Revise PAN-OS 11.2 addressed issues
This commit is contained in:
@@ -0,0 +1,61 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272809</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-0012"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-0012</a
|
||||
>
|
||||
(<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>PAN-SA-2024-0015</a
|
||||
>) and
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-9474"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-9474</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,389 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PLUG-16383</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the <span class="ph systemoutput">PAN_NET_FILE_TMP</span> was not
|
||||
found after an upgrade, which caused the firewall to enter maintenance
|
||||
mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-240174</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when LSVPN serial numbers and IP address
|
||||
authentication were enabled, IPv6 address ranges and complete IPv6
|
||||
addresses that were manually added to the IP address allow or exclude
|
||||
list were not usable after a restart of the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>gp_broker</a
|
||||
>
|
||||
process or the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-230362</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall truncated the payload of a TCP Out
|
||||
of Order segment with a FIN flag.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-228386</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue with session caching where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process stopped responding due to null values.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-227344</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where
|
||||
<span class="ph uicontrol">PDF Summary Reports</span> (<span
|
||||
class="ph uicontrol"
|
||||
>Monitor > PDF Reports > Manage PDF Summary</span
|
||||
>) displayed no data and were blank when predefined widgets were
|
||||
included in the summary report.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-227305</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SCEP certificate generation failed when a service
|
||||
route was used to reach the SCEP server.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-227224</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1400 Series firewalls</tt>) Fixed an issue where
|
||||
the firewall was unable to handle GRE packets for Point-to-Point
|
||||
Tunneling Protocol (PPTP) connections.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-226626</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall generated numerous
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
error messages related to netflow.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-225394</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where SNMP incorrectly reported high
|
||||
packet descriptor usage.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-225240</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the OSPF neighbor state remained in
|
||||
<span class="ph systemoutput">exstart</span> when the OSPF network had
|
||||
more than 40 routes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-225183</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SSH tunnels were unstable due to ciphers used as
|
||||
part of the high availability SSH configuration.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-224772</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed a high memory usage issue with the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>mongodb</a
|
||||
>
|
||||
process that caused an OOM condition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-224365</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where excessive network path monitoring messages were
|
||||
generated in the system logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-224067</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where cookie authentication did not work for
|
||||
GlobalProtect when an authentication override domain was configured in
|
||||
the SAML authentication profile.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-223501</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where diagnostic information for the dataplane in the
|
||||
dp-monitor.log file was not complete.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-223365</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama was unbale to query any logs if the
|
||||
Elasticsearch health status for any log collector was degraded.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-220881</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the CLI command
|
||||
<span class="ph systemoutput">show logging-status</span> did not
|
||||
correctly display the last log created and forwarded timestamps.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-220640</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where
|
||||
the firewall CPU percentage was miscalculated, and the values that
|
||||
were displayed were incorrect.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-219768</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where you were unable to filter Data Filtering logs
|
||||
with <span class="ph uicontrol">Threat ID/NAME</span> for custom data
|
||||
patterns created over Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-219585</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where enabling
|
||||
<span class="ph systemoutput">syslog-ng</span> debugs from the root
|
||||
caused 100% disk utilization.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-217510</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where inbound DHCP packets received by a DHCP client
|
||||
interface that were not addressed to itself were silently dropped
|
||||
instead of forwarded.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-208567</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue with email formatting where, when a scheduled email
|
||||
contained two or more attachments, only one attachment was visible.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-207003</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
process netflow buffer was not reset which resulted in duplicate
|
||||
netflow records.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-202095</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the web interface where the language setting is not
|
||||
retained.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PLUG-16385</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the file
|
||||
<span class="ph codeph">PAN_NET_FILE_TMP</span> was missing after the
|
||||
upgrade causing the VM-Series firewall to go into maintenance mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,61 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272809</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-0012"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-0012</a
|
||||
>
|
||||
(<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>PAN-SA-2024-0015</a
|
||||
>) and
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-9474"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-9474</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,146 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-257919</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when using explicit proxy with SAML
|
||||
authentication, initiating SAML authentication with a non-GET request
|
||||
resulted in a <span class="ph uicontrol">302 redirect</span> response
|
||||
instead of the expected
|
||||
<span class="ph uicontrol">200 ok</span> response.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-256343</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when Advanced Routing Engine was enabled and
|
||||
OSPFv3 was configured, the CLI command
|
||||
<span class="ph systemoutput"
|
||||
>show advanced-routing ospf interface</span
|
||||
>
|
||||
caused traffic to be disrupted, and the interface and area information
|
||||
did not display in CLI or the web interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255868</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
|
||||
where the firewall entered maintenance mode after enabling kernel data
|
||||
collection during the silent reboot.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-252661</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where changes to the gp-ip-mgmt service route did not
|
||||
take effect after a commit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255227</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the the MAC address was sent to the DHCP server
|
||||
instead of the hostname on macOS endpoints.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254236</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Client Hello packets were dropped when SSL/TLS
|
||||
handshake inspection was enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-249292</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Microsoft Azure environments only</tt
|
||||
>) Fixed an issue where CPU usage was higher than expected after a
|
||||
hotplug event when Accelerated Networking was enabled for the
|
||||
management interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-236909</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when you committed the first configuration
|
||||
change after booting up the firewall, the external dynamic list file
|
||||
download failed until the list was refreshed. This occurred when the
|
||||
configuration was pushed with a certificate profile.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-164885</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where
|
||||
<span class="ph uicontrol">Commit and Push</span> or
|
||||
<span class="ph uicontrol">Push to Devices</span> operations failed
|
||||
when an external dynamic list was configured to check for updates
|
||||
every 5 minutes due to the commit and external dynamic fetch processes
|
||||
overlapping.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,96 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306534</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue were the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process repeatedly restarted due to memory pool corruption when
|
||||
processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred
|
||||
due to incorrect buffer length calculations during memory deallocation
|
||||
when the query name field spanned multiple packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-305480</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process stopped responding while processing DoH JSON format traffic
|
||||
with DoH Security enabled, which caused missing cross-packet bytes in
|
||||
the decoded DNS query type field, and the dataplane went down.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-305301</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where GlobalProtect notifications in tunnels caused
|
||||
processes to stop responding and the dataplane to restart due to the
|
||||
session lookup returning an incorrect session, which resulted in the
|
||||
data being sent through the wrong tunnel.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303836</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the AIRS VM on session table reset intermittently
|
||||
dropped packets, which resulted in packet loss on responses to egress
|
||||
traffic.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,339 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306306</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances in FIPS-CC mode only</tt>)
|
||||
Fixed interdevice TLS communication failures that occurred with RSA
|
||||
and RSA-PSS signature algorithms across multiple layer 7 application
|
||||
services.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303051</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where a memory leak occurred related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process due to retaining memory that was temporarily used for report
|
||||
generation instead of releasing the memory for reuse, which resulted
|
||||
in continuous accumulation and memory exhaustion.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302927</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading Panorama, the
|
||||
<span class="ph uicontrol">Push to Devices</span> option did not
|
||||
display selected devices, and the
|
||||
<span class="ph uicontrol">OK</span> and
|
||||
<span class="ph uicontrol">Cancel</span>
|
||||
buttons did not function as expected. Selecting
|
||||
<span class="ph uicontrol">OK</span> did not close the window, and
|
||||
selecting <span class="ph uicontrol">Cancel</span> returned to the
|
||||
main push screen with the push selected devices displaying as empty.
