This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-242777</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where running debug online diagnostics run on a 5G
|
||||
supported PA-400 firewall models reported "Missing device on I2C bus"
|
||||
errors and did not execute cellular modem diagnostic tests. This
|
||||
occurred because the diagnostics script used an incorrect I2C device
|
||||
list for the 5G supported PA-400 hardware variants and did not
|
||||
recognize it as a cellular-capable platform. With this fix, the I2C
|
||||
scan correctly reflects the 5G supported PA-400 hardware configuration
|
||||
and cellular modem tests run as expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,840 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 34%" />
|
||||
<col style="width: 66%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-317755</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/pan-os/11-1/pan-os-release-notes/pan-os-11-1-16-known-and-addressed-issues/pan-os-11-1-16-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 11.1.16 Addressed Issues</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A selective push from Panorama to managed firewalls fail when plugin
|
||||
configurations reference certain Panorama settings, such as
|
||||
log-collector groups or access domains.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-314624</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/pan-os/11-1/pan-os-release-notes/pan-os-11-1-16-known-and-addressed-issues/pan-os-11-1-16-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 11.1.16 Addressed Issues</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process restarts when you attempt to dump the Host Information Profile
|
||||
(HIP) database using the
|
||||
<span class="ph codeph">debug user-id dump hip-profile-database</span>
|
||||
command. This occurs while the firewall is actively processing HIP
|
||||
reports, such as logouts or updates. The command initially hangs and
|
||||
times out before the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process restarts.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303959</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Traffic that is incorrectly identified as unknown-tcp/unknown-udp
|
||||
eventually drops due to an App-ID resource limitation issue.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292202</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The system logs repeatedly displayed the alert
|
||||
<span class="ph systemoutput"
|
||||
>Clearing snmpd.log due to log overflow</span
|
||||
>
|
||||
due to the SNMP counters rolling over. This is a benign message and
|
||||
does not impact device functionality.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289432 </b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Generating a certificate with the
|
||||
<span class="ph codeph">block-private-key yes</span> command on
|
||||
Panorama fails with the error:
|
||||
</div>
|
||||
<div class="p">
|
||||
<span class="ph codeph"
|
||||
>Could not get parameters for double encryption.</span
|
||||
>
|
||||
This occurred when the certificate was signed by an external
|
||||
Certificate Authority (CA).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286848</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
ECMP incorrectly balances sessions across links based on the
|
||||
configured metric, which leads to an imbalance in traffic distribution
|
||||
and results in traffic assignment shifting disproportionately to
|
||||
routes with lower metrics.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
|
||||
continue selections will function like a general URL-block action.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285894</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If the Preserve Pre-NAT feature is enabled, dataplane crashes may
|
||||
occur, which could result in firewall reboots.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Disable the Preserve Pre-NAT feature
|
||||
using the
|
||||
<span class="ph userinput"
|
||||
>set deviceconfig setting preserve-prenat-feature no</span
|
||||
>
|
||||
CLI command.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283429</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use custom certificates for the connection between Panorama
|
||||
and a log collector, the automated renewal for the predefined
|
||||
ElasticSearch certificates gets disrupted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Remove the custom certificates before
|
||||
the ElasticSearch certificates expire. This allows the system to
|
||||
correctly identify and renew the predefined ElasticSearch
|
||||
certificates. After the renewal is complete, re-install the custom
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279415</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Service routes configured for a data plane interface might incorrectly
|
||||
route traffic through the management plane interface instead. This
|
||||
issue impacts Syslog and CRL status traffic when the service route
|
||||
lacks a specific destination custom service route.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-275047</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) After an upgrade,
|
||||
the firewall is unable to send logs to the Strata Logging Service
|
||||
(SLS) when using a specific proxy server, and the SSL connection
|
||||
status displays as failed when attempting to forward logs through the
|
||||
web proxy.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-262556</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The ElasticSearch cluster health status might continue to remain
|
||||
yellow for an extended period after upgrading to PAN-OS 11.1
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260851</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
From the NGFW or Panorama CLI, you can override the existing
|
||||
application tag even if Disable Override is enabled for the
|
||||
application (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Applications</span></span
|
||||
>) tag.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254240</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In the event of an HSCI flap on an NGFW cluster node, traffic
|
||||
reconvergence takes three to four seconds.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-253963</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The auto commit job may take longer than expected to complete when the
|
||||
Panorama management server is in Panorama or Log Collector mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-251551</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When an NGFW cluster agent crashes and doesn't recover, leader
|
||||
election will take approximately 45 seconds to begin and traffic
|
||||
failover will occur during that time.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250903</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In a congestion scenario on an HSCI port of an NGFW cluster node, the
|
||||
QoS priorities of cross node traffic streams might be reversed if
|
||||
you're using the default QoS profile with class1 to class8 set as high
|
||||
to low.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247974</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
LACP flap is expected during a device failover in an NGFW cluster due
|
||||
to an L2 ctrld restart on the new leader node.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-234015</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-224502</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
|
||||
might take longer than expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-220180</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Configured botnet reports (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">Botnet</span></span
|
||||
>) are not generated.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207733</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls, if
|
||||
the DHCPv6 server goes down, after the lease time expires, the DHCPv6
|
||||
client should enter SOLICIT state on both the Active and Passive
|
||||
firewalls. Instead, the client is stuck in BOUND state with an IPv6
|
||||
address having lease time 0 on the Passive firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207611</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls, the
|
||||
Passive firewall sometimes crashes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207442</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
For M-700 appliances in an active/passive high availability (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">High Availability</span></span
|
||||
>) configuration, the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer
|
||||
configuration sync to the
|
||||
<span class="ph systemoutput">secondary-passive</span> HA peer may
|
||||
fail. When the config sync fails, the job Results is
|
||||
<span class="ph systemoutput">Successful</span>
|
||||
(<span class="ph uicontrol">Tasks</span>), however the sync status on
|
||||
the <span class="ph uicontrol">Dashboard</span> displays as
|
||||
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Perform a local commit on the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer and then
|
||||
synchronize the HA configuration.
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.1.14_ol_aqy_kbp_qxb" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Panorama web interface</a
|
||||
>
|
||||
of the <span class="ph systemoutput">active-primary</span> HA
|
||||
peer.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Select <span class="ph uicontrol">Commit</span> and
|
||||
<span class="ph uicontrol">Commit to Panorama</span>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
In the <span class="ph systemoutput">active-primary</span> HA peer
|
||||
<span class="ph uicontrol">Dashboard</span>, click
|
||||
<span class="ph uicontrol">Sync to Peer</span> in the High
|
||||
Availability widget.
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207040</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you disable Advanced Routing, remove logical routers, and downgrade
|
||||
from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
|
||||
commits fail and SD-WAN devices on Panorama have no Virtual Router
|
||||
name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-206913</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls,
|
||||
releasing the IPv6 address from the client (using Release in the UI or
|
||||
using the
|
||||
<span class="ph systemoutput"
|
||||
>request dhcp client ipv6 release all</span
|
||||
>
|
||||
CLI command) releases the IPv6 address from the Active firewall, but
|
||||
not the Passive firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-206909</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Dedicated Log Collector is unable to reconnect to the Panorama
|
||||
management server if the <span class="ph systemoutput">configd</span>
|
||||
process crashes. This results in the Dedicated Log Collector losing
|
||||
connectivity to Panorama despite the managed collector connection
|
||||
<span class="ph systemoutput">Status</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Collector</span></span
|
||||
>) displaying <span class="ph systemoutput">connected</span> and the
|
||||
managed colletor <span class="ph systemoutput">Health</span> status
|
||||
displaying as healthy.
|
||||
</div>
|
||||
<div class="p">
|
||||
This results in the local Panorama config and system logs not being
|
||||
forwarded to the Dedicated Log Collector. Firewall log forwarding to
|
||||
the disconnected Dedicated Log Collector is not impacted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Restart the
|
||||
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
|
||||
Log Collector.
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.1.14_ol_pdy_4bm_lvb" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Dedicated Log Collector CLI</a
|
||||
>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Confirm the Dedicated Log Collector is disconnected from Panorama.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
|
||||
<div class="p">
|
||||
Verify the <span class="ph systemoutput">Connected</span> status
|
||||
is <span class="ph systemoutput">no</span>.
|
||||
</div>
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197588</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The PAN-OS ACC (Application Command Center) does not display a widget
|
||||
detailing statistics and data associated with vulnerability exploits
|
||||
that have been detected using inline cloud analysis.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197419</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interface</span
|
||||
><span class="ph uicontrol">Ethernet</span></span
|
||||
>, the power over Ethernet (PoE) ports do not display a
|
||||
<span class="ph uicontrol">Tag</span> value.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-196758</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, pushing a configuration change to
|
||||
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
|
||||
configurations for SD-WAN as being edited or deleted despite no edits
|
||||
or deletions being made when you
|
||||
<span class="ph uicontrol">Preview Changes</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>
|
||||
or
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Commit and Push</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-195968</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
|
||||
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
|
||||
prints an error depending on whether an interface type was selected on
|
||||
the non-PoE port or not. If an interface type, such as tap, Layer 2,
|
||||
or virtual wire, was selected before PoE was configured, the error
|
||||
message will not include the interface name (eg. ethernet1/4). If an
|
||||
interface type was not selected before PoE was configured, the error
|
||||
message will include the interface name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-194978</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interface</span
|
||||
><span class="ph uicontrol">Ethernet</span></span
|
||||
>, hovering the mouse over a power over Ethernet (PoE)
|
||||
<span class="ph uicontrol">Link State</span> icon does not display
|
||||
link speed and link duplex details.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187685</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, the Template Status displays no
|
||||
synchronization status (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Devices</span
|
||||
><span class="ph uicontrol">Summary</span></span
|
||||
>) after a bootstrapped firewall is successfully added to Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
|
||||
successfully added to Panorama,
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>log in to the Panorama web interface</a
|
||||
>
|
||||
and select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span></span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187407</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The configured Advanced Threat Prevention inline cloud analysis action
|
||||
for a given model might not be honored under the following condition:
|
||||
If the firewall is set to
|
||||
<span class="ph uicontrol"
|
||||
>Hold client request for category lookup </span
|
||||
>and the action set to
|
||||
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
|
||||
been cleared, the first request for inline cloud analysis will be
|
||||
bypassed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-186283</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Templates appear out-of-sync on Panorama after successfully deploying
|
||||
the CFT stack using the Panorama plugin for AWS.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Use
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span></span
|
||||
>
|
||||
to synchronize the templates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-184708</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Scheduled report emails (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">PDF Reports</span
|
||||
><span class="ph uicontrol">Email Scheduler</span></span
|
||||
>) are not emailed if:
|
||||
</div>
|
||||
<ul id="panos-known-issues-11.1.14_ul_bqh_5qx_rsb" class="ul">
|
||||
<li class="li">
|
||||
A scheduled report email contains a Report Group (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">PDF Reports</span
|
||||
><span class="ph uicontrol">Report Group</span></span
|
||||
>) which includes a SaaS Application Usage report.
|
||||
</li>
|
||||
<li class="li">
|
||||
A scheduled report contains only a SaaS Application Usage Report.
|
||||
</li>
|
||||
</ul>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> To receive a scheduled report email
|
||||
for all other PDF report types:
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.1.14_ol_jgs_zqx_rsb" class="ol">
|
||||
<li class="li">
|
||||
Select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">PDF Reports</span
|
||||
><span class="ph uicontrol">Report Groups</span></span
|
||||
>
|
||||
and remove all SaaS Application Usage reports from all Report
|
||||
Groups.
|
||||
</li>
|
||||
<li class="li">
|
||||
Select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">PDF Reports</span
|
||||
><span class="ph uicontrol">Email Scheduler</span></span
|
||||
>
|
||||
and edit the scheduled report email that contains only a SaaS
|
||||
Application Usage report. For the Recurrence, select
|
||||
<span class="ph uicontrol">Disable</span> and click
|
||||
<span class="ph uicontrol">OK</span>.
|
||||
<div class="p">
|
||||
Repeat this step for all scheduled report emails that contain only
|
||||
a SaaS Application Usage report.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<span class="ph uicontrol">Commit</span>.
