads to an imbalance in traffic distribution
and results in traffic assignment shifting disproportionately to
routes with lower metrics.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286496</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
continue selections will function like a general URL-block action.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285894</b></div>
</td>
<td class="entry relcol">
<div class="p">
If the Preserve Pre-NAT feature is enabled, dataplane crashes may
occur, which could result in firewall reboots.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Disable the Preserve Pre-NAT feature
using the
<span class="ph userinput"
>set deviceconfig setting preserve-prenat-feature no</span
>
CLI command.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283429</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use custom certificates for the connection between Panorama
and a log collector, the automated renewal for the predefined
ElasticSearch certificates gets disrupted.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Remove the custom certificates before
the ElasticSearch certificates expire. This allows the system to
correctly identify and renew the predefined ElasticSearch
certificates. After the renewal is complete, re-install the custom
certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279415</b></div>
</td>
<td class="entry relcol">
<div class="p">
Service routes configured for a data plane interface might incorrectly
route traffic through the management plane interface instead. This
issue impacts Syslog and CRL status traffic when the service route
lacks a specific destination custom service route.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275047</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) After an upgrade,
the firewall is unable to send logs to the Strata Logging Service
(SLS) when using a specific proxy server, and the SSL connection
status displays as failed when attempting to forward logs through the
web proxy.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262556</b></div>
</td>
<td class="entry relcol">
<div class="p">
The ElasticSearch cluster health status might continue to remain
yellow for an extended period after upgrading to PAN-OS 11.1
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260851</b></div>
</td>
<td class="entry relcol">
<div class="p">
From the NGFW or Panorama CLI, you can override the existing
application tag even if Disable Override is enabled for the
application (<span class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Applications</span></span
>) tag.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254240</b></div>
</td>
<td class="entry relcol">
<div class="p">
In the event of an HSCI flap on an NGFW cluster node, traffic
reconvergence takes three to four seconds.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253963</b></div>
</td>
<td class="entry relcol">
<div class="p">
The auto commit job may take longer than expected to complete when the
Panorama management server is in Panorama or Log Collector mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251551</b></div>
</td>
<td class="entry relcol">
<div class="p">
When an NGFW cluster agent crashes and doesn't recover, leader
election will take approximately 45 seconds to begin and traffic
failover will occur during that time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250903</b></div>
</td>
<td class="entry relcol">
<div class="p">
In a congestion scenario on an HSCI port of an NGFW cluster node, the
QoS priorities of cross node traffic streams might be reversed if
you're using the default QoS profile with class1 to class8 set as high
to low.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247974</b></div>
</td>
<td class="entry relcol">
<div class="p">
LACP flap is expected during a device failover in an NGFW cluster due
to an L2 ctrld restart on the new leader node.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234015</b></div>
</td>
<td class="entry relcol">
<div class="p">
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224502</b></div>
</td>
<td class="entry relcol">
<div class="p">
The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
might take longer than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220180</b></div>
</td>
<td class="entry relcol">
<div class="p">
Configured botnet reports (<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">Botnet</span></span
>) are not generated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207733</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a DHCPv6 client is configured on HA Active/Passive firewalls, if
the DHCPv6 server goes down, after the lease time expires, the DHCPv6
client should enter SOLICIT state on both the Active and Passive
firewalls. Instead, the client is stuck in BOUND state with an IPv6
address having lease time 0 on the Passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207611</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a DHCPv6 client is configured on HA Active/Passive firewalls, the
Passive firewall sometimes crashes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207442</b></div>
</td>
<td class="entry relcol">
<div class="p">
For M-700 appliances in an active/passive high availability (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">High Availability</span></span
>) configuration, the
<span class="ph systemoutput">active-primary</span> HA peer
configuration sync to the
<span class="ph systemoutput">secondary-passive</span> HA peer may
fail. When the config sync fails, the job Results is
<span class="ph systemoutput">Successful</span>
(<span class="ph uicontrol">Tasks</span>), however the sync status on
the <span class="ph uicontrol">Dashboard</span> displays as
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Perform a local commit on the
<span class="ph systemoutput">active-primary</span> HA peer and then
synchronize the HA configuration.
</div>
<ol id="panos-known-issues-11.1.16_ol_aqy_kbp_qxb" class="ol">
<li class="li">
<div class="p">
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Log in to the Panorama web interface</a
>
of the <span class="ph systemoutput">active-primary</span> HA
peer.
</div>
</li>
<li class="li">
<div class="p">
Select <span class="ph uicontrol">Commit</span> and
<span class="ph uicontrol">Commit to Panorama</span>.
</div>
</li>
<li class="li">
<div class="p">
In the <span class="ph systemoutput">active-primary</span> HA peer
<span class="ph uicontrol">Dashboard</span>, click
<span class="ph uicontrol">Sync to Peer</span> in the High
Availability widget.
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207040</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you disable Advanced Routing, remove logical routers, and downgrade
from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
commits fail and SD-WAN devices on Panorama have no Virtual Router
name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206913</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a DHCPv6 client is configured on HA Active/Passive firewalls,
releasing the IPv6 address from the client (using Release in the UI or
using the
<span class="ph systemoutput"
>request dhcp client ipv6 release all</span
>
CLI command) releases the IPv6 address from the Active firewall, but
not the Passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206909</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Dedicated Log Collector is unable to reconnect to the Panorama
management server if the <span class="ph systemoutput">configd</span>
process crashes. This results in the Dedicated Log Collector losing
connectivity to Panorama despite the managed collector connection
<span class="ph systemoutput">Status</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Managed Collector</span></span
>) displaying <span class="ph systemoutput">connected</span> and the
managed colletor <span class="ph systemoutput">Health</span> status
displaying as healthy.
</div>
<div class="p">
This results in the local Panorama config and system logs not being
forwarded to the Dedicated Log Collector. Firewall log forwarding to
the disconnected Dedicated Log Collector is not impacted.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Restart the
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
Log Collector.
</div>
<ol id="panos-known-issues-11.1.16_ol_pdy_4bm_lvb" class="ol">
<li class="li">
<div class="p">
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Log in to the Dedicated Log Collector CLI</a
>.
</div>
</li>
<li class="li">
<div class="p">
Confirm the Dedicated Log Collector is disconnected from Panorama.
</div>
<!-- FM Dita Overlay for Code -->
<div class="code-wrap">
<pre
class="pre codeblock"
data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
<div class="p">
Verify the <span class="ph systemoutput">Connected</span> status
is <span class="ph systemoutput">no</span>.
</div>
</div>
</li>
<li class="li">
<div class="p">
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
</div>
<!-- FM Dita Overlay for Code -->
<div class="code-wrap">
<pre
class="pre codeblock"
data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197588</b></div>
</td>
<td class="entry relcol">
<div class="p">
The PAN-OS ACC (Application Command Center) does not display a widget
detailing statistics and data associated with vulnerability exploits
that have been detected using inline cloud analysis.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197419</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
<span class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">Interface</span
><span class="ph uicontrol">Ethernet</span></span
>, the power over Ethernet (PoE) ports do not display a
<span class="ph uicontrol">Tag</span> value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196758</b></div>
</td>
<td class="entry relcol">
<div class="p">
On the Panorama management server, pushing a configuration change to
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
configurations for SD-WAN as being edited or deleted despite no edits
or deletions being made when you
<span class="ph uicontrol">Preview Changes</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span
><span class="ph uicontrol">Edit Selections</span></span
>
or
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Commit and Push</span
><span class="ph uicontrol">Edit Selections</span></span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195968</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
prints an error depending on whether an interface type was selected on
the non-PoE port or not. If an interface type, such as tap, Layer 2,
or virtual wire, was selected before PoE was configured, the error
message will not include the interface name (eg. ethernet1/4). If an
interface type was not selected before PoE was configured, the error
message will include the interface name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194978</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
<span class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">Interface</span
><span class="ph uicontrol">Ethernet</span></span
>, hovering the mouse over a power over Ethernet (PoE)
<span class="ph uicontrol">Link State</span> icon does not display
link speed and link duplex details.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187685</b></div>
</td>
<td class="entry relcol">
<div class="p">
On the Panorama management server, the Template Status displays no
synchronization status (<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Managed Devices</span
><span class="ph uicontrol">Summary</span></span
>) after a bootstrapped firewall is successfully added to Panorama.
</div>
<div class="p">
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
successfully added to Panorama,
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>log in to the Panorama web interface</a
>
and select
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span></span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187407</b></div>
</td>
<td class="entry relcol">
<div class="p">
The configured Advanced Threat Prevention inline cloud analysis action
for a given model might not be honored under the following condition:
If the firewall is set to
<span class="ph uicontrol"
>Hold client request for category lookup </span
>and the action set to
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
been cleared, the first request for inline cloud analysis will be
bypassed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186283</b></div>
</td>
<td class="entry relcol">
<div class="p">
Templates appear out-of-sync on Panorama after successfully deploying
the CFT stack using the Panorama plugin for AWS.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Use
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span></span
>
to synchronize the templates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Scheduled report emails (<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">PDF Reports</span
><span class="ph uicontrol">Email Scheduler</span></span
>) are not emailed if:
</div>
<ul id="panos-known-issues-11.1.16_ul_bqh_5qx_rsb" class="ul">
<li class="li">
A scheduled report email contains a Report Group (<span
class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">PDF Reports</span
><span class="ph uicontrol">Report Group</span></span
>) which includes a SaaS Application Usage report.