|
||||
Despite this, selecting <span class="ph uicontrol">Push</span> or
|
||||
<span class="ph uicontrol">Validate Device Group Push</span> still
|
||||
pushed to the previously canceled, non-displayed devices.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301801</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Log Collectors where the Elasticsearch process
|
||||
fluctuated intermittently between green and red states, which led to
|
||||
interruptions in log collection. This issue occurred when the number
|
||||
of shards exceeded the cluster's maximum supported threshold of
|
||||
greater than 1000 shards per Elasticsearch instance.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301691</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where BGP stopped responding with the error message
|
||||
<span class="ph systemoutput">Too many open files</span> when pushing
|
||||
1000 eBGP (External BGP) neighbor configurations. With this fix, the
|
||||
number of file descriptors for the BGP process is increased from 1024
|
||||
to 8192.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301456</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where the
|
||||
<span class="ph systemoutput">debug system reset-ztp</span> CLI
|
||||
command was unavailable.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300216</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when SD-WAN Direct Internet Access was
|
||||
configured and traffic traversed the cellular interface without a NAT
|
||||
policy rule, intermittent cellular modem connectivity issues occurred,
|
||||
which caused the firewall to disconnect and reconnect to the cellular
|
||||
network.
|
||||
</div>
|
||||
<div class="p">
|
||||
To use this fix, run the CLI command
|
||||
<span class="ph systemoutput"
|
||||
>set session teardown-upon-fwd-zonechange yes</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300138</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS queries stalled or repeatedly time out due to
|
||||
multiple DNS responses with different CNAME values causing evasion
|
||||
false positive alerts.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299815</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on multi-vsys firewalls where a host was not removed
|
||||
from the quarantine list after receiving a redistribution message from
|
||||
Panorama. This occurred when Panorama was configured to redistribute
|
||||
quarantine messages to a firewall cluster, and the GlobalProtect
|
||||
configuration and redistribution were built out in a vsys other than
|
||||
vsys1.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298387</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where the source and destination NAT IP
|
||||
addresses did not display in traffic and threat logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-297610</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall became unresponsive after an upgrade
|
||||
due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>fsck</a
|
||||
>
|
||||
command scanning drive partitions in parallel with the root partition,
|
||||
which caused the process to take an extended amount of time.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297005</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where exporting custom reports resulted in empty CSV
|
||||
files.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296977</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the web interface became unresponsive when
|
||||
attempting to view
|
||||
<span class="ph uicontrol">Ethernet</span> interface details after
|
||||
applying a filter in
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interfaces</span></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296694</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process repeatedly restarting during an IP-port data type writes to
|
||||
the redis from multiple sources such as TSA or XML in a scale
|
||||
environment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296535</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where BGP peers disconnected when more
|
||||
than 500 BGP neighbors were configured in a single Logical Router
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295899</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS resolution failed on Linux machines running
|
||||
GlobalProtect client version 6.2.6 when connected with DNS Security
|
||||
enabled. This occurred because the firewall incorrectly discarded DNS
|
||||
packets when processing multiple DNS requests or responses over the
|
||||
same session, even when no malicious verdict was received.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276525</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Resolved multiple issues affecting IPSec tunnels using NAT Traversal
|
||||
(NAT-T) when a Dynamic NAT policy was configured (including Dynamic
|
||||
NAT or DIPP). During rekey events, tunnels could go down or flap due
|
||||
to incorrect session handling. This issue impacted both cluster and
|
||||
standalone deployments.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-209516</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when creating an interface, an error occurred
|
||||
when you clicked <span class="ph uicontrol">OK</span> without
|
||||
providing a value in the <span class="ph uicontrol">Tag</span> field
|
||||
even though the field was not displayed as mandatory.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-185731</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall was unable to parse the URL path and
|
||||
host when the host header was located in a different packet, which
|
||||
resulted in the firewall not logging the URL path in the first packet.
|
||||
</div>
|
||||
<div class="p">
|
||||
The fix is disabled by default. The following CLI commands can be used
|
||||
to enable/disable the feature: set system setting ctd
|
||||
url-crosspkt-host-path-caching enable set system setting ctd
|
||||
url-crosspkt-host-path-caching disable set system setting ctd
|
||||
url-crosspkt-host-path-caching default
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,160 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-307901</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a leak in decryption counters caused resource
|
||||
exhaustion, which led to a GlobalProtect service outage.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-307702</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||
issue where traffic passing through AE layer 2 interfaces was
|
||||
interrupted during HA failovers.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306451</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
|
||||
Fixed an issue where, after upgrading the firewall to an affected
|
||||
release, GlobalProtect clients did not connect with IPSec and instead
|
||||
connected using SSL due to traffic flow being disabled when checking
|
||||
for health check packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306103</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-3400 and PA-5400 Series firewalls only</tt>)
|
||||
Fixed an issue where the firewall dataplane frequently restarted when
|
||||
lockless QoS was enabled
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303959</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where traffic was incorrectly identified as
|
||||
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
|
||||
dropped.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301409</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama failed to perform a selective push to a
|
||||
managed device when device tags were added or modified on the policy
|
||||
rules. The selective push failed with the error message
|
||||
<span class="ph systemoutput"
|
||||
>Failed to generate selective push configuration. Schema validation
|
||||
failed. Please try a full push</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301222</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS Security logs incorrectly displayed a
|
||||
sinkhole action for benign DNS categories due to the firewall saving
|
||||
the drop or sinkhole action in session flags without discarding the
|
||||
session.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300638</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the firewall stopped responding due to an out-of-bounds read when
|
||||
parsing TLS 1.3 clientHello messages with large TLS clientHello
|
||||
extensions where the
|
||||
<span class="ph systemoutput">supported_versions</span> extension fell
|
||||
outside the first TCP segment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295803</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Addressed a memory leak issue under sc3 and automatic commit recovery
|
||||
(ACR) code path.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289723</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall web interface continuously loaded
|
||||
and not display any output when viewing the Route Table or FIB table
|
||||
(<span class="ph uicontrol">More Runtime Stats</span>). This issue
|
||||
occurred when L3 configurations were added to ethernet and AE
|
||||
interfaces.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,224 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308902</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading to an affected release, the
|
||||
firewall did not add mTLS websites that required client certificate
|
||||
authentication via DN list to the ssl-decrypt exclude-cache list.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308654</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Elasticsearch Close Indices process closed
|
||||
more indices than expected and dropped the number of open shards below
|
||||
the minimum of 800 per Elasticsearch instance. This occurred because
|
||||
the process did not correctly account for the number of Elasticsearch
|
||||
instances when calculating the maximum number of allowed open shards.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304718</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where OSPF and BGP outages occurred due to an
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process restart during clientless VPN content rewrite processing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304576</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall entered a non-functional state due
|
||||
to segmentation fault within the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_pktproc</a
|
||||
>
|
||||
process that was caused by a session that involved http2 cleartext
|
||||
traffic
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after unregistering an IP tag and registering a
|
||||
different IP tag for the same IP address via XML API, the dynamic
|
||||
address group membership was not updated on the dataplane, which
|
||||
resulted in Security policy rules being enforced incorrectly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303722</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where configuring spyware and
|
||||
vulnerability profiles in Security policy rules caused a memory leak
|
||||
in the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>devsrvr</a
|
||||
>
|
||||
process with each configuration commit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302790</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, with Sender Side Loop Detection enabled, BGP
|
||||
WITHDRAWAL updates were not sent to peers after a route was removed,
|
||||
which caused stale routes to persist in the BGP table of neighboring
|
||||
firewalls.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-288001</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where devices with 5G cellular modems did not support
|
||||
the ATT FirstNet auto Access Point Name (APN).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285181</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the wifclient ran out of memory when Enhanced
|
||||
Application Logging was enabled and a sudden traffic increase caused a
|
||||
surge in EAL messages sent through WIF.