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama managed firewalls</tt>) Select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Commit and Push</span></span
|
||||
>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-184406</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
|
||||
dmdb process to crash.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Contact customer support to stop the
|
||||
dmdb process before adding a RAID disk pair to a M-700 appliance.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-183404</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Static IP addresses are not recognized when "and" operators are used
|
||||
with IP CIDR range.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-181933</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
|
||||
all of the cards may not receive all of the updates and the mappings
|
||||
for the clients may become out of sync, which causes the firewall to
|
||||
not correctly populate the Source User column in the session logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,763 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 34%" />
|
||||
<col style="width: 66%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303959</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Traffic that is incorrectly identified as unknown-tcp/unknown-udp
|
||||
eventually drops due to an App-ID resource limitation issue.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292202</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The system logs repeatedly displayed the alert
|
||||
<span class="ph systemoutput"
|
||||
>Clearing snmpd.log due to log overflow</span
|
||||
>
|
||||
due to the SNMP counters rolling over. This is a benign message and
|
||||
does not impact device functionality.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289432 </b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Generating a certificate with the
|
||||
<span class="ph codeph">block-private-key yes</span> command on
|
||||
Panorama fails with the error:
|
||||
</div>
|
||||
<div class="p">
|
||||
<span class="ph codeph"
|
||||
>Could not get parameters for double encryption.</span
|
||||
>
|
||||
This occurred when the certificate was signed by an external
|
||||
Certificate Authority (CA).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286848</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
ECMP incorrectly balances sessions across links based on the
|
||||
configured metric, which leads to an imbalance in traffic distribution
|
||||
and results in traffic assignment shifting disproportionately to
|
||||
routes with lower metrics.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
|
||||
continue selections will function like a general URL-block action.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285894</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If the Preserve Pre-NAT feature is enabled, dataplane crashes may
|
||||
occur, which could result in firewall reboots.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Disable the Preserve Pre-NAT feature
|
||||
using the
|
||||
<span class="ph userinput"
|
||||
>set deviceconfig setting preserve-prenat-feature no</span
|
||||
>
|
||||
CLI command.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283429</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use custom certificates for the connection between Panorama
|
||||
and a log collector, the automated renewal for the predefined
|
||||
ElasticSearch certificates gets disrupted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Remove the custom certificates before
|
||||
the ElasticSearch certificates expire. This allows the system to
|
||||
correctly identify and renew the predefined ElasticSearch
|
||||
certificates. After the renewal is complete, re-install the custom
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279415</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Service routes configured for a data plane interface might incorrectly
|
||||
route traffic through the management plane interface instead. This
|
||||
issue impacts Syslog and CRL status traffic when the service route
|
||||
lacks a specific destination custom service route.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-275047</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) After an upgrade,
|
||||
the firewall is unable to send logs to the Strata Logging Service
|
||||
(SLS) when using a specific proxy server, and the SSL connection
|
||||
status displays as failed when attempting to forward logs through the
|
||||
web proxy.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-262556</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The ElasticSearch cluster health status might continue to remain
|
||||
yellow for an extended period after upgrading to PAN-OS 11.1
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260851</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
From the NGFW or Panorama CLI, you can override the existing
|
||||
application tag even if Disable Override is enabled for the
|
||||
application (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Applications</span></span
|
||||
>) tag.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254240</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In the event of an HSCI flap on an NGFW cluster node, traffic
|
||||
reconvergence takes three to four seconds.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-253963</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The auto commit job may take longer than expected to complete when the
|
||||
Panorama management server is in Panorama or Log Collector mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-251551</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When an NGFW cluster agent crashes and doesn't recover, leader
|
||||
election will take approximately 45 seconds to begin and traffic
|
||||
failover will occur during that time.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250903</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In a congestion scenario on an HSCI port of an NGFW cluster node, the
|
||||
QoS priorities of cross node traffic streams might be reversed if
|
||||
you're using the default QoS profile with class1 to class8 set as high
|
||||
to low.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247974</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
LACP flap is expected during a device failover in an NGFW cluster due
|
||||
to an L2 ctrld restart on the new leader node.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-234015</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-224502</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
|
||||
might take longer than expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-220180</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Configured botnet reports (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">Botnet</span></span
|
||||
>) are not generated.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207733</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls, if
|
||||
the DHCPv6 server goes down, after the lease time expires, the DHCPv6
|
||||
client should enter SOLICIT state on both the Active and Passive
|
||||
firewalls. Instead, the client is stuck in BOUND state with an IPv6
|
||||
address having lease time 0 on the Passive firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207611</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls, the
|
||||
Passive firewall sometimes crashes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207442</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
For M-700 appliances in an active/passive high availability (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">High Availability</span></span
|
||||
>) configuration, the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer
|
||||
configuration sync to the
|
||||
<span class="ph systemoutput">secondary-passive</span> HA peer may
|
||||
fail. When the config sync fails, the job Results is
|
||||
<span class="ph systemoutput">Successful</span>
|
||||
(<span class="ph uicontrol">Tasks</span>), however the sync status on
|
||||
the <span class="ph uicontrol">Dashboard</span> displays as
|
||||
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Perform a local commit on the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer and then
|
||||
synchronize the HA configuration.
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.1.16_ol_aqy_kbp_qxb" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Panorama web interface</a
|
||||
>
|
||||
of the <span class="ph systemoutput">active-primary</span> HA
|
||||
peer.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Select <span class="ph uicontrol">Commit</span> and
|
||||
<span class="ph uicontrol">Commit to Panorama</span>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
In the <span class="ph systemoutput">active-primary</span> HA peer
|
||||
<span class="ph uicontrol">Dashboard</span>, click
|
||||
<span class="ph uicontrol">Sync to Peer</span> in the High
|
||||
Availability widget.
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207040</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you disable Advanced Routing, remove logical routers, and downgrade
|
||||
from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
|
||||
commits fail and SD-WAN devices on Panorama have no Virtual Router
|
||||
name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-206913</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls,
|
||||
releasing the IPv6 address from the client (using Release in the UI or
|
||||
using the
|
||||
<span class="ph systemoutput"
|
||||
>request dhcp client ipv6 release all</span
|
||||
>
|
||||
CLI command) releases the IPv6 address from the Active firewall, but
|
||||
not the Passive firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-206909</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Dedicated Log Collector is unable to reconnect to the Panorama
|
||||
management server if the <span class="ph systemoutput">configd</span>
|
||||
process crashes. This results in the Dedicated Log Collector losing
|
||||
connectivity to Panorama despite the managed collector connection
|
||||
<span class="ph systemoutput">Status</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Collector</span></span
|
||||
>) displaying <span class="ph systemoutput">connected</span> and the
|
||||
managed colletor <span class="ph systemoutput">Health</span> status
|
||||
displaying as healthy.
|
||||
</div>
|
||||
<div class="p">
|
||||
This results in the local Panorama config and system logs not being
|
||||
forwarded to the Dedicated Log Collector. Firewall log forwarding to
|
||||
the disconnected Dedicated Log Collector is not impacted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Restart the
|
||||
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
|
||||
Log Collector.
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.1.16_ol_pdy_4bm_lvb" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Dedicated Log Collector CLI</a
|
||||
>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Confirm the Dedicated Log Collector is disconnected from Panorama.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
|
||||
<div class="p">
|
||||
Verify the <span class="ph systemoutput">Connected</span> status
|
||||
is <span class="ph systemoutput">no</span>.
|
||||
</div>
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197588</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The PAN-OS ACC (Application Command Center) does not display a widget
|
||||
detailing statistics and data associated with vulnerability exploits
|
||||
that have been detected using inline cloud analysis.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197419</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interface</span
|
||||
><span class="ph uicontrol">Ethernet</span></span
|
||||
>, the power over Ethernet (PoE) ports do not display a
|
||||
<span class="ph uicontrol">Tag</span> value.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-196758</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, pushing a configuration change to
|
||||
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
|
||||
configurations for SD-WAN as being edited or deleted despite no edits
|
||||
or deletions being made when you
|
||||
<span class="ph uicontrol">Preview Changes</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>
|
||||
or
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Commit and Push</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-195968</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
|
||||
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
|
||||
prints an error depending on whether an interface type was selected on
|
||||
the non-PoE port or not. If an interface type, such as tap, Layer 2,
|
||||
or virtual wire, was selected before PoE was configured, the error
|
||||
message will not include the interface name (eg. ethernet1/4). If an
|
||||
interface type was not selected before PoE was configured, the error
|
||||
message will include the interface name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-194978</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interface</span
|
||||
><span class="ph uicontrol">Ethernet</span></span
|
||||
>, hovering the mouse over a power over Ethernet (PoE)
|
||||
<span class="ph uicontrol">Link State</span> icon does not display
|
||||
link speed and link duplex details.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187685</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, the Template Status displays no
|
||||
synchronization status (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Devices</span
|
||||
><span class="ph uicontrol">Summary</span></span
|
||||
>) after a bootstrapped firewall is successfully added to Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
|
||||
successfully added to Panorama,
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>log in to the Panorama web interface</a
|
||||
>
|
||||
and select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span></span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187407</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The configured Advanced Threat Prevention inline cloud analysis action
|
||||
for a given model might not be honored under the following condition:
|
||||
If the firewall is set to
|
||||
<span class="ph uicontrol"
|
||||
>Hold client request for category lookup </span
|
||||
>and the action set to
|
||||
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
|
||||
been cleared, the first request for inline cloud analysis will be
|
||||
bypassed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-186283</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Templates appear out-of-sync on Panorama after successfully deploying
|
||||
the CFT stack using the Panorama plugin for AWS.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Use
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span></span
|
||||
>
|
||||
to synchronize the templates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-184708</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Scheduled report emails (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">PDF Reports</span
|
||||
><span class="ph uicontrol">Email Scheduler</span></span
|
||||
>) are not emailed if:
|
||||
</div>
|
||||
<ul id="panos-known-issues-11.1.16_ul_bqh_5qx_rsb" class="ul">
|
||||
<li class="li">
|
||||
A scheduled report email contains a Report Group (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">PDF Reports</span
|
||||
><span class="ph uicontrol">Report Group</span></span
|
||||
>) which includes a SaaS Application Usage report.