</li>
<li class="li">
A scheduled report contains only a SaaS Application Usage Report.
</li>
</ul>
<div class="p">
<b class="ph b">Workaround:</b> To receive a scheduled report email
for all other PDF report types:
</div>
<ol id="panos-known-issues-11.1.16_ol_jgs_zqx_rsb" class="ol">
<li class="li">
Select
<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">PDF Reports</span
><span class="ph uicontrol">Report Groups</span></span
>
and remove all SaaS Application Usage reports from all Report
Groups.
</li>
<li class="li">
Select
<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">PDF Reports</span
><span class="ph uicontrol">Email Scheduler</span></span
>
and edit the scheduled report email that contains only a SaaS
Application Usage report. For the Recurrence, select
<span class="ph uicontrol">Disable</span> and click
<span class="ph uicontrol">OK</span>.
<div class="p">
Repeat this step for all scheduled report emails that contain only
a SaaS Application Usage report.
</div>
</li>
<li class="li">
<span class="ph uicontrol">Commit</span>.
<div class="p">
(<tt class="ph tt">Panorama managed firewalls</tt>) Select
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Commit and Push</span></span
>
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184406</b></div>
</td>
<td class="entry relcol">
<div class="p">
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
dmdb process to crash.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Contact customer support to stop the
dmdb process before adding a RAID disk pair to a M-700 appliance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Static IP addresses are not recognized when "and" operators are used
with IP CIDR range.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181933</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
all of the cards may not receive all of the updates and the mappings
for the clients may become out of sync, which causes the firewall to
not correctly populate the Source User column in the session logs.
</div>
</td>
</tr>
</tbody>
</table>
+114 -28
View File
@@ -104,6 +104,105 @@
</td> </td>
</tr> </tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-325120</b></div>
<div class="p">
<tt class="ph tt">This issue affects PAN-OS 11.2.11</tt>
</div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-12-known-and-addressed-issues/pan-os-11-2-12-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 11.2.12 Addressed Issues</a
>
</div>
</td>
<td class="entry relcol">
<div dir="ltr" class="p">
On PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms, certain
PAN-OS versions may cause intermittent connectivity issues on Eth1/1
SFP/RJ45 data port. Additionally, devices onboarded or managed via
Eth1/1 lose call-home connectivity post-upgrade. The dedicated
management port SFP or RJ45 are not affected.
</div>
<b class="ph b">Workaround</b>: Move the Eth1/1 connection to any other
dataport (Eth1/2 to 1/9). Devices managed via Eth1/1 require an on-site
administrator to manually move the connection from Eth1/1 to the
dedicated management port. Devices managed via Eth1/1 require an on-site
administrator to manually move the connection from Eth1/1 to the
dedicated management port.
<div dir="ltr" class="p">
On the following platforms, PoE ports will not supply power. Ethernet
traffic on PoE ports continues to function for devices that do not
require inline power.
</div>
<ul id="panos-known-issues-11.2.11_ul-nhq_f3r_gjc" class="ul">
<li dir="ltr" class="li">
<div dir="ltr" class="p">
Affected PoE ports on PA-415, PA-415-5G, PA-445: Eth1/6Eth1/9
</div>
</li>
<li dir="ltr" class="li">
<div dir="ltr" class="p">
Affected PoE ports on PA-455, PA-455-5G: Eth1/5Eth1/8
</div>
</li>
</ul>
<b class="ph b">Workaround</b>: If power is needed from impacted PoE
ports, downgrade to an unaffected PAN-OS version. See the
<a
class="xref"
href="http://security.paloaltonetworks.com"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>May Security Advisory</a
>
for additional mitigations.
<div class="p"><b class="ph b">All Affected PAN-OS Versions: </b></div>
<ul id="panos-known-issues-11.2.11_ul-n5c_kjr_gjc" class="ul">
<li class="li">
<div class="p">
<b class="ph b">11.1: </b>11.1.10-h23, 11.1.10-h24, 11.1.10-h25,
11.1.13-h4, 11.1.13-h5, 11.1.14
</div>
</li>
<li class="li">
<b class="ph b">11.2: </b>11.2.7-h12, 11.2.7-h13, 11.2.7-h14,
11.2.10-h5, 11.2.10-h6, 11.2.10-h7, 11.2.11
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317755</b></div>
</td>
<td class="entry relcol">
<div class="p">
A selective push from Panorama to managed firewalls fail when plugin
configurations reference certain Panorama settings, such as
log-collector groups or access domains.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Perform a full push instead of a
selective push as a temporary measure. Note that selective push
attempts will continue to fail until you upgrade to the release that
includes the fix.
</div>
</td>
</tr>
<tr class="row"> <tr class="row">
<td class="entry"> <td class="entry">
<div class="p"><b class="ph b">PAN-308564</b></div> <div class="p"><b class="ph b">PAN-308564</b></div>
@@ -298,32 +397,6 @@
</td> </td>
</tr> </tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254236</b></div>
</td>
<td class="entry relcol">
<div class="p">
TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
Edge browsers results in dropped Client Hello packets when SSL/TLS
handshake inspection is enabled.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Disable
<a
class="xref"
href="https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/inspect-ssl-tls-handshakes"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>SSL/TLS handshake inspection</a
>.
</div>
</td>
</tr>
<tr class="row rowsep"> <tr class="row rowsep">
<td class="entry"> <td class="entry">
<div class="p"><b class="ph b">PAN-254108</b></div> <div class="p"><b class="ph b">PAN-254108</b></div>
@@ -433,6 +506,19 @@
<tr class="row"> <tr class="row">
<td class="entry"> <td class="entry">
<div class="p"><b class="ph b">PAN-247728</b></div> <div class="p"><b class="ph b">PAN-247728</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-1-known-and-addressed-issues/pan-os-11-2-1-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 11.2.1 Addressed Issues</a
>
</div>
</td> </td>
<td class="entry relcol"> <td class="entry relcol">
<div class="p"> <div class="p">
@@ -678,7 +764,7 @@
<pre <pre
class="pre codeblock" class="pre codeblock"
data-label="PRE CODEBLOCK" data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs">admin&gt;</span><span class="ph userinput hljs sql"> <span class="hljs-keyword">show</span> panorama-<span class="hljs-keyword">status</span></span></div></pre> ><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
<div class="p"> <div class="p">
Verify the <span class="ph systemoutput">Connected</span> status Verify the <span class="ph systemoutput">Connected</span> status
is <span class="ph systemoutput">no</span>. is <span class="ph systemoutput">no</span>.