|
||||
</div>
|
||||
<div class="p">
|
||||
To use this fix, run the CLI command
|
||||
<span class="ph codeph">debug iot eal memory-gc native</span>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278688</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS Security threat logs were not displayed on
|
||||
the firewall when packet capture was enabled and the domain name
|
||||
length was 62 characters.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273158</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
|
||||
where an incorrect ASIC configuration caused silent packet drops or
|
||||
application slowness when receiving a mix of jumbo and non-jumbo
|
||||
packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269228</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process stopped responding, which caused a split brain condition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,549 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-318275</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the firewall became unresponsive and did not automatically reboot,
|
||||
which led to prolonged outages. With this fix, the Linux kernel
|
||||
configuration will trigger a system panic and reboot.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-316911</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||
only</tt
|
||||
>) Fixed an issue where a newly bootstrapped firewall required a
|
||||
management server restart, relicensing, or license push from Panorama
|
||||
to invoke the device certificate.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-315912</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Maximum Segment Size (MSS) rewrite
|
||||
functionality for packets ingressing through SD-WAN interfaces on
|
||||
firewalls was not optimized.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-314147</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces
|
||||
with member having different MTU.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313623</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
|
||||
directory on Palo Alto Networks devices with TPM support became 100%
|
||||
utilized due to an accumulation of undeleted
|
||||
<span class="ph systemoutput">.pub_pem</span> files. This occurred
|
||||
because executing the
|
||||
<span class="ph systemoutput">show device-certificate status</span>
|
||||
CLI command initiated a process that generated these files but failed
|
||||
to remove them, which prevented the fetching of new device
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313216</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls with Prisma Access incorrectly
|
||||
displayed some traffic as unsanctioned in traffic logs for cloud
|
||||
applications that were tagged as
|
||||
<span class="ph uicontrol">sanctioned</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-312706</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewalls restarted due to a function lacking
|
||||
a NULL-pointer sanity check.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-311512</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where HIP (Host Information Profile) reports were
|
||||
blocked on GlobalProtect when
|
||||
<span class="ph uicontrol"
|
||||
>Authentication Cookie Usage Restrictions</span
|
||||
>
|
||||
was enabled and the Prisma Access Agent protocol was in use. This
|
||||
occurred because the system failed to correctly process HIP messages
|
||||
that were relayed via IPSec tunnels with a Virtual IP as the source,
|
||||
leading to their rejection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-309300</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where management plane system resources configuration
|
||||
size exceeded 28 MB for over 4 hours, and the following error message
|
||||
was displayed:
|
||||
<span class="ph systemoutput"
|
||||
>Configuration size reaching device capacity limit</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308786</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
||||
traffic log queries using the
|
||||
<span class="ph uicontrol">device_name</span> filter returned no
|
||||
results, and complex log queries that included negation operators
|
||||
produced incorrect outputs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where packets were dropped on SD-WAN interfaces when a
|
||||
proxy was enabled due to an MTU inconsistency where the firewall
|
||||
failed to rewrite the maximum segment size in SYN/ACK packets based on
|
||||
the SD-WAN virtual interface MTU.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Note</b>: This fix does not apply when the traffic
|
||||
egress interface is SD-WAN Direct Internet Access (DIA) interface
|
||||
and proxy is enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
|
||||
issue where the firewall intermittently failed to maintain active log
|
||||
forwarding streams to Strata Logging Service (SLS) even when duplicate
|
||||
logging and enhanced application logging were enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308418</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when Advanced DNS Security was enabled and
|
||||
experienced unusually high loads, DNS resolution failures occurred
|
||||
with the error
|
||||
<span class="ph uicontrol">resources-unavailable</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306555</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall stopped responding, which led to
|
||||
service outages.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304019</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the firewall did not send traffic to SCM or SLS via a configured
|
||||
explicit proxy IP address when the proxy username was not configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303745</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where inter-dataplane forwarding did not work for
|
||||
sessions ingressing on Slot 2, which resulted in intermittent ping
|
||||
failures to interfaces on Network Card 2 when traffic was forwarded to
|
||||
Slot 3.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Note</b>: With this fix, after a slot restart, the
|
||||
global counter will still show dot1q errors for a short period.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where a path monitoring failure
|
||||
occurred and caused the dataplane to restart.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301653</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS traffic sessions prematurely terminated with
|
||||
the message
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>resources-unavailable</a
|
||||
>. This occurred due to IPv4 fragmented DNS responses causing the
|
||||
Advanced DNS Security module to incorrectly pack the DNS payload
|
||||
multiple times when forwarding to the cloud for inspection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302983</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after committing changes on Panorama, a shared
|
||||
post-rule moved to the end of the
|
||||
<span class="ph systemoutput">post shared rulebase</span> on the
|
||||
managed device instead of remaining at the top.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300837</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls experienced multiple reboots due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process restarting with a SIGSEGV signal. This occurred because the
|
||||
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300671</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where traffic reports that were generated with
|
||||
destination/source and destination/source hostnames were not displayed
|
||||
in IPv4 format.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300423</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
|
||||
and 6 remained stuck in a starting state with the error
|
||||
<span class="ph uicontrol"
|
||||
>Signal detected for port xeS5-DP0 but Link Down</span
|
||||
>
|
||||
alerts, which resulted in device instability.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299242</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall's SSL proxy sent an empty HTTP2
|
||||
SETTINGS message to the client before confirming server support, which
|
||||
caused some clients to incorrectly assume HTTP/2 support and not fall
|
||||
back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad
|
||||
Request frames from the server, which prevented the client from
|
||||
correctly detecting the lack of HTTP/2 support.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298617</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Optimized the commit workflow to reduce the size of the effective
|
||||
configuration, resulting in lower memory consumption.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297708</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a long-lived session with many Machine Learning
|
||||
(ML) model triggers caused a memory leak of feature states associated
|
||||
with the ML model runs. This resulted in Spyware_State failure
|
||||
increases, allocation max outs, and impaired policy matching.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295802</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a memory leak related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process occurred.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295309</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where OSPF session using MD5 authentication experienced
|
||||
intermittent flapping due to out-of-order packet processing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293644</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||
issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process stopped responding during an External Dynamic List (EDL)
|
||||
refresh.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290938</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where multiple memory leaks occurred related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-264762</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall showed the status of SFP+ interfaces
|
||||
as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