|
||||
</li>
|
||||
<li class="li">
|
||||
A scheduled report contains only a SaaS Application Usage Report.
|
||||
</li>
|
||||
</ul>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> To receive a scheduled report email
|
||||
for all other PDF report types:
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.1.16_ol_jgs_zqx_rsb" class="ol">
|
||||
<li class="li">
|
||||
Select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">PDF Reports</span
|
||||
><span class="ph uicontrol">Report Groups</span></span
|
||||
>
|
||||
and remove all SaaS Application Usage reports from all Report
|
||||
Groups.
|
||||
</li>
|
||||
<li class="li">
|
||||
Select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Monitor</span
|
||||
><span class="ph uicontrol">PDF Reports</span
|
||||
><span class="ph uicontrol">Email Scheduler</span></span
|
||||
>
|
||||
and edit the scheduled report email that contains only a SaaS
|
||||
Application Usage report. For the Recurrence, select
|
||||
<span class="ph uicontrol">Disable</span> and click
|
||||
<span class="ph uicontrol">OK</span>.
|
||||
<div class="p">
|
||||
Repeat this step for all scheduled report emails that contain only
|
||||
a SaaS Application Usage report.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<span class="ph uicontrol">Commit</span>.
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama managed firewalls</tt>) Select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Commit and Push</span></span
|
||||
>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-184406</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
|
||||
dmdb process to crash.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Contact customer support to stop the
|
||||
dmdb process before adding a RAID disk pair to a M-700 appliance.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-183404</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Static IP addresses are not recognized when "and" operators are used
|
||||
with IP CIDR range.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-181933</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
|
||||
all of the cards may not receive all of the updates and the mappings
|
||||
for the clients may become out of sync, which causes the firewall to
|
||||
not correctly populate the Source User column in the session logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -104,6 +104,105 @@
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-325120</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue affects PAN-OS 11.2.11</tt>
|
||||
</div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-12-known-and-addressed-issues/pan-os-11-2-12-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 11.2.12 Addressed Issues</a
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div dir="ltr" class="p">
|
||||
On PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms, certain
|
||||
PAN-OS versions may cause intermittent connectivity issues on Eth1/1
|
||||
SFP/RJ45 data port. Additionally, devices onboarded or managed via
|
||||
Eth1/1 lose call-home connectivity post-upgrade. The dedicated
|
||||
management port SFP or RJ45 are not affected.
|
||||
</div>
|
||||
<b class="ph b">Workaround</b>: Move the Eth1/1 connection to any other
|
||||
dataport (Eth1/2 to 1/9). Devices managed via Eth1/1 require an on-site
|
||||
administrator to manually move the connection from Eth1/1 to the
|
||||
dedicated management port. Devices managed via Eth1/1 require an on-site
|
||||
administrator to manually move the connection from Eth1/1 to the
|
||||
dedicated management port.
|
||||
<div dir="ltr" class="p">
|
||||
On the following platforms, PoE ports will not supply power. Ethernet
|
||||
traffic on PoE ports continues to function for devices that do not
|
||||
require inline power.
|
||||
</div>
|
||||
<ul id="panos-known-issues-11.2.11_ul-nhq_f3r_gjc" class="ul">
|
||||
<li dir="ltr" class="li">
|
||||
<div dir="ltr" class="p">
|
||||
Affected PoE ports on PA-415, PA-415-5G, PA-445: Eth1/6–Eth1/9
|
||||
</div>
|
||||
</li>
|
||||
<li dir="ltr" class="li">
|
||||
<div dir="ltr" class="p">
|
||||
Affected PoE ports on PA-455, PA-455-5G: Eth1/5–Eth1/8
|
||||
</div>
|
||||
</li>
|
||||
</ul>
|
||||
<b class="ph b">Workaround</b>: If power is needed from impacted PoE
|
||||
ports, downgrade to an unaffected PAN-OS version. See the
|
||||
<a
|
||||
class="xref"
|
||||
href="http://security.paloaltonetworks.com"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>May Security Advisory</a
|
||||
>
|
||||
for additional mitigations.
|
||||
<div class="p"><b class="ph b">All Affected PAN-OS Versions: </b></div>
|
||||
<ul id="panos-known-issues-11.2.11_ul-n5c_kjr_gjc" class="ul">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<b class="ph b">11.1: </b>11.1.10-h23, 11.1.10-h24, 11.1.10-h25,
|
||||
11.1.13-h4, 11.1.13-h5, 11.1.14
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<b class="ph b">11.2: </b>11.2.7-h12, 11.2.7-h13, 11.2.7-h14,
|
||||
11.2.10-h5, 11.2.10-h6, 11.2.10-h7, 11.2.11
|
||||
</li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-317755</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A selective push from Panorama to managed firewalls fail when plugin
|
||||
configurations reference certain Panorama settings, such as
|
||||
log-collector groups or access domains.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Perform a full push instead of a
|
||||
selective push as a temporary measure. Note that selective push
|
||||
attempts will continue to fail until you upgrade to the release that
|
||||
includes the fix.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
@@ -298,32 +397,6 @@
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254236</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
|
||||
Edge browsers results in dropped Client Hello packets when SSL/TLS
|
||||
handshake inspection is enabled.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Disable
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/inspect-ssl-tls-handshakes"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>SSL/TLS handshake inspection</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254108</b></div>
|
||||
@@ -433,6 +506,19 @@
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247728</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-1-known-and-addressed-issues/pan-os-11-2-1-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 11.2.1 Addressed Issues</a
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
@@ -678,7 +764,7 @@
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs">admin></span><span class="ph userinput hljs sql"> <span class="hljs-keyword">show</span> panorama-<span class="hljs-keyword">status</span></span></div></pre>
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
|
||||
<div class="p">
|
||||
Verify the <span class="ph systemoutput">Connected</span> status
|
||||
is <span class="ph systemoutput">no</span>.
|
||||
@@ -694,7 +780,7 @@
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs">admin></span><span class="ph userinput hljs nginx"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
|
||||
@@ -0,0 +1,880 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 34%" />
|
||||
<col style="width: 66%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6271</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A WildFire cluster node that has been configured with an IPv6
|
||||
management port might not display the signature status when using the
|
||||
following CLI:
|
||||
<span class="ph codeph"
|
||||
>show wildfire global signature-status sha256 equal
|
||||
<SHA_256_Value></span
|
||||
>
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the affected
|
||||
Wildfire cluster nodes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6259</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a WildFire cluster node configured as a server or worker node is
|
||||
rebooted, issuing the CLI command,
|
||||
<span class="ph codeph">global sample-status</span> does not update
|
||||
the samples processed list on the active controller and non-server
|
||||
worker nodes.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the affected
|
||||
WildFire active controller and passive controller in the cluster.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6270</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The WildFire cluster server and worker nodes might disconnect from the
|
||||
Wildfire cluster management network, resulting in a notifier process
|
||||
exit on WildFire cluster controllers.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the WildFire
|
||||
cluster node where the process exit occurred.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6222</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When WildFire secure cluster communication is enabled using a custom
|
||||
DNS, the cluster formation might fail due to cluster management
|
||||
communication issues.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Do not configure a custom DNS when
|
||||
WildFire secure cluster communication is enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6176</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Panorama is used to manage a WildFire cluster, switchover
|
||||
functionality for active and passive controller roles is not
|
||||
available.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-317755</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A selective push from Panorama to managed firewalls fail when plugin
|
||||
configurations reference certain Panorama settings, such as
|
||||
log-collector groups or access domains.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Perform a full push instead of a
|
||||
selective push as a temporary measure. Note that selective push
|
||||
attempts will continue to fail until you upgrade to the release that
|
||||
includes the fix.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Packets are dropped on SD-WAN interfaces if they require fragmentation
|
||||
for an interface but have the
|
||||
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
|
||||
results in unexpected packet drops. This affects client to server
|
||||
sessions when using SD-WAN for NGFW.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
|
||||
set (<span class="ph userinput"
|
||||
>debug dataplane set ip4-ignore-df yes</span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Strata Logging Service (SLS) log-forwarding streams intermittently
|
||||
show as inactive. When checking the status of log-forwarding
|
||||
connections, one or more streams are reported as inactive. Restarting
|
||||
the <span class="ph codeph">log-receiver</span> process temporarily
|
||||
resolves the issue, but the streams become inactive again after
|
||||
approximately 1-2 hours. This intermittent inactivity results in log
|
||||
loss.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295645</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a WildFire cluster is configured centrally using Panorama, it
|
||||
initiates a series of processes, including a software install and
|
||||
reboot, in an order that will leave the resulting WildFire cluster in
|
||||
an unusable state.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288525</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the Enterprise DLP data filtering profile is configured with a
|
||||
<span class="ph uicontrol">Block</span> action and is used in
|
||||
conjunction with Advanced Threat Prevention, which is configured with
|
||||
an action of <span class="ph uicontrol">reset-both</span>,
|
||||
<span class="ph uicontrol">reset-server</span>,
|
||||
<span class="ph uicontrol">reset-client</span>, or
|
||||
<span class="ph uicontrol">drop</span> for the
|
||||
<span class="ph uicontrol">HTTP Command and Control detector</span>,
|
||||
Dropbox file uploads that exceed the maximum configured file size
|
||||
action will fail.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Configure the Advanced Threat
|
||||
Prevention Inline Cloud analysis (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Security Profiles</span
|
||||
><span class="ph uicontrol">Anti-Spyware</span></span
|
||||
>) action for the HTTP Command and Control detector to
|
||||
<span class="ph uicontrol">alert</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285061</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Enterprise DLP is enabled, file uploads might unexpectedly fail
|
||||
when 100 continue response is received from the server during file
|
||||
uploads.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284700</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
File downloads for content encoded with zstd (Zstandard), such as
|
||||
specific content from box.com, fail when using Enterprise DLP because
|
||||
zstd decompression is not supported in PAN-OS.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283429</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use custom certificates for the connection between Panorama
|
||||
and a log collector, the automated renewal for the predefined
|
||||
ElasticSearch certificates gets disrupted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Remove the custom certificates before
|
||||
the ElasticSearch certificates expire. This allows the system to
|
||||
correctly identify and renew the predefined ElasticSearch
|
||||
certificates. After the renewal is complete, re-install the custom
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260851</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
From the NGFW or Panorama CLI, you can override the existing
|
||||
application tag even if Disable Override is enabled for the
|
||||
application (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Applications</span></span
|
||||
>) tag.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260212</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When viewing <span class="ph uicontrol">Applications</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Applications</span></span
|
||||
>), child App-IDs may be listed under the incorrect container App-ID.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259853</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the DHCP server is enabled for GlobalProtect, the commit error
|
||||
message is not properly displayed when
|
||||
<span class="ph uicontrol">Any</span> is selected as the source
|
||||
interface in the service router configuration (
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Device</span
|
||||
><span class="ph uicontrol">Setup</span
|
||||
><span class="ph uicontrol">Service</span
|
||||
><span class="ph uicontrol"></span
|
||||
><span class="ph uicontrol"
|
||||
>Service Router Configuration</span
|
||||
></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259423</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the GlobalProtect DHCP feature is enabled with two primary DHCP
|
||||
servers on the GlobalProtect gateway, the gpsvc gets stuck during
|
||||
renewal and after HA failover.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254108</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
when upgrading or downgrading a Panorama management server (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), managed device (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Device Deployment</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), or standalone firewall (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Device</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), <span class="ph uicontrol">Base Releases</span> and
|
||||
<span class="ph uicontrol">Preferred Releases</span> settings are
|
||||
checked (enabled) by default and cause no PAN-OS software images to
|
||||
display.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Uncheck (disable)
|
||||
<span class="ph uicontrol">Base Releases</span> or
|
||||
<span class="ph uicontrol">Preferred Releases</span> to display either
|
||||
the available base PAN-OS or preferred PAN-OS releases available to
|
||||
download and install.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-253963</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The auto commit job may take longer than expected to complete when the
|
||||
Panorama management server is in Panorama or Log Collector mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-252661</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you change the service route of gp-ip-mgmt in
|
||||
<b class="ph b"
|
||||
>Device > Setup > Services > Service Features >
|
||||
gp-ip-mgmt</b
|
||||
>
|
||||
and <b class="ph b">Commit</b>, the change won’t take effect.