@@ -694,7 +780,7 @@
<pre <pre
class="pre codeblock" class="pre codeblock"
data-label="PRE CODEBLOCK" data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs">admin&gt;</span><span class="ph userinput hljs nginx"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre> ><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
</div> </div>
</li> </li>
</ol> </ol>
+880
View File
@@ -0,0 +1,880 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 34%" />
<col style="width: 66%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6271</b></div>
</td>
<td class="entry relcol">
<div class="p">
A WildFire cluster node that has been configured with an IPv6
management port might not display the signature status when using the
following CLI:
<span class="ph codeph"
>show wildfire global signature-status sha256 equal
&lt;SHA_256_Value&gt;</span
>
</div>
<div class="p">
<b class="ph b">Workaround:</b> Gracefully restart the affected
Wildfire cluster nodes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6259</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a WildFire cluster node configured as a server or worker node is
rebooted, issuing the CLI command,
<span class="ph codeph">global sample-status</span> does not update
the samples processed list on the active controller and non-server
worker nodes.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Gracefully restart the affected
WildFire active controller and passive controller in the cluster.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6270</b></div>
</td>
<td class="entry relcol">
<div class="p">
The WildFire cluster server and worker nodes might disconnect from the
Wildfire cluster management network, resulting in a notifier process
exit on WildFire cluster controllers.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Gracefully restart the WildFire
cluster node where the process exit occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6222</b></div>
</td>
<td class="entry relcol">
<div class="p">
When WildFire secure cluster communication is enabled using a custom
DNS, the cluster formation might fail due to cluster management
communication issues.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Do not configure a custom DNS when
WildFire secure cluster communication is enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6176</b></div>
</td>
<td class="entry relcol">
<div class="p">
When Panorama is used to manage a WildFire cluster, switchover
functionality for active and passive controller roles is not
available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317755</b></div>
</td>
<td class="entry relcol">
<div class="p">
A selective push from Panorama to managed firewalls fail when plugin
configurations reference certain Panorama settings, such as
log-collector groups or access domains.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Perform a full push instead of a
selective push as a temporary measure. Note that selective push
attempts will continue to fail until you upgrade to the release that
includes the fix.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308564</b></div>
</td>
<td class="entry relcol">
<div class="p">
Packets are dropped on SD-WAN interfaces if they require fragmentation
for an interface but have the
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
results in unexpected packet drops. This affects client to server
sessions when using SD-WAN for NGFW.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
set (<span class="ph userinput"
>debug dataplane set ip4-ignore-df yes</span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
Strata Logging Service (SLS) log-forwarding streams intermittently
show as inactive. When checking the status of log-forwarding
connections, one or more streams are reported as inactive. Restarting
the <span class="ph codeph">log-receiver</span> process temporarily
resolves the issue, but the streams become inactive again after
approximately 1-2 hours. This intermittent inactivity results in log
loss.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295645</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a WildFire cluster is configured centrally using Panorama, it
initiates a series of processes, including a software install and
reboot, in an order that will leave the resulting WildFire cluster in
an unusable state.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288525</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the Enterprise DLP data filtering profile is configured with a
<span class="ph uicontrol">Block</span> action and is used in
conjunction with Advanced Threat Prevention, which is configured with
an action of <span class="ph uicontrol">reset-both</span>,
<span class="ph uicontrol">reset-server</span>,
<span class="ph uicontrol">reset-client</span>, or
<span class="ph uicontrol">drop</span> for the
<span class="ph uicontrol">HTTP Command and Control detector</span>,
Dropbox file uploads that exceed the maximum configured file size
action will fail.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Configure the Advanced Threat
Prevention Inline Cloud analysis (<span class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Security Profiles</span
><span class="ph uicontrol">Anti-Spyware</span></span
>) action for the HTTP Command and Control detector to
<span class="ph uicontrol">alert</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285061</b></div>
</td>
<td class="entry relcol">
<div class="p">
When Enterprise DLP is enabled, file uploads might unexpectedly fail
when 100 continue response is received from the server during file
uploads.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284700</b></div>
</td>
<td class="entry relcol">
<div class="p">
File downloads for content encoded with zstd (Zstandard), such as
specific content from box.com, fail when using Enterprise DLP because
zstd decompression is not supported in PAN-OS.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283429</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use custom certificates for the connection between Panorama
and a log collector, the automated renewal for the predefined
ElasticSearch certificates gets disrupted.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Remove the custom certificates before
the ElasticSearch certificates expire. This allows the system to
correctly identify and renew the predefined ElasticSearch
certificates. After the renewal is complete, re-install the custom
certificates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260851</b></div>
</td>
<td class="entry relcol">
<div class="p">
From the NGFW or Panorama CLI, you can override the existing
application tag even if Disable Override is enabled for the
application (<span class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Applications</span></span
>) tag.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260212</b></div>
</td>
<td class="entry relcol">
<div class="p">
When viewing <span class="ph uicontrol">Applications</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Applications</span></span
>), child App-IDs may be listed under the incorrect container App-ID.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259853</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the DHCP server is enabled for GlobalProtect, the commit error
message is not properly displayed when
<span class="ph uicontrol">Any</span> is selected as the source
interface in the service router configuration (
<span class="ph menucascade"
><span class="ph uicontrol">Device</span
><span class="ph uicontrol">Setup</span
><span class="ph uicontrol">Service</span
><span class="ph uicontrol"></span
><span class="ph uicontrol"
>Service Router Configuration</span
></span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259423</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the GlobalProtect DHCP feature is enabled with two primary DHCP
servers on the GlobalProtect gateway, the gpsvc gets stuck during
renewal and after HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254108</b></div>
</td>
<td class="entry relcol">
<div class="p">
when upgrading or downgrading a Panorama management server (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Software</span></span
>), managed device (<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Device Deployment</span
><span class="ph uicontrol">Software</span></span
>), or standalone firewall (<span class="ph menucascade"
><span class="ph uicontrol">Device</span
><span class="ph uicontrol">Software</span></span
>), <span class="ph uicontrol">Base Releases</span> and
<span class="ph uicontrol">Preferred Releases</span> settings are
checked (enabled) by default and cause no PAN-OS software images to
display.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Uncheck (disable)
<span class="ph uicontrol">Base Releases</span> or
<span class="ph uicontrol">Preferred Releases</span> to display either
the available base PAN-OS or preferred PAN-OS releases available to
download and install.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253963</b></div>
</td>
<td class="entry relcol">
<div class="p">
The auto commit job may take longer than expected to complete when the
Panorama management server is in Panorama or Log Collector mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-252661</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you change the service route of gp-ip-mgmt in
<b class="ph b"
>Device &gt; Setup &gt; Services &gt; Service Features &gt;
gp-ip-mgmt</b
>
and <b class="ph b">Commit</b>, the change wont take effect.
gp-ip-mgmt continues to use the last committed service route.
</div>
<div class="p">
<b class="ph b">Workaround:</b> After you change the service route
interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
gateway, click <b class="ph b">OK </b>to save the configuration, and
<b class="ph b">Commit </b>the changes. This commit will include the
service route change.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250246</b></div>
</td>
<td class="entry relcol">
<div class="p">
Panorama and the firewall display inconsistent IP addresses for
dynamic address group members after manually syncing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250062</b></div>
</td>
<td class="entry relcol">
<div class="p">
Device telemetry might fail at configured intervals due to bundle
generation issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248836</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Advanced DNS Security trial license and trial license information
cannot be activated and viewed, respectively, on a managed firewall
(with expired or active status) from Panorama. These tasks can only be
performed on the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247728</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-1-known-and-addressed-issues/pan-os-11-2-1-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 11.2.1 Addressed Issues</a
>
</div>
</td>
<td class="entry relcol">
<div class="p">
When Advanced Routing is enabled, IP multicast is not supported. An
upcoming version will provide support for this feature. Customers who
have multicast configured or who plan to deploy multicast routing
should not upgrade to 11.2.0. Additionally, when Advanced Routing is
enabled, the BGP dampening configuration isn't applied to any peers or
peer group; the configuration is preserved but has no effect on BGP.
Customers can use BGP even if they have applied a Dampening profile to
a specific set of peers. The issue doesn't affect any other BGP
features.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241994</b></div>
</td>
<td class="entry relcol">
<div class="p">
The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
Palo Alto Networks recommends that you upgrade your ESXi version if it
is less than 6.7 U2. For more information, see the
<a
class="xref"
href="https://kb.vmware.com/s/article/2007240"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
rel="nofollow"
>compatibility matrix</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239612</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
agent doesn't work.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237106</b></div>
</td>
<td class="entry relcol">
<div class="p">
LSVPN satellite certificates may be generated with serial numbers
exceeding 40 hexadecimal characters. This causes certificate
revocation and deletion operations to fail with the following error
messages:
</div>
<ul id="pan_os_11_2_12_known_issues_ul-hby_2gs_jjc" class="ul">
<li class="li">
<span class="ph systemoutput"
>db-serialno can be at most 40 characters</span
>
</li>
<li class="li">
<span class="ph systemoutput">db-serialno is invalid</span>
</li>
</ul>
<b class="ph b">Workaround:</b>
<div class="p">
To resolve this issue, use the following CLI commands with the LSVPN
satellite serial number to manually delete or revoke the affected
certificates:
</div>
<div class="p">
<b class="ph b">Delete certificate information</b>:<span
class="ph userinput"
>delete sslmgr-store certificate-info portal name
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname">&lt;satellite_serial&gt;</var></span
>
</div>
<div class="p">
<b class="ph b">Revoke satellite certificates</b>:<span
class="ph userinput"
>delete sslmgr-store satellite-info-revoke-certificate portal
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname"
>&lt;list_of_satellite_serials&gt;</var
></span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-236649</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you change the configuration of a firewall acting as a PPPoEv4 or
PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
and route table for an inherited configuration with dynamic-identifier
or client remain visible. Old routes also remain visible for an
inherited interface when you execute the CLI command,
<span class="ph userinput">show interface all</span>.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Unconfigure and configure the
Inherited Interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234015</b></div>
</td>
<td class="entry relcol">
<div class="p">
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207442</b></div>
</td>
<td class="entry relcol">
<div class="p">
For M-700 appliances in an active/passive high availability (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">High Availability</span></span
>) configuration, the
<span class="ph systemoutput">active-primary</span> HA peer
configuration sync to the
<span class="ph systemoutput">secondary-passive</span> HA peer may
fail. When the config sync fails, the job Results is
<span class="ph systemoutput">Successful</span>
(<span class="ph uicontrol">Tasks</span>), however the sync status on
the <span class="ph uicontrol">Dashboard</span> displays as
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Perform a local commit on the
<span class="ph systemoutput">active-primary</span> HA peer and then
synchronize the HA configuration.
</div>
<ol id="pan_os_11_2_12_known_issues_ol-iby_2gs_jjc" class="ol">
<li class="li">
<div class="p">
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Log in to the Panorama web interface</a
>
of the <span class="ph systemoutput">active-primary</span> HA
peer.
</div>
</li>
<li class="li">
<div class="p">
Select <span class="ph uicontrol">Commit</span> and
<span class="ph uicontrol">Commit to Panorama</span>.
</div>
</li>
<li class="li">
<div class="p">
In the <span class="ph systemoutput">active-primary</span> HA peer
<span class="ph uicontrol">Dashboard</span>, click
<span class="ph uicontrol">Sync to Peer</span> in the High
Availability widget.