|
||||
connected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263691</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a
|
||||
memory leak in the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250339</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Added an improvement to automatically clean up idle HTTP connection
|
||||
pools to address an issue where idle connection pools accumulated when
|
||||
a circuit breaker limit was reached, which caused client requests to
|
||||
fail with a 503
|
||||
<span class="ph systemoutput">no_healthy_upstream</span> error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-248913</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Elasticsearch client certificate was not auto
|
||||
renewed, which caused it to enter a Red state, and logs were not
|
||||
displayed in Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,31 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263349</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an error in the bundling of software components.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,61 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272809</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-0012"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-0012</a
|
||||
>
|
||||
(<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>PAN-SA-2024-0015</a
|
||||
>) and
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-9474"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-9474</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,96 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-258702</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">WF-500 appliances only</tt>) Fixed an issue where
|
||||
the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>varrcvr</a
|
||||
>
|
||||
process stopped responding when files were being forwarded to the
|
||||
WildFire cloud.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255773</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where errors related to applications in
|
||||
<span class="ph uicontrol">Content-preview</span> caused commit
|
||||
failures.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-248508</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||
only</tt
|
||||
>) Fixed an issue where the firewall did not perform MSS clamping when
|
||||
GWLB endpoints were mapped to static subinterfaces.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247099</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall decrypted traffic unexpectedly when
|
||||
the client hello was spread across multiple packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-251929</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where inbound decryption did not work when FIPS self
|
||||
tests were turned on.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,87 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272809</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-0012"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-0012</a
|
||||
>
|
||||
(<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>PAN-SA-2024-0015</a
|
||||
>) and
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-9474"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-9474</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-247230</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the syslog forwarding configuration did not
|
||||
include the full path for Security policy rules.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259997</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-3410, PA-3420, and PA-3430 firewalls only</tt>)
|
||||
Fixed an issue where the install failed when upgrading from PAN-OS
|
||||
10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number
|
||||
of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,95 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273215</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a syntax error in the index generation script
|
||||
caused a high management plane CPU load after upgrading.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271613</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where configuration pushes from Panorama to the
|
||||
firewall failed due to an OOXML commit error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269404</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not reset the maximum latency
|
||||
timer for hold mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268823</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where
|
||||
<span class="ph uicontrol">Monitor > Log Display</span> did not
|
||||
display all logs when you applied a filter.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-264549</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after modifying a policy rule on Panorama,
|
||||
pushes to the Cloud NGFW failed with the error
|
||||
<span class="ph systemoutput">saas-user-list unexpected here</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259078</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where WildFire Analysis reports were not generated and
|
||||
the following error message was displayed:
|
||||
<span class="ph uicontrol">Error 500: Internal Server Error</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,61 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272809</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-0012"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-0012</a
|
||||
>
|
||||
(<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>PAN-SA-2024-0015</a
|
||||
>) and
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2024-9474"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2024-9474</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,732 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292503</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where the source and destination NAT IP
|
||||
addresses did not display in traffic & threat logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290996</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SNMP walks returned a value of 0 for the CPS
|
||||
(Connections Per Second) per vsys on firewalls after upgrading to
|
||||
PAN-OS 11.1.6-h3, even when active connections were present.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290088</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a memory leak occurred related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process when pushing configurations from Panorama to a firewall. This
|
||||
occurred when the configurations contained shared policy rules.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287838</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue on
|
||||
the web interface where resetting the rule hit counter for multiple
|
||||
policy rules failed with the error message
|
||||
<span class="ph systemoutput">Failed to reset rule-hit job</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287056</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where BGP export policy rules with next-hop matching
|
||||
failed to block the advertisement of static routes, and the firewall
|
||||
incorrectly matched the egress interface IP address instead of the
|
||||
original next-hop IP address of the static route, which caused the
|
||||
deny rule to fail.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287023</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a large number of logs caused the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
process to stop responding.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286848</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where ECMP incorrectly balanced sessions across links
|
||||
based on the configured metric, which led to an imbalance in traffic
|
||||
distribution and resulted in traffic assignment shifting
|
||||
disproportionately to routes with lower metrics.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286306</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when getting transceiver information from ESCC
|
||||
for SFP 25G modules, the transceiver code was incorrectly updated with
|
||||
<span class="ph systemoutput">Unknown</span> instead of
|
||||
<span class="ph systemoutput">25GBase-SR</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284117</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances in Log Collector mode only</tt
|
||||
>) Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>vm_agent</a
|
||||
>
|
||||
process restarted after an upgrade.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284073</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall that caused commits to fail and the web
|
||||
interface to become inaccessible.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284003</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where clients did not receive a valid response when
|
||||
searching a website due to a compression error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282391</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
|
||||
Fixed an issue where a VLD memory leak caused increased memory use,
|
||||
which resulted in OOM errors.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282359</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Panorama web interface was slower than
|
||||
expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-281649</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the index size limit was incorrectly calculated
|
||||
and indices rolled over earlier than expected, which resulted in high
|
||||
memory and OOM errors.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-281509</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
||||
log exports were slower than expected or failed when filtering logs
|
||||
after an upgrade, which resulted in timeouts or delays in displaying
|
||||
logs on the web interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279500</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where TLS connections failed to establish in asymmetric
|
||||
routing environments if the firewall did not see server-to-client
|
||||
(s2c) packets of the TLS handshake.