|
||||
gp-ip-mgmt continues to use the last committed service route.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> After you change the service route
|
||||
interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
|
||||
gateway, click <b class="ph b">OK </b>to save the configuration, and
|
||||
<b class="ph b">Commit </b>the changes. This commit will include the
|
||||
service route change.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250246</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Panorama and the firewall display inconsistent IP addresses for
|
||||
dynamic address group members after manually syncing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250062</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Device telemetry might fail at configured intervals due to bundle
|
||||
generation issues.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-248836</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Advanced DNS Security trial license and trial license information
|
||||
cannot be activated and viewed, respectively, on a managed firewall
|
||||
(with expired or active status) from Panorama. These tasks can only be
|
||||
performed on the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247728</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-1-known-and-addressed-issues/pan-os-11-2-1-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 11.2.1 Addressed Issues</a
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Advanced Routing is enabled, IP multicast is not supported. An
|
||||
upcoming version will provide support for this feature. Customers who
|
||||
have multicast configured or who plan to deploy multicast routing
|
||||
should not upgrade to 11.2.0. Additionally, when Advanced Routing is
|
||||
enabled, the BGP dampening configuration isn't applied to any peers or
|
||||
peer group; the configuration is preserved but has no effect on BGP.
|
||||
Customers can use BGP even if they have applied a Dampening profile to
|
||||
a specific set of peers. The issue doesn't affect any other BGP
|
||||
features.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-241994</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
|
||||
and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
|
||||
Palo Alto Networks recommends that you upgrade your ESXi version if it
|
||||
is less than 6.7 U2. For more information, see the
|
||||
<a
|
||||
class="xref"
|
||||
href="https://kb.vmware.com/s/article/2007240"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
rel="nofollow"
|
||||
>compatibility matrix</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-239612</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
|
||||
enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
|
||||
agent doesn't work.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-237106</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
LSVPN satellite certificates may be generated with serial numbers
|
||||
exceeding 40 hexadecimal characters. This causes certificate
|
||||
revocation and deletion operations to fail with the following error
|
||||
messages:
|
||||
</div>
|
||||
<ul id="pan_os_11_2_12_known_issues_ul-hby_2gs_jjc" class="ul">
|
||||
<li class="li">
|
||||
<span class="ph systemoutput"
|
||||
>db-serialno can be at most 40 characters</span
|
||||
>
|
||||
</li>
|
||||
<li class="li">
|
||||
<span class="ph systemoutput">db-serialno is invalid</span>
|
||||
</li>
|
||||
</ul>
|
||||
<b class="ph b">Workaround:</b>
|
||||
<div class="p">
|
||||
To resolve this issue, use the following CLI commands with the LSVPN
|
||||
satellite serial number to manually delete or revoke the affected
|
||||
certificates:
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Delete certificate information</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store certificate-info portal name
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"><satellite_serial></var></span
|
||||
>
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Revoke satellite certificates</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store satellite-info-revoke-certificate portal
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"
|
||||
><list_of_satellite_serials></var
|
||||
></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-236649</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you change the configuration of a firewall acting as a PPPoEv4 or
|
||||
PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
|
||||
and route table for an inherited configuration with dynamic-identifier
|
||||
or client remain visible. Old routes also remain visible for an
|
||||
inherited interface when you execute the CLI command,
|
||||
<span class="ph userinput">show interface all</span>.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Unconfigure and configure the
|
||||
Inherited Interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-234015</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207442</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
For M-700 appliances in an active/passive high availability (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">High Availability</span></span
|
||||
>) configuration, the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer
|
||||
configuration sync to the
|
||||
<span class="ph systemoutput">secondary-passive</span> HA peer may
|
||||
fail. When the config sync fails, the job Results is
|
||||
<span class="ph systemoutput">Successful</span>
|
||||
(<span class="ph uicontrol">Tasks</span>), however the sync status on
|
||||
the <span class="ph uicontrol">Dashboard</span> displays as
|
||||
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Perform a local commit on the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer and then
|
||||
synchronize the HA configuration.
|
||||
</div>
|
||||
<ol id="pan_os_11_2_12_known_issues_ol-iby_2gs_jjc" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Panorama web interface</a
|
||||
>
|
||||
of the <span class="ph systemoutput">active-primary</span> HA
|
||||
peer.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Select <span class="ph uicontrol">Commit</span> and
|
||||
<span class="ph uicontrol">Commit to Panorama</span>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
In the <span class="ph systemoutput">active-primary</span> HA peer
|
||||
<span class="ph uicontrol">Dashboard</span>, click
|
||||
<span class="ph uicontrol">Sync to Peer</span> in the High
|
||||
Availability widget.
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-206909</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Dedicated Log Collector is unable to reconnect to the Panorama
|
||||
management server if the <span class="ph systemoutput">configd</span>
|
||||
process crashes. This results in the Dedicated Log Collector losing
|
||||
connectivity to Panorama despite the managed collector connection
|
||||
<span class="ph systemoutput">Status</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Collector</span></span
|
||||
>) displaying <span class="ph systemoutput">connected</span> and the
|
||||
managed colletor <span class="ph systemoutput">Health</span> status
|
||||
displaying as healthy.
|
||||
</div>
|
||||
<div class="p">
|
||||
This results in the local Panorama config and system logs not being
|
||||
forwarded to the Dedicated Log Collector. Firewall log forwarding to
|
||||
the disconnected Dedicated Log Collector is not impacted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Restart the
|
||||
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
|
||||
Log Collector.
|
||||
</div>
|
||||
<ol id="pan_os_11_2_12_known_issues_ol-jby_2gs_jjc" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Dedicated Log Collector CLI</a
|
||||
>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Confirm the Dedicated Log Collector is disconnected from Panorama.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
|
||||
<div class="p">
|
||||
Verify the <span class="ph systemoutput">Connected</span> status
|
||||
is <span class="ph systemoutput">no</span>.