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206909</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Dedicated Log Collector is unable to reconnect to the Panorama
management server if the <span class="ph systemoutput">configd</span>
process crashes. This results in the Dedicated Log Collector losing
connectivity to Panorama despite the managed collector connection
<span class="ph systemoutput">Status</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Managed Collector</span></span
>) displaying <span class="ph systemoutput">connected</span> and the
managed colletor <span class="ph systemoutput">Health</span> status
displaying as healthy.
</div>
<div class="p">
This results in the local Panorama config and system logs not being
forwarded to the Dedicated Log Collector. Firewall log forwarding to
the disconnected Dedicated Log Collector is not impacted.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Restart the
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
Log Collector.
</div>
<ol id="pan_os_11_2_12_known_issues_ol-jby_2gs_jjc" class="ol">
<li class="li">
<div class="p">
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Log in to the Dedicated Log Collector CLI</a
>.
</div>
</li>
<li class="li">
<div class="p">
Confirm the Dedicated Log Collector is disconnected from Panorama.
</div>
<!-- FM Dita Overlay for Code -->
<div class="code-wrap">
<pre
class="pre codeblock"
data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
<div class="p">
Verify the <span class="ph systemoutput">Connected</span> status
is <span class="ph systemoutput">no</span>.
</div>
</div>
</li>
<li class="li">
<div class="p">
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
</div>
<!-- FM Dita Overlay for Code -->
<div class="code-wrap">
<pre
class="pre codeblock"
data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197588</b></div>
</td>
<td class="entry relcol">
<div class="p">
The PAN-OS ACC (Application Command Center) does not display a widget
detailing statistics and data associated with vulnerability exploits
that have been detected using inline cloud analysis.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197419</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
<span class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">Interface</span
><span class="ph uicontrol">Ethernet</span></span
>, the power over Ethernet (PoE) ports do not display a
<span class="ph uicontrol">Tag</span> value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196758</b></div>
</td>
<td class="entry relcol">
<div class="p">
On the Panorama management server, pushing a configuration change to
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
configurations for SD-WAN as being edited or deleted despite no edits
or deletions being made when you
<span class="ph uicontrol">Preview Changes</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span
><span class="ph uicontrol">Edit Selections</span></span
>
or
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Commit and Push</span
><span class="ph uicontrol">Edit Selections</span></span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195968</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
prints an error depending on whether an interface type was selected on
the non-PoE port or not. If an interface type, such as tap, Layer 2,
or virtual wire, was selected before PoE was configured, the error
message will not include the interface name (eg. ethernet1/4). If an
interface type was not selected before PoE was configured, the error
message will include the interface name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187685</b></div>
</td>
<td class="entry relcol">
<div class="p">
On the Panorama management server, the Template Status displays no
synchronization status (<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Managed Devices</span
><span class="ph uicontrol">Summary</span></span
>) after a bootstrapped firewall is successfully added to Panorama.
</div>
<div class="p">
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
successfully added to Panorama,
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>log in to the Panorama web interface</a
>
and select
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span></span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187407</b></div>
</td>
<td class="entry relcol">
<div class="p">
The configured Advanced Threat Prevention inline cloud analysis action
for a given model might not be honored under the following condition:
If the firewall is set to
<span class="ph uicontrol"
>Hold client request for category lookup </span
>and the action set to
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
been cleared, the first request for inline cloud analysis will be
bypassed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184406</b></div>
</td>
<td class="entry relcol">
<div class="p">
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
dmdb process to crash.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Contact customer support to stop the
dmdb process before adding a RAID disk pair to a M-700 appliance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Static IP addresses are not recognized when "and" operators are used
with IP CIDR range.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181933</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
all of the cards may not receive all of the updates and the mappings
for the clients may become out of sync, which causes the firewall to
not correctly populate the Source User column in the session logs.
</div>
</td>
</tr>
</tbody>
</table>
+880
View File
@@ -0,0 +1,880 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 34%" />
<col style="width: 66%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6271</b></div>
</td>
<td class="entry relcol">
<div class="p">
A WildFire cluster node that has been configured with an IPv6
management port might not display the signature status when using the
following CLI:
<span class="ph codeph"
>show wildfire global signature-status sha256 equal
&lt;SHA_256_Value&gt;</span
>
</div>
<div class="p">
<b class="ph b">Workaround:</b> Gracefully restart the affected
Wildfire cluster nodes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6259</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a WildFire cluster node configured as a server or worker node is
rebooted, issuing the CLI command,
<span class="ph codeph">global sample-status</span> does not update
the samples processed list on the active controller and non-server
worker nodes.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Gracefully restart the affected
WildFire active controller and passive controller in the cluster.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6270</b></div>
</td>
<td class="entry relcol">
<div class="p">
The WildFire cluster server and worker nodes might disconnect from the
Wildfire cluster management network, resulting in a notifier process
exit on WildFire cluster controllers.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Gracefully restart the WildFire
cluster node where the process exit occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6222</b></div>
</td>
<td class="entry relcol">
<div class="p">
When WildFire secure cluster communication is enabled using a custom
DNS, the cluster formation might fail due to cluster management
communication issues.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Do not configure a custom DNS when
WildFire secure cluster communication is enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">WF500-6176</b></div>
</td>
<td class="entry relcol">
<div class="p">
When Panorama is used to manage a WildFire cluster, switchover
functionality for active and passive controller roles is not
available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-317755</b></div>
</td>
<td class="entry relcol">
<div class="p">
A selective push from Panorama to managed firewalls fail when plugin
configurations reference certain Panorama settings, such as
log-collector groups or access domains.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Perform a full push instead of a
selective push as a temporary measure. Note that selective push
attempts will continue to fail until you upgrade to the release that
includes the fix.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308564</b></div>
</td>
<td class="entry relcol">
<div class="p">
Packets are dropped on SD-WAN interfaces if they require fragmentation
for an interface but have the
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
results in unexpected packet drops. This affects client to server
sessions when using SD-WAN for NGFW.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
set (<span class="ph userinput"
>debug dataplane set ip4-ignore-df yes</span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
Strata Logging Service (SLS) log-forwarding streams intermittently
show as inactive. When checking the status of log-forwarding
connections, one or more streams are reported as inactive. Restarting
the <span class="ph codeph">log-receiver</span> process temporarily
resolves the issue, but the streams become inactive again after
approximately 1-2 hours. This intermittent inactivity results in log
loss.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295645</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a WildFire cluster is configured centrally using Panorama, it
initiates a series of processes, including a software install and
reboot, in an order that will leave the resulting WildFire cluster in
an unusable state.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288525</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the Enterprise DLP data filtering profile is configured with a
<span class="ph uicontrol">Block</span> action and is used in
conjunction with Advanced Threat Prevention, which is configured with
an action of <span class="ph uicontrol">reset-both</span>,
<span class="ph uicontrol">reset-server</span>,
<span class="ph uicontrol">reset-client</span>, or
<span class="ph uicontrol">drop</span> for the
<span class="ph uicontrol">HTTP Command and Control detector</span>,
Dropbox file uploads that exceed the maximum configured file size
action will fail.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Configure the Advanced Threat
Prevention Inline Cloud analysis (<span class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Security Profiles</span
><span class="ph uicontrol">Anti-Spyware</span></span
>) action for the HTTP Command and Control detector to
<span class="ph uicontrol">alert</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285061</b></div>
</td>
<td class="entry relcol">
<div class="p">
When Enterprise DLP is enabled, file uploads might unexpectedly fail
when 100 continue response is received from the server during file
uploads.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284700</b></div>
</td>
<td class="entry relcol">
<div class="p">
File downloads for content encoded with zstd (Zstandard), such as
specific content from box.com, fail when using Enterprise DLP because
zstd decompression is not supported in PAN-OS.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283429</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use custom certificates for the connection between Panorama
and a log collector, the automated renewal for the predefined
ElasticSearch certificates gets disrupted.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Remove the custom certificates before
the ElasticSearch certificates expire. This allows the system to
correctly identify and renew the predefined ElasticSearch
certificates. After the renewal is complete, re-install the custom
certificates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260851</b></div>
</td>
<td class="entry relcol">
<div class="p">
From the NGFW or Panorama CLI, you can override the existing
application tag even if Disable Override is enabled for the
application (<span class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Applications</span></span
>) tag.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260212</b></div>
</td>
<td class="entry relcol">
<div class="p">
When viewing <span class="ph uicontrol">Applications</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Applications</span></span
>), child App-IDs may be listed under the incorrect container App-ID.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259853</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the DHCP server is enabled for GlobalProtect, the commit error
message is not properly displayed when
<span class="ph uicontrol">Any</span> is selected as the source
interface in the service router configuration (
<span class="ph menucascade"
><span class="ph uicontrol">Device</span
><span class="ph uicontrol">Setup</span
><span class="ph uicontrol">Service</span
><span class="ph uicontrol"></span
><span class="ph uicontrol"
>Service Router Configuration</span
></span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259423</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the GlobalProtect DHCP feature is enabled with two primary DHCP
servers on the GlobalProtect gateway, the gpsvc gets stuck during
renewal and after HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254108</b></div>
</td>
<td class="entry relcol">
<div class="p">
when upgrading or downgrading a Panorama management server (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Software</span></span
>), managed device (<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Device Deployment</span
><span class="ph uicontrol">Software</span></span
>), or standalone firewall (<span class="ph menucascade"
><span class="ph uicontrol">Device</span
><span class="ph uicontrol">Software</span></span
>), <span class="ph uicontrol">Base Releases</span> and
<span class="ph uicontrol">Preferred Releases</span> settings are
checked (enabled) by default and cause no PAN-OS software images to
display.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Uncheck (disable)
<span class="ph uicontrol">Base Releases</span> or
<span class="ph uicontrol">Preferred Releases</span> to display either
the available base PAN-OS or preferred PAN-OS releases available to
download and install.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253963</b></div>
</td>
<td class="entry relcol">
<div class="p">
The auto commit job may take longer than expected to complete when the
Panorama management server is in Panorama or Log Collector mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-252661</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you change the service route of gp-ip-mgmt in
<b class="ph b"
>Device &gt; Setup &gt; Services &gt; Service Features &gt;
gp-ip-mgmt</b
>
and <b class="ph b">Commit</b>, the change wont take effect.
gp-ip-mgmt continues to use the last committed service route.