|
||||
</div>
|
||||
<div class="p">
|
||||
To use this fix, run the following CLI command:
|
||||
<span class="ph systemoutput"
|
||||
>debug dataplane set ssl-decrypt accumulate-client-hello
|
||||
asym-disable yes</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279415</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where service routes configured to use a data plane
|
||||
interface incorrectly used the management plane interface for traffic
|
||||
transmission. This issue affected syslog and CRL status traffic when a
|
||||
custom service route was not configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278812</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where authentication to GlobalProtect failed with the
|
||||
error message
|
||||
<span class="ph systemoutput">User not in allowed list</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278150</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall removed the Authentication Key
|
||||
Identifier (AKID) from the certificate during SSL decryption, which
|
||||
caused Python 3.13 to fail with a certificate verification error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-277417</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an memory leak issue related to TLS inbound decryption.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-277147</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where daily scheduled reports were not generated and
|
||||
emailed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276920</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where web-advertisement traffic was not immediately
|
||||
blocked which resulted in pages loading indefinitely.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276616</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where half-duplex settings on Ethernet
|
||||
were not visible.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276276</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-450 firewalls only</tt>) Fixed an issue where,
|
||||
after an upgrade, data that was excluded using the query builder in a
|
||||
custom report was still visible in the report, and the logs displayed
|
||||
errors related to invalid threat names being queried.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-275047</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue
|
||||
where, after an upgrade, the firewall was unable to send logs to the
|
||||
Strata Logging Service (SLS) when using a specific proxy server, and
|
||||
the SSL connection status displayed as failed when attempting to
|
||||
forward logs through the web proxy.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-275032</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
|
||||
the Elasticsearch cluster certificate (CC) status displayed with a
|
||||
past expiration date, which caused all shards to be unassigned.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-274671</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where empty traffic
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logdb</a
|
||||
>
|
||||
folders were generated for each day even when trafcfic logs were not
|
||||
received by the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272812</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
|
||||
zero values for received bytes and packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271810</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where auto-negotiation advertised and negotiated 10/100
|
||||
half and full duplex.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271700</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where User-ID connections were lost after an HA
|
||||
failover.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271560</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS requests to malware sites were not blocked as
|
||||
expected, and the
|
||||
<span class="ph systemoutput">dns-security-categories log-level</span>
|
||||
and action displayed default values instead of
|
||||
<span class="ph systemoutput">unavailable</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-270849</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed a memory leak issue related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process that occurred when running consecutive commits for multiple
|
||||
days.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269899</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Panorama web interface was slower than
|
||||
expected when querying for device tags.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269731</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama did not display logs from firewalls
|
||||
after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
|
||||
getting restarted continuously.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268787</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where users were unable to log in to Panorama and the
|
||||
following error message was displayed:
|
||||
<span class="ph systemoutput"
|
||||
>Timed out while getting config lock. Please try again</span
|
||||
>. This occurred when pushing configurations to a large number of
|
||||
devices.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267535</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
processes stopped responding on the remote network firewall, which
|
||||
caused tunnels to go down and the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
CPU usage to approach 100%.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267091</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-266639</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where administrators were unable to edit or add virtual
|
||||
router configurations when a filter was applied to the viewer.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263369</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where commits from Panorama to Panorama virtual
|
||||
appliances failed with the error message
|
||||
<span class="ph systemoutput"
|
||||
>Internal error during commit processing. Commit/Validate
|
||||
failed</span
|
||||
>
|
||||
after upgrading Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-261209</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>Firewalls in active/active HA configuration only</tt
|
||||
>) Fixed an issue where the firewall displayed the HA2 status as down
|
||||
when the HSCI port was used for both HA2 and HA3.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260604</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall displayed inaccurate throughput
|
||||
utilization stats in NetFlow analyzer tools.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259881</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where traffic log details were not
|
||||
displayed under <span class="ph uicontrol">detailed log view</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-258757</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where upgrades failed with validation
|
||||
errors.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255860</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5200 firewalls only</tt>) Fixed an issue where
|
||||
the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_pktproc</a
|
||||
>
|
||||
process stopped responding when the firewall was under a heavy traffic
|
||||
load.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-249384</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where configuration locks were observed
|
||||
during a partial rulebase commit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-246699</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where
|
||||
<span class="ph uicontrol">Rule Usage</span> and
|
||||
<span class="ph uicontrol">Apps Seen</span> under Security policy
|
||||
rules stopped incrementing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-245064</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
|
||||
where commits failed on the firewall after selecting
|
||||
<span class="ph uicontrol">Export or push device config bundle</span>
|
||||
on Panorama and a force push was required.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,196 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291499</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||
only</tt
|
||||
>) Fixed an issue where newly deployed firewalls were unable to
|
||||
connect to the Palo Alto Networks Software License Server (SLS) until
|
||||
after a reboot, license fetch, or management server restart.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290803</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Microsoft Azure environments only</tt
|
||||
>) Fixed an issue where firewall failed to bootstrap with a custom
|
||||
image, and VM-Series plugin information was not displayed in the
|
||||
system information.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290241</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process became unresponsive, which caused User ID CLI commands to time
|
||||
out.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288939</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
process stopped responding due to an invalid SSL context being used
|
||||
for socket communication, which caused commits to fail.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287688</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto
|
||||
Networks update server when using a customized service route with the
|
||||
source interface as <span class="ph uicontrol">MGT</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279901</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
An issue was fixed where the firewall dropped fragmented TLS
|
||||
ClientHello packets, which blocked access to certain websites. This
|
||||
occurred because the packets arrived truncated, in varying sizes and
|
||||
orders, and the firewall's heuristics failed to handle them correctly.