|
||||
</div>
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197588</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The PAN-OS ACC (Application Command Center) does not display a widget
|
||||
detailing statistics and data associated with vulnerability exploits
|
||||
that have been detected using inline cloud analysis.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197419</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interface</span
|
||||
><span class="ph uicontrol">Ethernet</span></span
|
||||
>, the power over Ethernet (PoE) ports do not display a
|
||||
<span class="ph uicontrol">Tag</span> value.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-196758</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, pushing a configuration change to
|
||||
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
|
||||
configurations for SD-WAN as being edited or deleted despite no edits
|
||||
or deletions being made when you
|
||||
<span class="ph uicontrol">Preview Changes</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>
|
||||
or
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Commit and Push</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-195968</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
|
||||
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
|
||||
prints an error depending on whether an interface type was selected on
|
||||
the non-PoE port or not. If an interface type, such as tap, Layer 2,
|
||||
or virtual wire, was selected before PoE was configured, the error
|
||||
message will not include the interface name (eg. ethernet1/4). If an
|
||||
interface type was not selected before PoE was configured, the error
|
||||
message will include the interface name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187685</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, the Template Status displays no
|
||||
synchronization status (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Devices</span
|
||||
><span class="ph uicontrol">Summary</span></span
|
||||
>) after a bootstrapped firewall is successfully added to Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
|
||||
successfully added to Panorama,
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>log in to the Panorama web interface</a
|
||||
>
|
||||
and select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span></span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187407</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The configured Advanced Threat Prevention inline cloud analysis action
|
||||
for a given model might not be honored under the following condition:
|
||||
If the firewall is set to
|
||||
<span class="ph uicontrol"
|
||||
>Hold client request for category lookup </span
|
||||
>and the action set to
|
||||
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
|
||||
been cleared, the first request for inline cloud analysis will be
|
||||
bypassed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-184406</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
|
||||
dmdb process to crash.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Contact customer support to stop the
|
||||
dmdb process before adding a RAID disk pair to a M-700 appliance.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-183404</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Static IP addresses are not recognized when "and" operators are used
|
||||
with IP CIDR range.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-181933</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
|
||||
all of the cards may not receive all of the updates and the mappings
|
||||
for the clients may become out of sync, which causes the firewall to
|
||||
not correctly populate the Source User column in the session logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,880 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 34%" />
|
||||
<col style="width: 66%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6271</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A WildFire cluster node that has been configured with an IPv6
|
||||
management port might not display the signature status when using the
|
||||
following CLI:
|
||||
<span class="ph codeph"
|
||||
>show wildfire global signature-status sha256 equal
|
||||
<SHA_256_Value></span
|
||||
>
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the affected
|
||||
Wildfire cluster nodes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6259</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a WildFire cluster node configured as a server or worker node is
|
||||
rebooted, issuing the CLI command,
|
||||
<span class="ph codeph">global sample-status</span> does not update
|
||||
the samples processed list on the active controller and non-server
|
||||
worker nodes.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the affected
|
||||
WildFire active controller and passive controller in the cluster.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6270</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The WildFire cluster server and worker nodes might disconnect from the
|
||||
Wildfire cluster management network, resulting in a notifier process
|
||||
exit on WildFire cluster controllers.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Gracefully restart the WildFire
|
||||
cluster node where the process exit occurred.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6222</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When WildFire secure cluster communication is enabled using a custom
|
||||
DNS, the cluster formation might fail due to cluster management
|
||||
communication issues.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Do not configure a custom DNS when
|
||||
WildFire secure cluster communication is enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">WF500-6176</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Panorama is used to manage a WildFire cluster, switchover
|
||||
functionality for active and passive controller roles is not
|
||||
available.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-317755</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A selective push from Panorama to managed firewalls fail when plugin
|
||||
configurations reference certain Panorama settings, such as
|
||||
log-collector groups or access domains.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Perform a full push instead of a
|
||||
selective push as a temporary measure. Note that selective push
|
||||
attempts will continue to fail until you upgrade to the release that
|
||||
includes the fix.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Packets are dropped on SD-WAN interfaces if they require fragmentation
|
||||
for an interface but have the
|
||||
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
|
||||
results in unexpected packet drops. This affects client to server
|
||||
sessions when using SD-WAN for NGFW.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
|
||||
set (<span class="ph userinput"
|
||||
>debug dataplane set ip4-ignore-df yes</span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Strata Logging Service (SLS) log-forwarding streams intermittently
|
||||
show as inactive. When checking the status of log-forwarding
|
||||
connections, one or more streams are reported as inactive. Restarting
|
||||
the <span class="ph codeph">log-receiver</span> process temporarily
|
||||
resolves the issue, but the streams become inactive again after
|
||||
approximately 1-2 hours. This intermittent inactivity results in log
|
||||
loss.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295645</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a WildFire cluster is configured centrally using Panorama, it
|
||||
initiates a series of processes, including a software install and
|
||||
reboot, in an order that will leave the resulting WildFire cluster in
|
||||
an unusable state.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288525</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the Enterprise DLP data filtering profile is configured with a
|
||||
<span class="ph uicontrol">Block</span> action and is used in
|
||||
conjunction with Advanced Threat Prevention, which is configured with
|
||||
an action of <span class="ph uicontrol">reset-both</span>,
|
||||
<span class="ph uicontrol">reset-server</span>,
|
||||
<span class="ph uicontrol">reset-client</span>, or
|
||||
<span class="ph uicontrol">drop</span> for the
|
||||
<span class="ph uicontrol">HTTP Command and Control detector</span>,
|
||||
Dropbox file uploads that exceed the maximum configured file size
|
||||
action will fail.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Configure the Advanced Threat
|
||||
Prevention Inline Cloud analysis (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Security Profiles</span
|
||||
><span class="ph uicontrol">Anti-Spyware</span></span
|
||||
>) action for the HTTP Command and Control detector to
|
||||
<span class="ph uicontrol">alert</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285061</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Enterprise DLP is enabled, file uploads might unexpectedly fail
|
||||
when 100 continue response is received from the server during file
|
||||
uploads.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284700</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
File downloads for content encoded with zstd (Zstandard), such as
|
||||
specific content from box.com, fail when using Enterprise DLP because
|
||||
zstd decompression is not supported in PAN-OS.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283429</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you use custom certificates for the connection between Panorama
|
||||
and a log collector, the automated renewal for the predefined
|
||||
ElasticSearch certificates gets disrupted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Remove the custom certificates before
|
||||
the ElasticSearch certificates expire. This allows the system to
|
||||
correctly identify and renew the predefined ElasticSearch
|
||||
certificates. After the renewal is complete, re-install the custom
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260851</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
From the NGFW or Panorama CLI, you can override the existing
|
||||
application tag even if Disable Override is enabled for the
|
||||
application (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Applications</span></span
|
||||
>) tag.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260212</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When viewing <span class="ph uicontrol">Applications</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Objects</span
|
||||
><span class="ph uicontrol">Applications</span></span
|
||||
>), child App-IDs may be listed under the incorrect container App-ID.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259853</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the DHCP server is enabled for GlobalProtect, the commit error
|
||||
message is not properly displayed when
|
||||
<span class="ph uicontrol">Any</span> is selected as the source
|
||||
interface in the service router configuration (
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Device</span
|
||||
><span class="ph uicontrol">Setup</span
|
||||
><span class="ph uicontrol">Service</span
|
||||
><span class="ph uicontrol"></span
|
||||
><span class="ph uicontrol"
|
||||
>Service Router Configuration</span
|
||||
></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259423</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the GlobalProtect DHCP feature is enabled with two primary DHCP
|
||||
servers on the GlobalProtect gateway, the gpsvc gets stuck during
|
||||
renewal and after HA failover.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254108</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
when upgrading or downgrading a Panorama management server (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), managed device (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Device Deployment</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), or standalone firewall (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Device</span
|
||||
><span class="ph uicontrol">Software</span></span
|
||||
>), <span class="ph uicontrol">Base Releases</span> and
|
||||
<span class="ph uicontrol">Preferred Releases</span> settings are
|
||||
checked (enabled) by default and cause no PAN-OS software images to
|
||||
display.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Uncheck (disable)
|
||||
<span class="ph uicontrol">Base Releases</span> or
|
||||
<span class="ph uicontrol">Preferred Releases</span> to display either
|
||||
the available base PAN-OS or preferred PAN-OS releases available to
|
||||
download and install.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-253963</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The auto commit job may take longer than expected to complete when the
|
||||
Panorama management server is in Panorama or Log Collector mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-252661</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you change the service route of gp-ip-mgmt in
|
||||
<b class="ph b"
|
||||
>Device > Setup > Services > Service Features >
|
||||
gp-ip-mgmt</b
|
||||
>
|
||||
and <b class="ph b">Commit</b>, the change won’t take effect.
|
||||
gp-ip-mgmt continues to use the last committed service route.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> After you change the service route
|
||||
interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
|
||||
gateway, click <b class="ph b">OK </b>to save the configuration, and
|
||||
<b class="ph b">Commit </b>the changes. This commit will include the
|
||||
service route change.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250246</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Panorama and the firewall display inconsistent IP addresses for
|
||||
dynamic address group members after manually syncing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250062</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Device telemetry might fail at configured intervals due to bundle
|
||||
generation issues.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-248836</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Advanced DNS Security trial license and trial license information
|
||||
cannot be activated and viewed, respectively, on a managed firewall
|
||||
(with expired or active status) from Panorama. These tasks can only be
|
||||
performed on the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247728</b></div>
|
||||
<div class="p">
|
||||
<tt class="ph tt">This issue is now resolved. See </tt
|
||||
><a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/pan-os/11-2/pan-os-release-notes/pan-os-11-2-1-known-and-addressed-issues/pan-os-11-2-1-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 11.2.1 Addressed Issues</a
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When Advanced Routing is enabled, IP multicast is not supported. An
|
||||
upcoming version will provide support for this feature. Customers who
|
||||
have multicast configured or who plan to deploy multicast routing
|
||||
should not upgrade to 11.2.0. Additionally, when Advanced Routing is
|
||||
enabled, the BGP dampening configuration isn't applied to any peers or
|
||||
peer group; the configuration is preserved but has no effect on BGP.
|
||||
Customers can use BGP even if they have applied a Dampening profile to
|
||||
a specific set of peers. The issue doesn't affect any other BGP
|
||||
features.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-241994</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
|
||||
and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
|
||||
Palo Alto Networks recommends that you upgrade your ESXi version if it
|
||||
is less than 6.7 U2. For more information, see the
|
||||
<a
|
||||
class="xref"
|
||||
href="https://kb.vmware.com/s/article/2007240"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
rel="nofollow"
|
||||
>compatibility matrix</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-239612</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
|
||||
enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
|
||||
agent doesn't work.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-237106</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
LSVPN satellite certificates may be generated with serial numbers
|
||||
exceeding 40 hexadecimal characters. This causes certificate
|
||||
revocation and deletion operations to fail with the following error
|
||||
messages:
|
||||
</div>
|
||||
<ul id="panos-known-issues-11.2.13_ul-hby_2gs_jjc" class="ul">
|
||||
<li class="li">
|
||||
<span class="ph systemoutput"
|
||||
>db-serialno can be at most 40 characters</span
|
||||
>
|
||||
</li>
|
||||
<li class="li">
|
||||
<span class="ph systemoutput">db-serialno is invalid</span>
|
||||
</li>
|
||||
</ul>
|
||||
<b class="ph b">Workaround:</b>
|
||||
<div class="p">
|
||||
To resolve this issue, use the following CLI commands with the LSVPN
|
||||
satellite serial number to manually delete or revoke the affected
|
||||
certificates:
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Delete certificate information</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store certificate-info portal name
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"><satellite_serial></var></span
|
||||
>
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Revoke satellite certificates</b>:<span
|
||||
class="ph userinput"
|
||||
>delete sslmgr-store satellite-info-revoke-certificate portal
|
||||
<var class="keyword varname"><name></var> serialno
|
||||
<var class="keyword varname"
|
||||
><list_of_satellite_serials></var
|
||||
></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-236649</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you change the configuration of a firewall acting as a PPPoEv4 or
|
||||
PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
|
||||
and route table for an inherited configuration with dynamic-identifier
|
||||
or client remain visible. Old routes also remain visible for an
|
||||
inherited interface when you execute the CLI command,
|
||||
<span class="ph userinput">show interface all</span>.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Unconfigure and configure the
|
||||
Inherited Interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-234015</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207442</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
For M-700 appliances in an active/passive high availability (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">High Availability</span></span
|
||||
>) configuration, the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer
|
||||
configuration sync to the
|
||||
<span class="ph systemoutput">secondary-passive</span> HA peer may
|
||||
fail. When the config sync fails, the job Results is
|
||||
<span class="ph systemoutput">Successful</span>
|
||||
(<span class="ph uicontrol">Tasks</span>), however the sync status on
|
||||
the <span class="ph uicontrol">Dashboard</span> displays as
|
||||
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Perform a local commit on the
|
||||
<span class="ph systemoutput">active-primary</span> HA peer and then
|
||||
synchronize the HA configuration.