</div>
<div class="p">
<b class="ph b">Workaround:</b> After you change the service route
interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
gateway, click <b class="ph b">OK </b>to save the configuration, and
<b class="ph b">Commit </b>the changes. This commit will include the
service route change.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250246</b></div>
</td>
<td class="entry relcol">
<div class="p">
Panorama and the firewall display inconsistent IP addresses for
dynamic address group members after manually syncing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250062</b></div>
</td>
<td class="entry relcol">
<div class="p">
Device telemetry might fail at configured intervals due to bundle
generation issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248836</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Advanced DNS Security trial license and trial license information
cannot be activated and viewed, respectively, on a managed firewall
(with expired or active status) from Panorama. These tasks can only be
performed on the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247728</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-1-known-and-addressed-issues/pan-os-11-2-1-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 11.2.1 Addressed Issues</a
>
</div>
</td>
<td class="entry relcol">
<div class="p">
When Advanced Routing is enabled, IP multicast is not supported. An
upcoming version will provide support for this feature. Customers who
have multicast configured or who plan to deploy multicast routing
should not upgrade to 11.2.0. Additionally, when Advanced Routing is
enabled, the BGP dampening configuration isn't applied to any peers or
peer group; the configuration is preserved but has no effect on BGP.
Customers can use BGP even if they have applied a Dampening profile to
a specific set of peers. The issue doesn't affect any other BGP
features.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241994</b></div>
</td>
<td class="entry relcol">
<div class="p">
The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
Palo Alto Networks recommends that you upgrade your ESXi version if it
is less than 6.7 U2. For more information, see the
<a
class="xref"
href="https://kb.vmware.com/s/article/2007240"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
rel="nofollow"
>compatibility matrix</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239612</b></div>
</td>
<td class="entry relcol">
<div class="p">
When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
agent doesn't work.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237106</b></div>
</td>
<td class="entry relcol">
<div class="p">
LSVPN satellite certificates may be generated with serial numbers
exceeding 40 hexadecimal characters. This causes certificate
revocation and deletion operations to fail with the following error
messages:
</div>
<ul id="panos-known-issues-11.2.13_ul-hby_2gs_jjc" class="ul">
<li class="li">
<span class="ph systemoutput"
>db-serialno can be at most 40 characters</span
>
</li>
<li class="li">
<span class="ph systemoutput">db-serialno is invalid</span>
</li>
</ul>
<b class="ph b">Workaround:</b>
<div class="p">
To resolve this issue, use the following CLI commands with the LSVPN
satellite serial number to manually delete or revoke the affected
certificates:
</div>
<div class="p">
<b class="ph b">Delete certificate information</b>:<span
class="ph userinput"
>delete sslmgr-store certificate-info portal name
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname">&lt;satellite_serial&gt;</var></span
>
</div>
<div class="p">
<b class="ph b">Revoke satellite certificates</b>:<span
class="ph userinput"
>delete sslmgr-store satellite-info-revoke-certificate portal
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname"
>&lt;list_of_satellite_serials&gt;</var
></span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-236649</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you change the configuration of a firewall acting as a PPPoEv4 or
PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
and route table for an inherited configuration with dynamic-identifier
or client remain visible. Old routes also remain visible for an
inherited interface when you execute the CLI command,
<span class="ph userinput">show interface all</span>.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Unconfigure and configure the
Inherited Interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234015</b></div>
</td>
<td class="entry relcol">
<div class="p">
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207442</b></div>
</td>
<td class="entry relcol">
<div class="p">
For M-700 appliances in an active/passive high availability (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">High Availability</span></span
>) configuration, the
<span class="ph systemoutput">active-primary</span> HA peer
configuration sync to the
<span class="ph systemoutput">secondary-passive</span> HA peer may
fail. When the config sync fails, the job Results is
<span class="ph systemoutput">Successful</span>
(<span class="ph uicontrol">Tasks</span>), however the sync status on
the <span class="ph uicontrol">Dashboard</span> displays as
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Perform a local commit on the
<span class="ph systemoutput">active-primary</span> HA peer and then
synchronize the HA configuration.
</div>
<ol id="panos-known-issues-11.2.13_ol-iby_2gs_jjc" class="ol">
<li class="li">
<div class="p">
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Log in to the Panorama web interface</a
>
of the <span class="ph systemoutput">active-primary</span> HA
peer.
</div>
</li>
<li class="li">
<div class="p">
Select <span class="ph uicontrol">Commit</span> and
<span class="ph uicontrol">Commit to Panorama</span>.
</div>
</li>
<li class="li">
<div class="p">
In the <span class="ph systemoutput">active-primary</span> HA peer
<span class="ph uicontrol">Dashboard</span>, click
<span class="ph uicontrol">Sync to Peer</span> in the High
Availability widget.
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206909</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Dedicated Log Collector is unable to reconnect to the Panorama
management server if the <span class="ph systemoutput">configd</span>
process crashes. This results in the Dedicated Log Collector losing
connectivity to Panorama despite the managed collector connection
<span class="ph systemoutput">Status</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Managed Collector</span></span
>) displaying <span class="ph systemoutput">connected</span> and the
managed colletor <span class="ph systemoutput">Health</span> status
displaying as healthy.
</div>
<div class="p">
This results in the local Panorama config and system logs not being
forwarded to the Dedicated Log Collector. Firewall log forwarding to
the disconnected Dedicated Log Collector is not impacted.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Restart the
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
Log Collector.
</div>
<ol id="panos-known-issues-11.2.13_ol-jby_2gs_jjc" class="ol">
<li class="li">
<div class="p">
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>Log in to the Dedicated Log Collector CLI</a
>.
</div>
</li>
<li class="li">
<div class="p">
Confirm the Dedicated Log Collector is disconnected from Panorama.
</div>
<!-- FM Dita Overlay for Code -->
<div class="code-wrap">
<pre
class="pre codeblock"
data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
<div class="p">
Verify the <span class="ph systemoutput">Connected</span> status
is <span class="ph systemoutput">no</span>.
</div>
</div>
</li>
<li class="li">
<div class="p">
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
</div>
<!-- FM Dita Overlay for Code -->
<div class="code-wrap">
<pre
class="pre codeblock"
data-label="PRE CODEBLOCK"
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin&gt;</span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
</div>
</li>
</ol>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197588</b></div>
</td>
<td class="entry relcol">
<div class="p">
The PAN-OS ACC (Application Command Center) does not display a widget
detailing statistics and data associated with vulnerability exploits
that have been detected using inline cloud analysis.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197419</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
<span class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">Interface</span
><span class="ph uicontrol">Ethernet</span></span
>, the power over Ethernet (PoE) ports do not display a
<span class="ph uicontrol">Tag</span> value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196758</b></div>
</td>
<td class="entry relcol">
<div class="p">
On the Panorama management server, pushing a configuration change to
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
configurations for SD-WAN as being edited or deleted despite no edits
or deletions being made when you
<span class="ph uicontrol">Preview Changes</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span
><span class="ph uicontrol">Edit Selections</span></span
>
or
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Commit and Push</span
><span class="ph uicontrol">Edit Selections</span></span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195968</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
prints an error depending on whether an interface type was selected on
the non-PoE port or not. If an interface type, such as tap, Layer 2,
or virtual wire, was selected before PoE was configured, the error
message will not include the interface name (eg. ethernet1/4). If an
interface type was not selected before PoE was configured, the error
message will include the interface name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187685</b></div>
</td>
<td class="entry relcol">
<div class="p">
On the Panorama management server, the Template Status displays no
synchronization status (<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Managed Devices</span
><span class="ph uicontrol">Summary</span></span
>) after a bootstrapped firewall is successfully added to Panorama.