|
||||
</div>
|
||||
<div class="p">
|
||||
To enable this fix, run:
|
||||
<span class="ph systemoutput"
|
||||
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
|
||||
yes</span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268680</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process stopped responding when a configuration merge operation
|
||||
changed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268522</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall failed to connect to the update
|
||||
server with a customized service route when the source interface was
|
||||
set to <span class="ph uicontrol">MGT</span> and the source address
|
||||
was set as IPv4.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255914</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||
only</tt
|
||||
>) Fixed an issue where a newly bootstrapped firewall required a
|
||||
management server restart, relicensing, or license push from Panorama
|
||||
to invoke the device certificate.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-241230</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the SNMP get request status value for Panorama
|
||||
connections was incorrect.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,458 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296519</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a stream receiving a reconnect signal with an
|
||||
associated error in
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>Wifclient</a
|
||||
>
|
||||
caused the entire pool to close, which resulted in a complete
|
||||
disconnection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295560</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors,
|
||||
tunnel logs were not visible in Panorama or Splunk even though traffic
|
||||
and threat logs were received.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293673</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall stopped all tasks due to an OOM
|
||||
condition caused by a scheduled log export using FTP to an external
|
||||
FTP server.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292229</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama was unable to retrieve
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>userid</a
|
||||
>
|
||||
logs from the firewall for subscribed user-ip-mappings after Panorama
|
||||
was rebooted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292202</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the system logs repeatedly displayed the alert
|
||||
<span class="ph systemoutput"
|
||||
>Clearing snmpd.log due to log overflow</span
|
||||
>
|
||||
due to the SNMP counters rolling over.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291716</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
|
||||
conditions, leading to device crashes and reboots.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291631</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the firewall frequently rebooted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291288</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process restart related to page allocation failures.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291094</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue the firewall experienced packet descriptor on chip and
|
||||
buffer spikes, which led to dropped traffic due to an unidentified
|
||||
traffic pattern.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291067</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>devsrvr</a
|
||||
>
|
||||
process periodically exceeded its virtual memory limit and restarted,
|
||||
which led to intermittent outages.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290542</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process stopped responding when an additional header logging HTTP
|
||||
header was split across 2 packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290449</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when multiple scheduled vulnerability reports
|
||||
were sent in the same email, only the first attached report was
|
||||
displayed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287818</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where sessions timed out sooner than expected due to
|
||||
the
|
||||
<span class="ph systemoutput"
|
||||
>pan_proxy_accumulation_restore_timeout</span
|
||||
>
|
||||
not initiating when the accumulation
|
||||
<span class="ph systemoutput">session_init</span> failed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287803</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
|
||||
certain websites weren't accessible when the accumulation proxy was
|
||||
enabled. The proxy did not use the same DF bit state as the original
|
||||
traffic, causing it to be fragmented and dropped elsewhere in the
|
||||
network.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287782</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls configured in vwire mode modified DSCP
|
||||
values from AF11 to CS0 on traffic passing through the firewall, even
|
||||
when QoS policy rules and DSCP rewrite settings were not configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287622</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where IPv6 traffic was affected after upgrading the
|
||||
firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
|
||||
enabled and a decryption policy configured for the traffic, the
|
||||
firewall dropped packets due to receiving a
|
||||
<span class="ph systemoutput">Packet Too Big</span> ICMP message. This
|
||||
occurred because the PathMTU information update was incorrect for the
|
||||
TCB (pan-server) when the firewall was acting as a server.
|
||||
Additionally, the flow label under the IPv6 header was set to zero
|
||||
while the packet was being transmitted out of the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287601</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where commits took longer than expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-287423</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where content loading issues occurred on IPv6 websites
|
||||
due to the firewall incorrectly setting the IPv6 header flow label to
|
||||
0.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286299</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after
|
||||
being offboarded from Panorama, the firewall XML configuration file
|
||||
retained template information from the previous Panorama
|
||||
configuration. As a result, when the firewall and its configuration
|
||||
were imported to another Panorama appliance, all configurations in the
|
||||
<span class="ph uicontrol">Network</span> and
|
||||
<span class="ph uicontrol">Device</span> tabs became read-only.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285285</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where commits remained at 98% completion when static
|
||||
route configuration cleanup was in progress.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-286231</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a simultaneous selective push from Panorama to
|
||||
multiple firewalls with different base configurations resulted in
|
||||
configuration corruption, which caused the firewall to go down.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-280698</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall removed the TCP timestamp from
|
||||
client hello messages that did not fit in a single packet, which
|
||||
resulted in connection issues.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279706</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
|
||||
Panorama did not update all
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>panreplay</a
|
||||
>
|
||||
database entries after performing a commit and full push to all
|
||||
devices.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276484</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama did not display license information for
|
||||
Cloud NGFW firewalls under (<span class="ph uicontrol"
|
||||
>Device Deployment > Licenses</span
|
||||
>) due to the inability to perform batch-license refreshes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273453</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where restarting the firewall did not initiate an
|
||||
autocommit job, which caused the firewall to stop responding and the
|
||||
HA interface to go down.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273300</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed
|
||||
with a validation error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-265044</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the default software packet buffer size for the
|
||||
Advanced Header Learning (AHL) feature was excessively large, which
|
||||
led to inefficient use of software packet buffers.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260015</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where enabling Inline Cloud Analysis
|
||||
features might cause the firewall to unexpectedly reboot, due to an
|
||||
issue related to loopback data handling.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,503 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303559</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after manually creating a device telemetry
|
||||
bundle, the
|
||||
<span class="ph systemoutput">hour_cli_output.txt</span> file within
|
||||
the bundle had a file size of 0 bytes. This occurred when checking the
|
||||
bundle content after enabling device telemetry and setting the device
|
||||
telemetry upload endpoint.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301456</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where the
|
||||
<span class="ph systemoutput">debug system reset-ztp</span> CLI
|
||||
command was unavailable.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300216</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when SD-WAN Direct Internet Access was
|
||||
configured and traffic traversed the cellular interface without a NAT
|
||||
policy rule, intermittent cellular modem connectivity issues occurred,
|
||||
which caused the firewall to disconnect and reconnect to the cellular
|
||||
network.
|
||||
<span class="ph systemoutput"
|
||||
>To use this fix, run the CLI command set session
|
||||
teardown-upon-fwd-zonechange yes</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298462</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall experienced extended boot times
|
||||
after a reboot due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process needing to rebuild the ACE catalog after detecting
|
||||
discrepancies that were caused by duplicate application checking
|
||||
between the ACE catalog and content.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297976</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall experienced extended boot times
|
||||
after a reboot due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process needing to rebuild the ACE catalog after detecting
|
||||
discrepancies that were caused by duplicate application checking
|
||||
between the ACE catalog and content.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297972</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a dataplane crash occurred when traffic matched
|
||||
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
|
||||
Analysis features were not enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297775</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading to an affected PAN-OS release,
|
||||
the Visible Virtual System field referenced the vsys name instead of
|
||||
the vsys ID, which caused inter-vsys routing to fail. This occurred
|
||||
when a vsys display name matched one of the vsys IDs. If you're using
|
||||
a multivsys environment, you must upgrade your firewalls to a fixed
|
||||
PAN-OS version. The best practice is to upgrade both the firewalls and
|
||||
Panorama to a fixed PAN-OS version.
|
||||
</div>
|
||||
<div class="p">
|
||||
If you don't upgrade Panorama to a fixed version, you'll encounter
|
||||
PAN-245064, where a commit on a multivsys firewall fails with the
|
||||
message
|
||||
<span class="ph systemoutput"
|
||||
>vsys name should end with a number vsys is invalid</span
|
||||
>
|
||||
after you
|
||||
<span class="ph systemoutput"
|
||||
>Export or push device config bundle</span
|
||||
>
|
||||
from 11.1.1 Panorama.