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.2.13_ol-iby_2gs_jjc" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Panorama web interface</a
|
||||
>
|
||||
of the <span class="ph systemoutput">active-primary</span> HA
|
||||
peer.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Select <span class="ph uicontrol">Commit</span> and
|
||||
<span class="ph uicontrol">Commit to Panorama</span>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
In the <span class="ph systemoutput">active-primary</span> HA peer
|
||||
<span class="ph uicontrol">Dashboard</span>, click
|
||||
<span class="ph uicontrol">Sync to Peer</span> in the High
|
||||
Availability widget.
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-206909</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The Dedicated Log Collector is unable to reconnect to the Panorama
|
||||
management server if the <span class="ph systemoutput">configd</span>
|
||||
process crashes. This results in the Dedicated Log Collector losing
|
||||
connectivity to Panorama despite the managed collector connection
|
||||
<span class="ph systemoutput">Status</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Collector</span></span
|
||||
>) displaying <span class="ph systemoutput">connected</span> and the
|
||||
managed colletor <span class="ph systemoutput">Health</span> status
|
||||
displaying as healthy.
|
||||
</div>
|
||||
<div class="p">
|
||||
This results in the local Panorama config and system logs not being
|
||||
forwarded to the Dedicated Log Collector. Firewall log forwarding to
|
||||
the disconnected Dedicated Log Collector is not impacted.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Restart the
|
||||
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
|
||||
Log Collector.
|
||||
</div>
|
||||
<ol id="panos-known-issues-11.2.13_ol-jby_2gs_jjc" class="ol">
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>Log in to the Dedicated Log Collector CLI</a
|
||||
>.
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Confirm the Dedicated Log Collector is disconnected from Panorama.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
|
||||
<div class="p">
|
||||
Verify the <span class="ph systemoutput">Connected</span> status
|
||||
is <span class="ph systemoutput">no</span>.
|
||||
</div>
|
||||
</div>
|
||||
</li>
|
||||
<li class="li">
|
||||
<div class="p">
|
||||
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
|
||||
</div>
|
||||
<!-- FM Dita Overlay for Code -->
|
||||
<div class="code-wrap">
|
||||
<pre
|
||||
class="pre codeblock"
|
||||
data-label="PRE CODEBLOCK"
|
||||
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
||||
</div>
|
||||
</li>
|
||||
</ol>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197588</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The PAN-OS ACC (Application Command Center) does not display a widget
|
||||
detailing statistics and data associated with vulnerability exploits
|
||||
that have been detected using inline cloud analysis.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-197419</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interface</span
|
||||
><span class="ph uicontrol">Ethernet</span></span
|
||||
>, the power over Ethernet (PoE) ports do not display a
|
||||
<span class="ph uicontrol">Tag</span> value.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-196758</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, pushing a configuration change to
|
||||
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
|
||||
configurations for SD-WAN as being edited or deleted despite no edits
|
||||
or deletions being made when you
|
||||
<span class="ph uicontrol">Preview Changes</span> (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>
|
||||
or
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Commit and Push</span
|
||||
><span class="ph uicontrol">Edit Selections</span></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-195968</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
|
||||
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
|
||||
prints an error depending on whether an interface type was selected on
|
||||
the non-PoE port or not. If an interface type, such as tap, Layer 2,
|
||||
or virtual wire, was selected before PoE was configured, the error
|
||||
message will not include the interface name (eg. ethernet1/4). If an
|
||||
interface type was not selected before PoE was configured, the error
|
||||
message will include the interface name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187685</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On the Panorama management server, the Template Status displays no
|
||||
synchronization status (<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Panorama</span
|
||||
><span class="ph uicontrol">Managed Devices</span
|
||||
><span class="ph uicontrol">Summary</span></span
|
||||
>) after a bootstrapped firewall is successfully added to Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
|
||||
successfully added to Panorama,
|
||||
<a
|
||||
class="xref"
|
||||
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>log in to the Panorama web interface</a
|
||||
>
|
||||
and select
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Commit</span
|
||||
><span class="ph uicontrol">Push to Devices</span></span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-187407</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The configured Advanced Threat Prevention inline cloud analysis action
|
||||
for a given model might not be honored under the following condition:
|
||||
If the firewall is set to
|
||||
<span class="ph uicontrol"
|
||||
>Hold client request for category lookup </span
|
||||
>and the action set to
|
||||
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
|
||||
been cleared, the first request for inline cloud analysis will be
|
||||
bypassed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-184406</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
|
||||
dmdb process to crash.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Contact customer support to stop the
|
||||
dmdb process before adding a RAID disk pair to a M-700 appliance.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-183404</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Static IP addresses are not recognized when "and" operators are used
|
||||
with IP CIDR range.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-181933</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
|
||||
all of the cards may not receive all of the updates and the mappings
|
||||
for the clients may become out of sync, which causes the firewall to
|
||||
not correctly populate the Source User column in the session logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,254 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row">
|
||||
<th class="entry">
|
||||
<div class="p">Issue ID</div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p">Description</div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-330836</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series software firewalls with 16 GB of memory and 16 vCPUs
|
||||
only</tt
|
||||
>) Starting in PAN-OS 12.1.5, memory usage increases to approximately
|
||||
6 GB for firewalls running a maximum configuration, compared to
|
||||
approximately 5 GB in PAN-OS 12.1.2. This increase eliminates the
|
||||
available memory buffer, leaving no capacity to absorb additional
|
||||
memory demand during peak load. The firewall may become unstable or
|
||||
unresponsive under high-load conditions.
|
||||
</div>
|
||||
<div class="p">
|
||||
Firewalls operating with 12 dp cores, or processing more than 512K
|
||||
sessions, are specifically at risk for memory issues. To ensure
|
||||
continued stability for firewalls matching this criteria, Palo Alto
|
||||
Networks recommends an increase of overall memory allocation by 2 GB.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p">
|
||||
PAN-317755<tt class="ph tt">This issue is now resolved. See</tt>
|
||||
<a
|
||||
class="xref"
|
||||
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-7-known-and-addressed-issues/pan-os-12-1-7-h1-addressed-issues.html"
|
||||
title=""
|
||||
data-scope="local"
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>PAN-OS 12.1.7-h1 Addressed Issues</a
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A selective push from Panorama to managed firewalls fail when plugin
|
||||
configurations reference certain Panorama settings, such as
|
||||
log-collector groups or access domains.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Perform a full push instead of a
|
||||
selective push as a temporary measure. Note that selective push
|
||||
attempts will continue to fail until you upgrade to the release that
|
||||
includes the fix.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-312143</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(Firewalls in active/passive high availability (HA) configurations
|
||||
only) When attempting to synchronize the running configuration with an
|
||||
HA peer, particularly during script runs involving different topology
|
||||
builds (e.g., during a smoke runlist), the synchronization process
|
||||
fails. This results in an error indicating that the running
|
||||
configuration could not be synchronized with the HA peer.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-311601</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If the node is seen stuck with fault "session clearing fault". Node
|
||||
reboot is the workaround to get the node back in online state after
|
||||
all other fault conditions are removed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-310328</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If the node is seen stuck with fault "session clearing fault". Node
|
||||
reboot is the workaround to get the node back in online state after
|
||||
all other fault conditions are removed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-300667</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Panorama cannot display Threat log entries (Monitor > Logs >
|
||||
Threat) when the managed log collector is running a lower PAN-OS
|
||||
release than Panorama. Workaround: Upgrade the log collectors to the
|
||||
same version as Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-300230</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(NGFW Cluster) In an NGFW cluster, your pings to the HSCI-B link might
|
||||
fail, even when the link indicates it is up. In the event that the
|
||||
HSCI-A link is brought down or unplugged, the cluster node will
|
||||
transition to failed state, avoiding split brain as both HSCI links
|
||||
are down in this case. Workaround: Reboot the cluster node to resolve
|
||||
the HSCI-B ping issue.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-299562</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a client sends a Client Hello with Transport Layer Security (TLS)
|
||||
1.3 or TLS 1.2, using only the p-192 elliptic curve and some
|
||||
non-perfect forward secrecy (PFS) ciphers, the firewall discards the
|
||||
Client Hello. The firewall should allow the connection to proceed
|
||||
using TLS 1.2, maintaining backward compatibility with previous
|
||||
releases.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-298083</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Draft for review: After you change the system mode on an M-700
|
||||
appliance from Panorama mode to PAN-DB private cloud mode, the snmpd
|
||||
process fails to work.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-295946</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a Panorama appliance (running PAN-OS 12.1.2 or higher) manages
|
||||
firewalls running PAN-OS versions lower than 12.1.2, and an NTP server
|
||||
configuration template includes SHA256 or SHA512 as the authentication
|
||||
mechanism, pushing this template to the firewalls running PAN-OS
|
||||
versions lower than 12.1.2 will cause the commit operation to fail.
|
||||
Workaround: Create two separate templates: one for firewalls running
|
||||
PAN-OS 12.1.2 or higher (which can include SHA256/SHA512
|
||||
authentication) and another for firewalls running PAN-OS versions
|
||||
lower than 12.1.2 (which should use other authentication algorithms
|
||||
such as SHA1, MD5, or Autokey). Then, push the appropriate template to
|
||||
the corresponding devices from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-292601</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
|
||||
configuration for an address object. If there are two address objects
|
||||
with same FQDN, but one object has Load Balanced DNS enabled and other
|
||||
object has Load Balanced DNS disabled, then the policy match for the
|
||||
removed IP addresses doesn't work as expected. Workaround: Enable (or
|
||||
disable) Load Balanced DNS consistently for an FQDN that is used with
|
||||
multiple address objects.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-289524</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
|
||||
IP addresses from a Load balanced DNS server and use them in a policy
|
||||
match. However, this functionality does not work as intended when the
|
||||
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
|
||||
enabled, the DNS resolution works as if the Load balanced DNS flag
|
||||
(for an Address object) is disabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-283028</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The following error is thrown when an existing template overrides the
|
||||
SD-WAN configuration followed by the commit and push from Panorama to
|
||||
the firewall.