</div>
<div class="p">
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
successfully added to Panorama,
<a
class="xref"
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>log in to the Panorama web interface</a
>
and select
<span class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Push to Devices</span></span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187407</b></div>
</td>
<td class="entry relcol">
<div class="p">
The configured Advanced Threat Prevention inline cloud analysis action
for a given model might not be honored under the following condition:
If the firewall is set to
<span class="ph uicontrol"
>Hold client request for category lookup </span
>and the action set to
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
been cleared, the first request for inline cloud analysis will be
bypassed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184406</b></div>
</td>
<td class="entry relcol">
<div class="p">
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
dmdb process to crash.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Contact customer support to stop the
dmdb process before adding a RAID disk pair to a M-700 appliance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Static IP addresses are not recognized when "and" operators are used
with IP CIDR range.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181933</b></div>
</td>
<td class="entry relcol">
<div class="p">
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
all of the cards may not receive all of the updates and the mappings
for the clients may become out of sync, which causes the firewall to
not correctly populate the Source User column in the session logs.
</div>
</td>
</tr>
</tbody>
</table>
+254
View File
@@ -0,0 +1,254 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p">PAN-330836</div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series software firewalls with 16 GB of memory and 16 vCPUs
only</tt
>) Starting in PAN-OS 12.1.5, memory usage increases to approximately
6 GB for firewalls running a maximum configuration, compared to
approximately 5 GB in PAN-OS 12.1.2. This increase eliminates the
available memory buffer, leaving no capacity to absorb additional
memory demand during peak load. The firewall may become unstable or
unresponsive under high-load conditions.
</div>
<div class="p">
Firewalls operating with 12 dp cores, or processing more than 512K
sessions, are specifically at risk for memory issues. To ensure
continued stability for firewalls matching this criteria, Palo Alto
Networks recommends an increase of overall memory allocation by 2 GB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
PAN-317755<tt class="ph tt">This issue is now resolved. See</tt>
<a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-7-known-and-addressed-issues/pan-os-12-1-7-h1-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.7-h1 Addressed Issues</a
>
</div>
</td>
<td class="entry relcol">
<div class="p">
A selective push from Panorama to managed firewalls fail when plugin
configurations reference certain Panorama settings, such as
log-collector groups or access domains.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Perform a full push instead of a
selective push as a temporary measure. Note that selective push
attempts will continue to fail until you upgrade to the release that
includes the fix.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-312143</div>
</td>
<td class="entry relcol">
<div class="p">
(Firewalls in active/passive high availability (HA) configurations
only) When attempting to synchronize the running configuration with an
HA peer, particularly during script runs involving different topology
builds (e.g., during a smoke runlist), the synchronization process
fails. This results in an error indicating that the running
configuration could not be synchronized with the HA peer.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-311601</div>
</td>
<td class="entry relcol">
<div class="p">
If the node is seen stuck with fault "session clearing fault". Node
reboot is the workaround to get the node back in online state after
all other fault conditions are removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-310328</div>
</td>
<td class="entry relcol">
<div class="p">
If the node is seen stuck with fault "session clearing fault". Node
reboot is the workaround to get the node back in online state after
all other fault conditions are removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-300667</div>
</td>
<td class="entry relcol">
<div class="p">
Panorama cannot display Threat log entries (Monitor &gt; Logs &gt;
Threat) when the managed log collector is running a lower PAN-OS
release than Panorama. Workaround: Upgrade the log collectors to the
same version as Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-300230</div>
</td>
<td class="entry relcol">
<div class="p">
(NGFW Cluster) In an NGFW cluster, your pings to the HSCI-B link might
fail, even when the link indicates it is up. In the event that the
HSCI-A link is brought down or unplugged, the cluster node will
transition to failed state, avoiding split brain as both HSCI links
are down in this case. Workaround: Reboot the cluster node to resolve
the HSCI-B ping issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-299562</div>
</td>
<td class="entry relcol">
<div class="p">
When a client sends a Client Hello with Transport Layer Security (TLS)
1.3 or TLS 1.2, using only the p-192 elliptic curve and some
non-perfect forward secrecy (PFS) ciphers, the firewall discards the
Client Hello. The firewall should allow the connection to proceed
using TLS 1.2, maintaining backward compatibility with previous
releases.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-298083</div>
</td>
<td class="entry relcol">
<div class="p">
Draft for review: After you change the system mode on an M-700
appliance from Panorama mode to PAN-DB private cloud mode, the snmpd
process fails to work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-295946</div>
</td>
<td class="entry relcol">
<div class="p">
When a Panorama appliance (running PAN-OS 12.1.2 or higher) manages
firewalls running PAN-OS versions lower than 12.1.2, and an NTP server
configuration template includes SHA256 or SHA512 as the authentication
mechanism, pushing this template to the firewalls running PAN-OS
versions lower than 12.1.2 will cause the commit operation to fail.
Workaround: Create two separate templates: one for firewalls running
PAN-OS 12.1.2 or higher (which can include SHA256/SHA512
authentication) and another for firewalls running PAN-OS versions
lower than 12.1.2 (which should use other authentication algorithms
such as SHA1, MD5, or Autokey). Then, push the appropriate template to
the corresponding devices from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-292601</div>
</td>
<td class="entry relcol">
<div class="p">
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
configuration for an address object. If there are two address objects
with same FQDN, but one object has Load Balanced DNS enabled and other
object has Load Balanced DNS disabled, then the policy match for the
removed IP addresses doesn't work as expected. Workaround: Enable (or
disable) Load Balanced DNS consistently for an FQDN that is used with
multiple address objects.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-289524</div>
</td>
<td class="entry relcol">
<div class="p">
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
IP addresses from a Load balanced DNS server and use them in a policy
match. However, this functionality does not work as intended when the
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
enabled, the DNS resolution works as if the Load balanced DNS flag
(for an Address object) is disabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p">PAN-283028</div>
</td>
<td class="entry relcol">
<div class="p">
The following error is thrown when an existing template overrides the
SD-WAN configuration followed by the commit and push from Panorama to
the firewall.
</div>
<div class="p">
BGP is invalid. AS number does not fit in 2 byte AS format
</div>
<div class="p">
This issue occurs because different AS formats are present on the
Panorama and the firewall (the firewall configuration is generated by
the SD-WAN plugin). That is, both the hub and branch firewall must
have the same AS format in hub-and-spoke topology. In full mesh
topology, all the firewalls must have the same AS format.
</div>
</td>
</tr>
</tbody>
</table>
+317
View File
@@ -0,0 +1,317 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p">PAN-330995</div>
</td>
<td class="entry relcol">
<div class="p">
Within GCP NSI environments, egress traffic logs fail to accurately
reflect the designated NAT IP addresses.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">PAN-330964</div>
</td>
<td class="entry relcol">
<div class="p">
In PA-VM deployed on GCP instances, it is observed that the gVNIC
interfaces appear inactive after enabling jumbo frames.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">PAN-330906</div>
</td>
<td class="entry relcol">
<div class="p">
On Panorama, the configuration Push Scope might not include the shared
<span class="ph uicontrol">Devices</span> object entries, even though
these objects are visible in the staged configuration changes for the
specified administrator and device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">PAN-330902</div>
</td>
<td class="entry relcol">
<div class="p">
After restarting MongoDB (mdb) on Panorama using the
<span class="ph userinput"
>request mongo set mongo-update-sort-limit</span
>
CLI command, push to devices (both full push and selective push)
fails.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Restart
<span class="ph userinput">configd</span> on Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">PAN-330836</div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series software firewalls with 16 GB of memory and 16 vCPUs
only</tt
>) Starting in PAN-OS 12.1.5, memory usage increases to approximately
6 GB for firewalls running a maximum configuration, compared to
approximately 5 GB in PAN-OS 12.1.2. This increase eliminates the
available memory buffer, leaving no capacity to absorb additional
memory demand during peak load. The firewall may become unstable or
unresponsive under high-load conditions.
</div>
<div class="p">
Firewalls operating with 12 dp cores, or processing more than 512K
sessions, are specifically at risk for memory issues. To ensure
continued stability for firewalls matching this criteria, Palo Alto
Networks recommends an increase of overall memory allocation by 2 GB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">PAN-329146</div>
</td>
<td class="entry relcol">
<div class="p">
Within GCP NSI environments, it is observed that the Prisma AIRS
license activates geneve parsing as a
<i class="ph i">default setting</i>, permitting intraVPC traffic flow
regardless of NSI status. Hence, you will not be able to disable this
feature through CLI.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313669</div></td>
<td class="entry relcol">
<div class="p">
(PA-5500 Series firewalls in cluster configurations only) When a
firewall node is removed from a PA-5500 Series cluster, after the
cluster commit and reboot, the node starts in standalone mode with a
default virtual wire (vwire) configuration loaded. This default
configuration is missing zone assignments for ports eth1/1 and eth1/2,
which causes commit operations to fail. Even if zones are manually
assigned to these ports, subsequent commit attempts will fail with a
"no UUId for rule1" error.
</div>
<div class="p">
<span class="ph uicontrol">Workaround:</span> To resolve this, either:
</div>
<ul class="ul">
<li class="li">
Manually assign zone configurations to ports eth1/1 (e.g., untrust)
and eth1/2 (e.g., trust), then open and close security policy rule1
without making changes, and
<span class="ph uicontrol">Commit</span>.
</li>
<li class="li">
Delete the default rule and the default virtual wire Ethernet
interfaces, then commit.