|
||||
</div>
|
||||
<div class="p">
|
||||
After you upgrade Panorama to a fixed version, you'll encounter
|
||||
PAN-214177, which causes an
|
||||
<span class="ph systemoutput"
|
||||
>Export or Push device config bundle</span
|
||||
>
|
||||
from Panorama to the firewall to fail. The workaround for PAN-214177
|
||||
is to first push only the template configuration and then push the
|
||||
device group configurations.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296752</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1410 Firewalls only</tt>) Fixed an issue where
|
||||
the firewall experienced high management CPU usage and repeatedly
|
||||
rebooted when attempting to retrieve SMART data.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296694</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process repeatedly restarting during an IP-port data type writes to
|
||||
the redis from multiple sources such as TSA or XML in a scale
|
||||
environment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296535</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where BGP peers disconnected due to
|
||||
<span class="ph systemoutput">frr_ns1_bgpd</span> restarting.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294436</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>PA-410, PA-440, PA-450, and PA-460 firewalls only</tt
|
||||
>) Fixed an issue where, after upgrading to PAN-OS 11.1.6-h6 the
|
||||
Eth1/2, Eth1/3, Eth1/8, and HA interfaces failed to display counters
|
||||
and statistics in the CLI and SNMP.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292447</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama did not display data in the
|
||||
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
|
||||
Manager due to the system creating and deleting a CLI user for each
|
||||
interval instead of reusing a permanent CLI user for telemetry.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291940</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall established multiple TCP connections
|
||||
to a syslog server, which caused logs to be dropped. This occurred
|
||||
because the firewall established a new TCP session for each transfer
|
||||
and the sessions were not closed, which resulted in a continuous
|
||||
increase in connections over time.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291661</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama appliances and Log Collectors where, after
|
||||
an upgrade, Elasticsearch intermittently entered into a Red state
|
||||
before automatically recovering.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289249</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a memory leak occurred on the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process when a WildFire update was initiated while device telemetry
|
||||
data collection was in progress. This resulted in an OOM condition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289109</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Panorama web interface was slower than
|
||||
expected during configuration operations and a configuration lock time
|
||||
out occurred during a commit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287387</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where API jobs failed with the error
|
||||
message
|
||||
<span class="ph systemoutput"
|
||||
>Server error: Timed out while getting config lock</span
|
||||
>. This occurred due to slow set request performance when setting a
|
||||
large number of address objects in a single set call.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284279</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the policy destination always defaulted to
|
||||
<span class="ph uicontrol">any</span>, even when specific IP addresses
|
||||
and FQDNs were specified during policy import.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284067</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed a cumulative memory leak in the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>devsrvr</a
|
||||
>
|
||||
process that occurred whenever the CLI command
|
||||
<span class="ph systemoutput"
|
||||
>show running application statistics</span
|
||||
>
|
||||
was issued. This memory leak would gradually consume system memory and
|
||||
produce an OOM condition, causing the firewall to reboot.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-281776</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the Panorama web interface where the error message
|
||||
<span class="ph uicontrol"
|
||||
>PPPoEv6 Client Interface cannot be enabled with DHCPv6 client</span
|
||||
>
|
||||
was generated when overriding aggregate interfaces even when no DHCPv6
|
||||
or PPPoE was configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279829</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where NAT pool leaks occurred during a test when RTSP
|
||||
traffic hit NAT rules.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272746</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-440 firewalls only</tt>) Fixed an issue where
|
||||
the firewall entered an unstable state after committing changes or
|
||||
onboarding to Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272605</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not display VPC endpoints when
|
||||
there was a large amount of VPC endpoints to interface mappings.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272245</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>dnsproxy</a
|
||||
>
|
||||
process stopped responding due to memory corruption caused by a race
|
||||
condition when the allow list downloading was impacted by a
|
||||
configuration change.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267450</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process stopped responding with a SIGSEGV at
|
||||
<span class="ph systemoutput">schedule_report_es_response</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-266312</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where BFD sessions took longer than expected to
|
||||
establish after an HA failover due to BGP.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-264131</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>routed</a
|
||||
>
|
||||
process core failed the automation run.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,37 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 46.728971962616825%" />
|
||||
<col style="width: 53.27102803738318%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">Issue ID</th>
|
||||
<th class="entry">Description</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">—</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2026-0227"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2026-0227</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,69 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273215</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a syntax error in the index generation script
|
||||
caused a high management plane CPU load after upgrading.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271613</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where configuration pushes from Panorama to the
|
||||
firewall failed due to an OOXML commit error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269404</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not reset the maximum latency
|
||||
timer for hold mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259078</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where WildFire Analysis reports were not generated and
|
||||
the following error message was displayed:
|
||||
<span class="ph uicontrol">Error 500: Internal Server Error</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,350 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 50%" />
|
||||
<col style="width: 50%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">Issue ID</th>
|
||||
<th class="entry">Description</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276130</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when a new IKEv2 was created on Panorama on a
|
||||
PAN-OS 11.2 release using the default IKE version (IKEv2) and IPSec
|
||||
crypto profiles with no specific changes to the crypto profile
|
||||
parameters, and the configuration was pushed to a firewall on PAN-OS
|
||||
11.2.0 to PAN-OS 11.2.4, the firewall interpreted the IKEv2 gateway as
|
||||
IKEv1.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-274029</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where upgrading Panorama and pushing configurations to
|
||||
the firewall caused an IKE version mismatch, which resulted in IPSec
|
||||
tunnel failure with the peer device.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273994</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2025-0111"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2025-0111</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273971</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2025-0108"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2025-0108</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273278</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2025-0109"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2025-0109</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273197</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the endpoint ID was not populated in logs when
|
||||
the least significant word of the Geneve header was 0.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273165</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where HTTP/2 sessions failed on the firewall when
|
||||
Dynamic Memory Management was enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273085</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the web interface where you were unable to edit or
|
||||
create policy rules.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273019</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an intermittent issue where SSL decryption failed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272021</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">M-300 Appliances only</tt>) Fixed an issue where a
|
||||
split brain condition was not triggered during an inter-Log Collector
|
||||
disconnect between DLC firewalls in an Elasticsearch cluster, which
|
||||
resulted in missing logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271926</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
|
||||
error when the firewall was configured to decrypt and inspect TLS
|
||||
traffic.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271828</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after an accumulation proxy changed to
|
||||
no-decrypt or no proxy, only the Client Hello was sent to Content
|
||||
Threat Detection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-270549</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where some TLS connections were not handled correctly,
|
||||
which led to instability in the dataplane.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-270248</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
Fixed an issue where the firewall failed to forward logs to a SNMP trap
|
||||
server if the SNMP manager IP address was unable to be resolved.
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268815</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall entered a non-functional state due
|
||||
to duplicate entries in the shared memory.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268727</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
Fixed an issue where traffic was dropped when the accumulation proxy was
|
||||
enabled and header insertion modified packets.