|
||||
</div>
|
||||
<div class="p">
|
||||
BGP is invalid. AS number does not fit in 2 byte AS format
|
||||
</div>
|
||||
<div class="p">
|
||||
This issue occurs because different AS formats are present on the
|
||||
Panorama and the firewall (the firewall configuration is generated by
|
||||
the SD-WAN plugin). That is, both the hub and branch firewall must
|
||||
have the same AS format in hub-and-spoke topology. In full mesh
|
||||
topology, all the firewalls must have the same AS format.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,317 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row">
|
||||
<th class="entry">
|
||||
<div class="p">Issue ID</div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p">Description</div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-330995</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Within GCP NSI environments, egress traffic logs fail to accurately
|
||||
reflect the designated NAT IP addresses.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-330964</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In PA-VM deployed on GCP instances, it is observed that the gVNIC
|
||||
interfaces appear inactive after enabling jumbo frames.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-330906</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On Panorama, the configuration Push Scope might not include the shared
|
||||
<span class="ph uicontrol">Devices</span> object entries, even though
|
||||
these objects are visible in the staged configuration changes for the
|
||||
specified administrator and device group.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-330902</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After restarting MongoDB (mdb) on Panorama using the
|
||||
<span class="ph userinput"
|
||||
>request mongo set mongo-update-sort-limit</span
|
||||
>
|
||||
CLI command, push to devices (both full push and selective push)
|
||||
fails.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround</b>: Restart
|
||||
<span class="ph userinput">configd</span> on Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-330836</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series software firewalls with 16 GB of memory and 16 vCPUs
|
||||
only</tt
|
||||
>) Starting in PAN-OS 12.1.5, memory usage increases to approximately
|
||||
6 GB for firewalls running a maximum configuration, compared to
|
||||
approximately 5 GB in PAN-OS 12.1.2. This increase eliminates the
|
||||
available memory buffer, leaving no capacity to absorb additional
|
||||
memory demand during peak load. The firewall may become unstable or
|
||||
unresponsive under high-load conditions.
|
||||
</div>
|
||||
<div class="p">
|
||||
Firewalls operating with 12 dp cores, or processing more than 512K
|
||||
sessions, are specifically at risk for memory issues. To ensure
|
||||
continued stability for firewalls matching this criteria, Palo Alto
|
||||
Networks recommends an increase of overall memory allocation by 2 GB.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p">PAN-329146</div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Within GCP NSI environments, it is observed that the Prisma AIRS
|
||||
license activates geneve parsing as a
|
||||
<i class="ph i">default setting</i>, permitting intraVPC traffic flow
|
||||
regardless of NSI status. Hence, you will not be able to disable this
|
||||
feature through CLI.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-313669</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(PA-5500 Series firewalls in cluster configurations only) When a
|
||||
firewall node is removed from a PA-5500 Series cluster, after the
|
||||
cluster commit and reboot, the node starts in standalone mode with a
|
||||
default virtual wire (vwire) configuration loaded. This default
|
||||
configuration is missing zone assignments for ports eth1/1 and eth1/2,
|
||||
which causes commit operations to fail. Even if zones are manually
|
||||
assigned to these ports, subsequent commit attempts will fail with a
|
||||
"no UUId for rule1" error.
|
||||
</div>
|
||||
<div class="p">
|
||||
<span class="ph uicontrol">Workaround:</span> To resolve this, either:
|
||||
</div>
|
||||
<ul class="ul">
|
||||
<li class="li">
|
||||
Manually assign zone configurations to ports eth1/1 (e.g., untrust)
|
||||
and eth1/2 (e.g., trust), then open and close security policy rule1
|
||||
without making changes, and
|
||||
<span class="ph uicontrol">Commit</span>.
|
||||
</li>
|
||||
<li class="li">
|
||||
Delete the default rule and the default virtual wire Ethernet
|
||||
interfaces, then commit.
|
||||
</li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-312143</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(Firewalls in active/passive high availability (HA) configurations
|
||||
only) When attempting to synchronize the running configuration with an
|
||||
HA peer, particularly during script runs involving different topology
|
||||
builds (e.g., during a smoke runlist), the synchronization process
|
||||
fails. This results in an error indicating that the running
|
||||
configuration could not be synchronized with the HA peer.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-311601</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If the node is seen stuck with fault "session clearing fault". Node
|
||||
reboot is the workaround to get the node back in online state after
|
||||
all other fault conditions are removed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-310328</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If the node is seen stuck with fault "session clearing fault". Node
|
||||
reboot is the workaround to get the node back in online state after
|
||||
all other fault conditions are removed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-300667</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Panorama cannot display Threat log entries (Monitor > Logs >
|
||||
Threat) when the managed log collector is running a lower PAN-OS
|
||||
release than Panorama. Workaround: Upgrade the log collectors to the
|
||||
same version as Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-300230</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(NGFW Cluster) In an NGFW cluster, your pings to the HSCI-B link might
|
||||
fail, even when the link indicates it is up. In the event that the
|
||||
HSCI-A link is brought down or unplugged, the cluster node will
|
||||
transition to failed state, avoiding split brain as both HSCI links
|
||||
are down in this case. Workaround: Reboot the cluster node to resolve
|
||||
the HSCI-B ping issue.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-299562</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a client sends a Client Hello with Transport Layer Security (TLS)
|
||||
1.3 or TLS 1.2, using only the p-192 elliptic curve and some
|
||||
non-perfect forward secrecy (PFS) ciphers, the firewall discards the
|
||||
Client Hello. The firewall should allow the connection to proceed
|
||||
using TLS 1.2, maintaining backward compatibility with previous
|
||||
releases.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-298083</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Draft for review: After you change the system mode on an M-700
|
||||
appliance from Panorama mode to PAN-DB private cloud mode, the snmpd
|
||||
process fails to work.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-295946</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a Panorama appliance (running PAN-OS 12.1.2 or higher) manages
|
||||
firewalls running PAN-OS versions lower than 12.1.2, and an NTP server
|
||||
configuration template includes SHA256 or SHA512 as the authentication
|
||||
mechanism, pushing this template to the firewalls running PAN-OS
|
||||
versions lower than 12.1.2 will cause the commit operation to fail.
|
||||
Workaround: Create two separate templates: one for firewalls running
|
||||
PAN-OS 12.1.2 or higher (which can include SHA256/SHA512
|
||||
authentication) and another for firewalls running PAN-OS versions
|
||||
lower than 12.1.2 (which should use other authentication algorithms
|
||||
such as SHA1, MD5, or Autokey). Then, push the appropriate template to
|
||||
the corresponding devices from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-293718</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Draft for review: When high speed logging is enabled on a PA-5560
|
||||
device, the expected warning message is not displayed on the web
|
||||
interface. This prevents administrators from being notified that logs
|
||||
can only be viewed from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-292601</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
|
||||
configuration for an address object. If there are two address objects
|
||||
with same FQDN, but one object has Load Balanced DNS enabled and other
|
||||
object has Load Balanced DNS disabled, then the policy match for the
|
||||
removed IP addresses doesn't work as expected. Workaround: Enable (or
|
||||
disable) Load Balanced DNS consistently for an FQDN that is used with
|
||||
multiple address objects.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-289524</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
|
||||
IP addresses from a Load balanced DNS server and use them in a policy
|
||||
match. However, this functionality does not work as intended when the
|
||||
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
|
||||
enabled, the DNS resolution works as if the Load balanced DNS flag
|
||||
(for an Address object) is disabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry"><div class="p">PAN-283028</div></td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The following error is thrown when an existing template overrides the
|
||||
SD-WAN configuration followed by the commit and push from Panorama to
|
||||
the firewall.
|
||||
</div>
|
||||
<div class="p">
|
||||
BGP is invalid. AS number does not fit in 2 byte AS format
|
||||
</div>
|
||||
<div class="p">
|
||||
This issue occurs because different AS formats are present on the
|
||||
Panorama and the firewall (the firewall configuration is generated by
|
||||
the SD-WAN plugin). That is, both the hub and branch firewall must
|
||||
have the same AS format in hub-and-spoke topology. In full mesh
|
||||
topology, all the firewalls must have the same AS format.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,573 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row">
|
||||
<th class="entry">
|
||||
<div class="p">Issue ID</div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p">Description</div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-332943</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you upgrade a PA-450R, PA-450R-5G, PA-410R, or PA-410R-5G
|
||||
firewall to PAN-OS 12.2.2 from an earlier release with Fail-to-Wire
|
||||
enabled, subsequent manual commits fail with the following validation
|
||||
error: network -> interface -> fail-open is invalid. This occurs
|
||||
because PAN-OS 12.2.2 introduced a configuration schema change for the
|
||||
Fail-to-Wire feature that is not automatically migrated during
|
||||
upgrade. Fail-to-Wire also does not function correctly after the
|
||||
upgrade.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b>Remove and re-add the Fail-to-Wire
|
||||
configuration.
|
||||
</div>
|
||||
<div class="p">
|
||||
<span class="keyword cmdname"
|
||||
>delete network interface fail-open</span
|
||||
>
|
||||
</div>
|
||||
<div class="p"><span class="keyword cmdname">commit</span></div>
|
||||
<div class="p">
|
||||
<span class="keyword cmdname">set network interface fail-open</span>
|
||||
</div>
|
||||
<div class="p"><span class="keyword cmdname">commit</span></div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-332874</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On 5G firewalls, Zero Touch Provisioning (ZTP) over cellular does not
|
||||
complete when the cellular carrier MTU is 1428. During ZTP, the
|
||||
firewall does not correctly account for cellular tunnel header
|
||||
overhead when negotiating the TCP maximum segment size (MSS). The
|
||||
firewall advertises an MSS value that is too large for the 1428 MTU
|
||||
cellular link, causing the certificate server's response packets to
|
||||
exceed the link MTU. The certificate fetch does not complete, and the
|
||||
firewall does not finish provisioning.