</li>
</ul>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312143</div></td>
<td class="entry relcol">
<div class="p">
(Firewalls in active/passive high availability (HA) configurations
only) When attempting to synchronize the running configuration with an
HA peer, particularly during script runs involving different topology
builds (e.g., during a smoke runlist), the synchronization process
fails. This results in an error indicating that the running
configuration could not be synchronized with the HA peer.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311601</div></td>
<td class="entry relcol">
<div class="p">
If the node is seen stuck with fault "session clearing fault". Node
reboot is the workaround to get the node back in online state after
all other fault conditions are removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310328</div></td>
<td class="entry relcol">
<div class="p">
If the node is seen stuck with fault "session clearing fault". Node
reboot is the workaround to get the node back in online state after
all other fault conditions are removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-300667</div></td>
<td class="entry relcol">
<div class="p">
Panorama cannot display Threat log entries (Monitor &gt; Logs &gt;
Threat) when the managed log collector is running a lower PAN-OS
release than Panorama. Workaround: Upgrade the log collectors to the
same version as Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-300230</div></td>
<td class="entry relcol">
<div class="p">
(NGFW Cluster) In an NGFW cluster, your pings to the HSCI-B link might
fail, even when the link indicates it is up. In the event that the
HSCI-A link is brought down or unplugged, the cluster node will
transition to failed state, avoiding split brain as both HSCI links
are down in this case. Workaround: Reboot the cluster node to resolve
the HSCI-B ping issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-299562</div></td>
<td class="entry relcol">
<div class="p">
When a client sends a Client Hello with Transport Layer Security (TLS)
1.3 or TLS 1.2, using only the p-192 elliptic curve and some
non-perfect forward secrecy (PFS) ciphers, the firewall discards the
Client Hello. The firewall should allow the connection to proceed
using TLS 1.2, maintaining backward compatibility with previous
releases.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-298083</div></td>
<td class="entry relcol">
<div class="p">
Draft for review: After you change the system mode on an M-700
appliance from Panorama mode to PAN-DB private cloud mode, the snmpd
process fails to work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-295946</div></td>
<td class="entry relcol">
<div class="p">
When a Panorama appliance (running PAN-OS 12.1.2 or higher) manages
firewalls running PAN-OS versions lower than 12.1.2, and an NTP server
configuration template includes SHA256 or SHA512 as the authentication
mechanism, pushing this template to the firewalls running PAN-OS
versions lower than 12.1.2 will cause the commit operation to fail.
Workaround: Create two separate templates: one for firewalls running
PAN-OS 12.1.2 or higher (which can include SHA256/SHA512
authentication) and another for firewalls running PAN-OS versions
lower than 12.1.2 (which should use other authentication algorithms
such as SHA1, MD5, or Autokey). Then, push the appropriate template to
the corresponding devices from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-293718</div></td>
<td class="entry relcol">
<div class="p">
Draft for review: When high speed logging is enabled on a PA-5560
device, the expected warning message is not displayed on the web
interface. This prevents administrators from being notified that logs
can only be viewed from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-292601</div></td>
<td class="entry relcol">
<div class="p">
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
configuration for an address object. If there are two address objects
with same FQDN, but one object has Load Balanced DNS enabled and other
object has Load Balanced DNS disabled, then the policy match for the
removed IP addresses doesn't work as expected. Workaround: Enable (or
disable) Load Balanced DNS consistently for an FQDN that is used with
multiple address objects.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-289524</div></td>
<td class="entry relcol">
<div class="p">
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
IP addresses from a Load balanced DNS server and use them in a policy
match. However, this functionality does not work as intended when the
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
enabled, the DNS resolution works as if the Load balanced DNS flag
(for an Address object) is disabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-283028</div></td>
<td class="entry relcol">
<div class="p">
The following error is thrown when an existing template overrides the
SD-WAN configuration followed by the commit and push from Panorama to
the firewall.
</div>
<div class="p">
BGP is invalid. AS number does not fit in 2 byte AS format
</div>
<div class="p">
This issue occurs because different AS formats are present on the
Panorama and the firewall (the firewall configuration is generated by
the SD-WAN plugin). That is, both the hub and branch firewall must
have the same AS format in hub-and-spoke topology. In full mesh
topology, all the firewalls must have the same AS format.
</div>
</td>
</tr>
</tbody>
</table>
+573
View File
@@ -0,0 +1,573 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">PAN-332943</td>
<td class="entry relcol">
<div class="p">
When you upgrade a PA-450R, PA-450R-5G, PA-410R, or PA-410R-5G
firewall to PAN-OS 12.2.2 from an earlier release with Fail-to-Wire
enabled, subsequent manual commits fail with the following validation
error: network -&gt; interface -&gt; fail-open is invalid. This occurs
because PAN-OS 12.2.2 introduced a configuration schema change for the
Fail-to-Wire feature that is not automatically migrated during
upgrade. Fail-to-Wire also does not function correctly after the
upgrade.
</div>
<div class="p">
<b class="ph b">Workaround:</b>Remove and re-add the Fail-to-Wire
configuration.
</div>
<div class="p">
<span class="keyword cmdname"
>delete network interface fail-open</span
>
</div>
<div class="p"><span class="keyword cmdname">commit</span></div>
<div class="p">
<span class="keyword cmdname">set network interface fail-open</span>
</div>
<div class="p"><span class="keyword cmdname">commit</span></div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-332874</td>
<td class="entry relcol">
<div class="p">
On 5G firewalls, Zero Touch Provisioning (ZTP) over cellular does not
complete when the cellular carrier MTU is 1428. During ZTP, the
firewall does not correctly account for cellular tunnel header
overhead when negotiating the TCP maximum segment size (MSS). The
firewall advertises an MSS value that is too large for the 1428 MTU
cellular link, causing the certificate server's response packets to
exceed the link MTU. The certificate fetch does not complete, and the
firewall does not finish provisioning.
</div>
<div class="p">
This issue occurs when using a cellular connection with a
carrier-negotiated MTU of 1428, which is the standard MTU for cellular
wireless. ZTP process will succeed when carrier provided Network MTU
is greater than or equal to 1500.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-332576</td>
<td class="entry relcol">
<div class="p">
On HA pairs running PAN-OS 12.2.2, the useridd process may exhaust its
ID manager (type 17) when the passive firewall accumulates more than
1,000,000 user entries. When this occurs, useridd consumes 100% CPU
and becomes unresponsive, causing commits to fail with the error
Management server failed to send phase 1 to client useridd or to stall
at 0%.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-332130</td>
<td class="entry relcol">
<div class="p">
On firewalls with cellular interfaces configured with parent and
sub-interfaces, APN authentication fails on sub-interfaces when the
PDP type is set to both (IPv4 and IPv6). Data sessions on the parent
interface establish successfully for both IPv4 and IPv6, but
sub-interfaces fail to bring up their data sessions when using PAP or
CHAP authentication with PDP type both.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Set the PDP type to IPv4 only on
sub-interfaces.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-331987</td>
<td class="entry relcol">
<div class="p">
(PA-5450, PA-5500, and PA-7500 firewalls with PAN-OS Shield enabled)
When connecting to GlobalProtect Portal or Gateway, users receive a
`Portal unreachable` error. GlobalProtect connections are frequently
unsuccessful, though they may connect successfully after multiple
attempts.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Change the session distribution policy
to Round-robin.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-331722</td>
<td class="entry relcol">
<div class="p">
On PA-54R-POE (BH/Eagle) firewalls, the PAN-S-SFP-100BASE-FX
transceiver on fiber interfaces does not link up when the interface
link speed is explicitly set to 100 Mbps. The interface links up
correctly when the link speed is set to auto.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Set the interface link speed to auto.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-331659</td>
<td class="entry relcol">
<div class="p">
Running the CLI command debug dataplane packet-path-test counter on
PAN-OS 12.2.2 returns a server error instead of counter output.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-330995</td>
<td class="entry relcol">
<div class="p">
Within GCP NSI environments, egress traffic logs fail to accurately
reflect the designated NAT IP addresses.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-330974</td>
<td class="entry relcol">
<div class="p">
If Azure hotplug events occur, the firewall may experience a crash and
data interfaces may transition to an unknown state, leading to traffic
disruption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-330964</td>
<td class="entry relcol">
<div class="p">
In PA-VM deployed on GCP instances, gVNIC interfaces appear inactive
after enabling jumbo frames.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-330381</td>
<td class="entry relcol">
<div class="p">
When firewalls are configured in a cluster operating in default mode,
IP-Tag, User-Tag, and IP-Port mappings registered on the leader node
do not synchronize to the follower node. On the follower node,
commands such as `show object registered-ip all` and `show object
registered-user all` display no registered entries for these data
types, even though they are present on the leader. This prevents
Dynamic Address Group (DAG) and Dynamic User Group (DUG) based
security policies, which rely on these mappings, from functioning
correctly on the follower node. As a result, traffic routed through
the follower node does not match these policies, leading to an
inconsistent security posture across the cluster.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Configure the firewall cluster to
operate in ICD mode. This enables the correct synchronization of
IP-Tag, User-Tag, and IP-Port mappings between the leader and follower
nodes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-329606</td>
<td class="entry relcol">
<div class="p">
On PA-54R-POE (BH) firewalls, SCP export and import of cellular
firmware files fail from the CLI. Running
<span class="ph codeph">request cellular firmware scp-export</span> or
<span class="ph codeph">request cellular firmware scp-import</span>
returns a server error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-329515</td>
<td class="entry relcol">
<div class="p">
When scheduling cellular firmware downloads on Panorama (<b
class="ph b"
>Device Deployment &gt; Cellular Firmware &gt; Schedule</b
>), the Files and Devices fields are not populated in the UI for
PA-54R-POE-5G (BH/Eagle) devices. As a result, scheduled Download Only
and Download and Install operations for cellular firmware cannot be
configured through Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-329146</td>
<td class="entry relcol">
<div class="p">
Within GCP NSI environments, the Prisma® AIRS license activates geneve
parsing as a default setting, permitting intraVPC traffic flow
regardless of NSI status. You cannot disable this feature through CLI.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-328647</td>
<td class="entry relcol">
<div class="p">
When you configure ML7-CUID in a multi-vsys environment on PAN-OS
12.2.2, data upload only supports the hub vsys configuration. When a
publisher is configured on a non-hub vsys, data from that vsys is not
uploaded to the cloud. All vsys must share the same segment
configuration for data upload to function correctly in this release.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Configure the publisher on the hub
vsys and ensure all vsys use the same segment configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-327958</td>
<td class="entry relcol">
<div class="p">
(PA-5450 Firewalls only) Basic authentication for web proxy is not
supported in 12.2.2.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-326791</td>
<td class="entry relcol">
<div class="p">
When a Hyperscale Security Fabric (HSF) cluster uses an offline
license, the system allows the removal of configuration and
uninstallation of the Security Fabric License (SFL) plugin. If the SFL
plugin is uninstalled under these conditions, subsequent undeploy
operations do not complete successfully.