|
||||
</div>
|
||||
<div class="p">
|
||||
This issue occurs when using a cellular connection with a
|
||||
carrier-negotiated MTU of 1428, which is the standard MTU for cellular
|
||||
wireless. ZTP process will succeed when carrier provided Network MTU
|
||||
is greater than or equal to 1500.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-332576</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On HA pairs running PAN-OS 12.2.2, the useridd process may exhaust its
|
||||
ID manager (type 17) when the passive firewall accumulates more than
|
||||
1,000,000 user entries. When this occurs, useridd consumes 100% CPU
|
||||
and becomes unresponsive, causing commits to fail with the error
|
||||
Management server failed to send phase 1 to client useridd or to stall
|
||||
at 0%.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-332130</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On firewalls with cellular interfaces configured with parent and
|
||||
sub-interfaces, APN authentication fails on sub-interfaces when the
|
||||
PDP type is set to both (IPv4 and IPv6). Data sessions on the parent
|
||||
interface establish successfully for both IPv4 and IPv6, but
|
||||
sub-interfaces fail to bring up their data sessions when using PAP or
|
||||
CHAP authentication with PDP type both.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Set the PDP type to IPv4 only on
|
||||
sub-interfaces.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-331987</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(PA-5450, PA-5500, and PA-7500 firewalls with PAN-OS Shield enabled)
|
||||
When connecting to GlobalProtect Portal or Gateway, users receive a
|
||||
`Portal unreachable` error. GlobalProtect connections are frequently
|
||||
unsuccessful, though they may connect successfully after multiple
|
||||
attempts.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Change the session distribution policy
|
||||
to Round-robin.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-331722</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On PA-54R-POE (BH/Eagle) firewalls, the PAN-S-SFP-100BASE-FX
|
||||
transceiver on fiber interfaces does not link up when the interface
|
||||
link speed is explicitly set to 100 Mbps. The interface links up
|
||||
correctly when the link speed is set to auto.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Set the interface link speed to auto.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-331659</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Running the CLI command debug dataplane packet-path-test counter on
|
||||
PAN-OS 12.2.2 returns a server error instead of counter output.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-330995</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Within GCP NSI environments, egress traffic logs fail to accurately
|
||||
reflect the designated NAT IP addresses.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-330974</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If Azure hotplug events occur, the firewall may experience a crash and
|
||||
data interfaces may transition to an unknown state, leading to traffic
|
||||
disruption.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-330964</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In PA-VM deployed on GCP instances, gVNIC interfaces appear inactive
|
||||
after enabling jumbo frames.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-330381</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When firewalls are configured in a cluster operating in default mode,
|
||||
IP-Tag, User-Tag, and IP-Port mappings registered on the leader node
|
||||
do not synchronize to the follower node. On the follower node,
|
||||
commands such as `show object registered-ip all` and `show object
|
||||
registered-user all` display no registered entries for these data
|
||||
types, even though they are present on the leader. This prevents
|
||||
Dynamic Address Group (DAG) and Dynamic User Group (DUG) based
|
||||
security policies, which rely on these mappings, from functioning
|
||||
correctly on the follower node. As a result, traffic routed through
|
||||
the follower node does not match these policies, leading to an
|
||||
inconsistent security posture across the cluster.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Configure the firewall cluster to
|
||||
operate in ICD mode. This enables the correct synchronization of
|
||||
IP-Tag, User-Tag, and IP-Port mappings between the leader and follower
|
||||
nodes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-329606</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On PA-54R-POE (BH) firewalls, SCP export and import of cellular
|
||||
firmware files fail from the CLI. Running
|
||||
<span class="ph codeph">request cellular firmware scp-export</span> or
|
||||
<span class="ph codeph">request cellular firmware scp-import</span>
|
||||
returns a server error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-329515</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When scheduling cellular firmware downloads on Panorama (<b
|
||||
class="ph b"
|
||||
>Device Deployment > Cellular Firmware > Schedule</b
|
||||
>), the Files and Devices fields are not populated in the UI for
|
||||
PA-54R-POE-5G (BH/Eagle) devices. As a result, scheduled Download Only
|
||||
and Download and Install operations for cellular firmware cannot be
|
||||
configured through Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-329146</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Within GCP NSI environments, the Prisma® AIRS license activates geneve
|
||||
parsing as a default setting, permitting intraVPC traffic flow
|
||||
regardless of NSI status. You cannot disable this feature through CLI.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-328647</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When you configure ML7-CUID in a multi-vsys environment on PAN-OS
|
||||
12.2.2, data upload only supports the hub vsys configuration. When a
|
||||
publisher is configured on a non-hub vsys, data from that vsys is not
|
||||
uploaded to the cloud. All vsys must share the same segment
|
||||
configuration for data upload to function correctly in this release.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Configure the publisher on the hub
|
||||
vsys and ensure all vsys use the same segment configuration.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-327958</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(PA-5450 Firewalls only) Basic authentication for web proxy is not
|
||||
supported in 12.2.2.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-326791</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a Hyperscale Security Fabric (HSF) cluster uses an offline
|
||||
license, the system allows the removal of configuration and
|
||||
uninstallation of the Security Fabric License (SFL) plugin. If the SFL
|
||||
plugin is uninstalled under these conditions, subsequent undeploy
|
||||
operations do not complete successfully.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> To allow the undeploy operation to
|
||||
complete, reinstall the Security Fabric License (SFL) plugin.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-316972</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After downgrading a PA-520 firewall from PAN-OS 12.2.0 to 12.1.5 or
|
||||
later 12.1.x releases, auto-commit repeatedly fails after the
|
||||
downgrade completes, leaving the firewall unable to apply its
|
||||
configuration automatically.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-314625</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The `useridd` process restarts when you attempt to dump the Host
|
||||
Information Profile (HIP) database using the `debug user-id dump
|
||||
hip-profile-database` command. This occurs while the firewall is
|
||||
actively processing HIP reports, such as logouts or updates. The
|
||||
command initially hangs and times out before the `useridd` process
|
||||
restarts.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-313669</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(PA-5500 Series firewalls in cluster configurations only) When a
|
||||
firewall node is removed from a PA-5500 Series cluster, after the
|
||||
cluster commit and reboot, the node starts in standalone mode with a
|
||||
default virtual wire (vwire) configuration loaded. This default
|
||||
configuration is missing zone assignments for ports eth1/1 and eth1/2,
|
||||
which causes commit operations to fail. Even if zones are manually
|
||||
assigned to these ports, subsequent commit attempts fail with a "no
|
||||
UUId for rule1" error.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Manually assign zone configurations to
|
||||
ports eth1/1 (for example, untrust) and eth1/2 (for example, trust),
|
||||
then open and close security policy rule1 without making changes, and
|
||||
commit. Alternatively, delete the default rule and the default virtual
|
||||
wire Ethernet interfaces, then commit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-312143</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(Firewalls in active/passive high availability (HA) configurations
|
||||
only) When you synchronize the running configuration with an HA peer,
|
||||
particularly during script runs involving different topology builds,
|
||||
the synchronization process fails with an error indicating that the
|
||||
running configuration could not be synchronized with the HA peer.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-311601</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If a node is stuck with a "session clearing fault," reboot the node to
|
||||
restore it to an online state after all other fault conditions are
|
||||
removed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-310328</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
If a node is stuck with a "session clearing fault," reboot the node to
|
||||
restore it to an online state after all other fault conditions are
|
||||
removed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-309410</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Subscriber Identity and Equipment Identity values are missing from URL
|
||||
filtering and Data Filtering logs for GTP mobility traffic.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-305734</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
On firewalls with 5G cellular interfaces, the default auto MTU value
|
||||
of 1428 bytes causes IP fragmentation errors and out-of-order packets,
|
||||
resulting in degraded throughput performance on cellular connections.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Manually set the cellular interface
|
||||
MTU to 1500 bytes instead of using the auto MTU default.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-300667</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Panorama cannot display Threat log entries (<b class="ph b"
|
||||
>Monitor > Logs > Threat</b
|
||||
>) when the managed log collector is running a lower PAN-OS release
|
||||
than Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Upgrade the log collectors to the same
|
||||
version as Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-300230</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(NGFW Cluster) In an NGFW cluster, pings to the HSCI-B link may fail
|
||||
even when the link indicates it is up. If the HSCI-A link is brought
|
||||
down or unplugged, the cluster node transitions to a failed state,
|
||||
avoiding split brain because both HSCI links are down.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Reboot the cluster node to resolve the
|
||||
HSCI-B ping issue.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-299562</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a client sends a Client Hello with TLS 1.3 or TLS 1.2 using only
|
||||
the p-192 elliptic curve and some non-perfect forward secrecy (PFS)
|
||||
ciphers, the firewall discards the Client Hello. The firewall should
|
||||
allow the connection to proceed using TLS 1.2, maintaining backward
|
||||
compatibility with previous releases.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-299286</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When configuring a PIM6 neighbor filter, you must include both the
|
||||
primary and secondary IPv6 addresses of each neighbor in the prefix
|
||||
list. Filtering on the primary address alone is not sufficient because
|
||||
PIM6 Hello messages (Option 5) advertise both addresses to peers. A
|
||||
filter that allows only the primary address will prevent neighbor
|
||||
adjacency from forming.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-298083</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
After you change the system mode on an M-700 appliance from Panorama
|
||||
mode to PAN-DB private cloud mode, the snmpd process fails to work.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-295946</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When a Panorama appliance running PAN-OS 12.1.2 or later manages
|
||||
firewalls running earlier PAN-OS versions, and an NTP server
|
||||
configuration template includes SHA256 or SHA512 as the authentication
|
||||
mechanism, pushing the template to firewalls running PAN-OS versions
|
||||
earlier than 12.1.2 causes the commit operation to fail.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Create two separate templates: one for
|
||||
firewalls running PAN-OS 12.1.2 or later (which can include
|
||||
SHA256/SHA512 authentication) and another for firewalls running
|
||||
earlier PAN-OS versions (which should use SHA1, MD5, or Autokey). Push
|
||||
the appropriate template to the corresponding devices from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-294752</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In any 15-second interval, if connectivity (CI or management) on a
|
||||
GW-Node (not P-Node) changes more than once, with each change
|
||||
occurring on a different node and affecting a different link, the
|
||||
cluster loses its leader, all routing protocols fail, and traffic is
|
||||
blackholed if route changes occur in the network.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Reboot nodes that are in a FAILED
|
||||
state or suspend and unsuspend any online GW-Node (not P-Node).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-293718</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When high-speed logging is enabled on a PA-5560 firewall, the expected
|
||||
warning message does not appear on the web interface. This prevents
|
||||
you from being notified that logs can only be viewed from Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-292601</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
PAN-OS 12.1.2 and later 12.1 releases support a load-balanced DNS
|
||||
configuration for an address object. If two address objects share the
|
||||
same FQDN but one has load-balanced DNS enabled and the other has it
|
||||
disabled, the policy match for removed IP addresses does not work as
|
||||
expected.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Workaround:</b> Enable or disable load-balanced DNS
|
||||
consistently for any FQDN used with multiple address objects.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-289524</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In PAN-OS 12.1.2 and later and PAN-OS 12.2.2 and later releases,
|
||||
PAN-OS can obtain resolved IP addresses from a load-balanced DNS
|
||||
server and use them in a policy match. However, this functionality
|
||||
does not work as intended when the DNS cache reuse flag is enabled.
|
||||
When the DNS cache reuse flag is enabled, the DNS resolution works as
|
||||
if the load-balanced DNS flag (for an address object) is disabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PAN-283028</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
When an existing template overrides the SD-WAN configuration followed
|
||||
by a commit and push from Panorama to the firewall, the following
|
||||
error occurs: BGP is invalid. AS number does not fit in 2 byte AS
|
||||
format. This issue occurs because different AS formats are present on
|
||||
Panorama and the firewall (the firewall configuration is generated by
|
||||
the SD-WAN plugin). In hub-and-spoke topology, both the hub and branch
|
||||
firewall must have the same AS format. In full mesh topology, all
|
||||
firewalls must have the same AS format.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">PLUG-23656</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
In Software Firewall Licensed HSF environments, serial numbers linked
|
||||
to stale entries can be manually released for reuse. This procedure
|
||||
allows for the recovery of Software Firewall License credits when
|
||||
virtual instances are deleted without being formally decommissioned.
|
||||
For optimal resource management, it is recommended to utilize
|
||||
Orchestration plugin workflows for VM operations rather than manual
|
||||
intervention.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
Reference in New Issue
Block a user