</div>
<div class="p">
<b class="ph b">Workaround:</b> To allow the undeploy operation to
complete, reinstall the Security Fabric License (SFL) plugin.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-316972</td>
<td class="entry relcol">
<div class="p">
After downgrading a PA-520 firewall from PAN-OS 12.2.0 to 12.1.5 or
later 12.1.x releases, auto-commit repeatedly fails after the
downgrade completes, leaving the firewall unable to apply its
configuration automatically.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-314625</td>
<td class="entry relcol">
<div class="p">
The `useridd` process restarts when you attempt to dump the Host
Information Profile (HIP) database using the `debug user-id dump
hip-profile-database` command. This occurs while the firewall is
actively processing HIP reports, such as logouts or updates. The
command initially hangs and times out before the `useridd` process
restarts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-313669</td>
<td class="entry relcol">
<div class="p">
(PA-5500 Series firewalls in cluster configurations only) When a
firewall node is removed from a PA-5500 Series cluster, after the
cluster commit and reboot, the node starts in standalone mode with a
default virtual wire (vwire) configuration loaded. This default
configuration is missing zone assignments for ports eth1/1 and eth1/2,
which causes commit operations to fail. Even if zones are manually
assigned to these ports, subsequent commit attempts fail with a "no
UUId for rule1" error.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Manually assign zone configurations to
ports eth1/1 (for example, untrust) and eth1/2 (for example, trust),
then open and close security policy rule1 without making changes, and
commit. Alternatively, delete the default rule and the default virtual
wire Ethernet interfaces, then commit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-312143</td>
<td class="entry relcol">
<div class="p">
(Firewalls in active/passive high availability (HA) configurations
only) When you synchronize the running configuration with an HA peer,
particularly during script runs involving different topology builds,
the synchronization process fails with an error indicating that the
running configuration could not be synchronized with the HA peer.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-311601</td>
<td class="entry relcol">
<div class="p">
If a node is stuck with a "session clearing fault," reboot the node to
restore it to an online state after all other fault conditions are
removed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-310328</td>
<td class="entry relcol">
<div class="p">
If a node is stuck with a "session clearing fault," reboot the node to
restore it to an online state after all other fault conditions are
removed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-309410</td>
<td class="entry relcol">
<div class="p">
Subscriber Identity and Equipment Identity values are missing from URL
filtering and Data Filtering logs for GTP mobility traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-305734</td>
<td class="entry relcol">
<div class="p">
On firewalls with 5G cellular interfaces, the default auto MTU value
of 1428 bytes causes IP fragmentation errors and out-of-order packets,
resulting in degraded throughput performance on cellular connections.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Manually set the cellular interface
MTU to 1500 bytes instead of using the auto MTU default.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-300667</td>
<td class="entry relcol">
<div class="p">
Panorama cannot display Threat log entries (<b class="ph b"
>Monitor &gt; Logs &gt; Threat</b
>) when the managed log collector is running a lower PAN-OS release
than Panorama.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Upgrade the log collectors to the same
version as Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-300230</td>
<td class="entry relcol">
<div class="p">
(NGFW Cluster) In an NGFW cluster, pings to the HSCI-B link may fail
even when the link indicates it is up. If the HSCI-A link is brought
down or unplugged, the cluster node transitions to a failed state,
avoiding split brain because both HSCI links are down.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Reboot the cluster node to resolve the
HSCI-B ping issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-299562</td>
<td class="entry relcol">
<div class="p">
When a client sends a Client Hello with TLS 1.3 or TLS 1.2 using only
the p-192 elliptic curve and some non-perfect forward secrecy (PFS)
ciphers, the firewall discards the Client Hello. The firewall should
allow the connection to proceed using TLS 1.2, maintaining backward
compatibility with previous releases.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-299286</td>
<td class="entry relcol">
<div class="p">
When configuring a PIM6 neighbor filter, you must include both the
primary and secondary IPv6 addresses of each neighbor in the prefix
list. Filtering on the primary address alone is not sufficient because
PIM6 Hello messages (Option 5) advertise both addresses to peers. A
filter that allows only the primary address will prevent neighbor
adjacency from forming.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-298083</td>
<td class="entry relcol">
<div class="p">
After you change the system mode on an M-700 appliance from Panorama
mode to PAN-DB private cloud mode, the snmpd process fails to work.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-295946</td>
<td class="entry relcol">
<div class="p">
When a Panorama appliance running PAN-OS 12.1.2 or later manages
firewalls running earlier PAN-OS versions, and an NTP server
configuration template includes SHA256 or SHA512 as the authentication
mechanism, pushing the template to firewalls running PAN-OS versions
earlier than 12.1.2 causes the commit operation to fail.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Create two separate templates: one for
firewalls running PAN-OS 12.1.2 or later (which can include
SHA256/SHA512 authentication) and another for firewalls running
earlier PAN-OS versions (which should use SHA1, MD5, or Autokey). Push
the appropriate template to the corresponding devices from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-294752</td>
<td class="entry relcol">
<div class="p">
In any 15-second interval, if connectivity (CI or management) on a
GW-Node (not P-Node) changes more than once, with each change
occurring on a different node and affecting a different link, the
cluster loses its leader, all routing protocols fail, and traffic is
blackholed if route changes occur in the network.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Reboot nodes that are in a FAILED
state or suspend and unsuspend any online GW-Node (not P-Node).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-293718</td>
<td class="entry relcol">
<div class="p">
When high-speed logging is enabled on a PA-5560 firewall, the expected
warning message does not appear on the web interface. This prevents
you from being notified that logs can only be viewed from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-292601</td>
<td class="entry relcol">
<div class="p">
PAN-OS 12.1.2 and later 12.1 releases support a load-balanced DNS
configuration for an address object. If two address objects share the
same FQDN but one has load-balanced DNS enabled and the other has it
disabled, the policy match for removed IP addresses does not work as
expected.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Enable or disable load-balanced DNS
consistently for any FQDN used with multiple address objects.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-289524</td>
<td class="entry relcol">
<div class="p">
In PAN-OS 12.1.2 and later and PAN-OS 12.2.2 and later releases,
PAN-OS can obtain resolved IP addresses from a load-balanced DNS
server and use them in a policy match. However, this functionality
does not work as intended when the DNS cache reuse flag is enabled.
When the DNS cache reuse flag is enabled, the DNS resolution works as
if the load-balanced DNS flag (for an address object) is disabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PAN-283028</td>
<td class="entry relcol">
<div class="p">
When an existing template overrides the SD-WAN configuration followed
by a commit and push from Panorama to the firewall, the following
error occurs: BGP is invalid. AS number does not fit in 2 byte AS
format. This issue occurs because different AS formats are present on
Panorama and the firewall (the firewall configuration is generated by
the SD-WAN plugin). In hub-and-spoke topology, both the hub and branch
firewall must have the same AS format. In full mesh topology, all
firewalls must have the same AS format.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">PLUG-23656</td>
<td class="entry relcol">
<div class="p">
In Software Firewall Licensed HSF environments, serial numbers linked
to stale entries can be manually released for reuse. This procedure
allows for the recovery of Software Firewall License credits when
virtual instances are deleted without being formally decommissioned.
For optimal resource management, it is recommended to utilize
Orchestration plugin workflows for VM operations rather than manual
intervention.
</div>
</td>
</tr>
</tbody>
</table>