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268229</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall stopped responding during session
|
||||
setup for ECMP hit-count updates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268215</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances in HA configurations only</tt>)
|
||||
Fixed an issue where, when Elasticsearch was forming a cluster and the
|
||||
port was disabled or disconnected and then reconnected, Elasticsearch
|
||||
did not reform the cluster
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267781</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama did not display the Source Dynamic
|
||||
Address Group.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267671</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process restarting and repeated OOM conditions occurring on the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-265742</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the Panorama web interface where the
|
||||
<span class="ph uicontrol">OK</span> button on the GlobalProtect
|
||||
gateway configuration dialog box was not clickable.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263987</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where, when a NAT transversal IPSec
|
||||
tunnel was terminated, and the NAT rule that was applied to the NAT-T
|
||||
IPSec tunnel was on the same firewall, traffic flowing through the
|
||||
tunnel was not correctly translated.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-252036</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when the GlobalProtect portal was not
|
||||
configured, accessing the GlobalProtect gateway still loaded a portal
|
||||
malformed page.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,103 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 50%" />
|
||||
<col style="width: 50%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">Issue ID</th>
|
||||
<th class="entry">Description</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279604</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where scheduled SaaS application usage reports were
|
||||
generated incorrectly, and the login page was displayed instead of the
|
||||
report content.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276177</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where
|
||||
<span class="ph uicontrol">App Acceleration</span> did not work with
|
||||
Oracle databases.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-274791</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted when Shared Pool Type 32
|
||||
was depleted and traffic matched advanced features.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269499</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall stopped responding when receiving a
|
||||
high number of logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-252224</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama did not forward logs to a syslog server
|
||||
over an SSL connection using CRL as a revocation verification method.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-234082</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
|
||||
issue where Saas reports were generated with a report period of 0
|
||||
days.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-216054</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue that caused the firewall's fan speed to increase while
|
||||
it was idle.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,559 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284036</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-450R and PA-450R-5G firewalls only</tt>) Fixed
|
||||
an issue where the maximum temperature threshold and shutdown
|
||||
threshold were not set correctly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282236</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where large IPv6 packets were reassembled incorrectly
|
||||
on the firewall when the packets arrived fragmented over an IPv4
|
||||
tunnel.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282206</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where configuring Secure Web Gateway (SWG) in
|
||||
<span class="ph uicontrol">no-auth</span> mode led to latency when no
|
||||
decryption policy rules or
|
||||
<span class="ph uicontrol">No-decrypt</span> policy rules were
|
||||
present.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282022</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed the support limitation for the Panorama M-600 and M-700
|
||||
appliances.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-280471</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where navigating
|
||||
<span class="ph uicontrol">Panorama > Monitor > Logs</span> was
|
||||
slower than expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279746</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SMTP packets were not sent out when the Client
|
||||
Hello arrived at the firewall in multiple out-of-order segments and
|
||||
the traffic was not subject to SSL decryption.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279197</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-450R-5G firewalls only</tt>) Fixed an issue
|
||||
where the firewall stopped responding and displayed the error message
|
||||
`Thermal temperature exceeds system threshold! Shutting down NOW` even
|
||||
when the firewall was within the threshold.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278684</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-445 firewalls only</tt>) Fixed an issue where
|
||||
the firewall did not properly power cycle during a reboot.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278296</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the system MAC address of the aggregate interface
|
||||
was the same on the active firewall and the passive firewall after an
|
||||
upgrade.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276546</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a session lost the PBF rule mapping after a
|
||||
configuration change or commit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-275905</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Panorama web interface was slower than
|
||||
expected and Elasticsearch CPU usage was high.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273949</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall generated the following error
|
||||
message in the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>snmpd</a
|
||||
>
|
||||
logs:
|
||||
<span class="ph systemoutput"
|
||||
>pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
|
||||
X2F1dGhfa2V5 import from cryptod failed.</span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273026</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where traffic logs did not display correctly when
|
||||
filters were applied.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273021</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where 25G port links did not come up due to a change in
|
||||
the handling of 25G DAC modules.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272849</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where log forwarding to a UDP syslog server stopped
|
||||
when an unreachable TCP syslog server was configured and applied.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272538</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process stopped responding during a commit-all validation when there
|
||||
were uncommitted changes and
|
||||
<span class="ph systemoutput">share-unused-objects-with-devices</span>
|
||||
was set to off.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272085</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall might crash and reboot when DoH is
|
||||
enabled for DNS Security and multiple DoH transactions are sent in a
|
||||
single HTTP/1 connection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271912</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process stopped responding when filtering in the configuration audit
|
||||
window after upgrading to PAN-OS 11.1.3.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271351</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2025-0116"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2025-0116</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-270224</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where indices were not opened after a query.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269956</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_pktproc</a
|
||||
>
|
||||
process stopped responding, which caused internal path monitor
|
||||
failures.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269291</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the scheduled report generation script did not
|
||||
return debug information.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269106</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<span class="ph systemoutput">wifclient</span> stopped responding
|
||||
during server certificate verification for MICA gRPC connections and
|
||||
caused the dataplane to restart when using a cloud-based ML detection
|
||||
engine (MICA). On certain platforms, this caused the firewall to
|
||||
reboot periodically.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269091</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>varrcvr</a
|
||||
>
|
||||
process stopped responding.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268501</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall was unable to generate a TSF file
|
||||
due to a full root partition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267430</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama was unable to return logs for queries
|
||||
that were longer than 64,000 characters.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-265179</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a kernel race condition caused the firewall to
|
||||
reboot with a kernel panic.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263208</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5440 and PA-5445 firewalls only</tt>) Fixed an
|
||||
issue where interrupts were generated at a certain packet rate, and
|
||||
dataplane processes missed heartbeats, which caused the dataplane to
|
||||
go down.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-262383</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall was unable to decompress the HTTP2
|
||||
header, which caused the session to be classified as unknown-tcp
|
||||
instead of web-browsing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-261739</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||
>) Fixed an issue where the firewall displayed 0 for the physical port
|
||||
counters read from MAC.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-261484</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where DPDK allocated twice the amount
|
||||
of memory as requested for pre-allocation.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-258736</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where policy rule configurations pushed from Panorama
|
||||
were not reflected on the firewall if the rule had 63 characters.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-258570</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall might reboot unexpectedly due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>varrcvr</a
|
||||
>
|
||||
process progressively using more memory when WildFire file forwarding
|
||||
is handling PE files.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-257619</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where the
|
||||
<span class="ph uicontrol">Task Manager</span> took longer than
|
||||
expected to display managed firewall report tasks.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-257028 </b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>Firewalls in active/passive HA configurations only</tt
|
||||
>) Fixed an issue where firewalls entered a non-functional state and
|
||||
displayed the error message
|
||||
<span class="ph systemoutput"
|
||||
>Dataplane down: path monitor failure during the fail-over</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255323</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-7050 firewalls only</tt>) Fixed an issue where
|
||||
the Network Processing Card (NPC), Data Processing Card (DPC), and Log
|
||||
forwarding Card (LFC) remained in a starting state after an unexpected
|
||||
power cycle.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,112 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286255</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when the firewall received an unexpected
|
||||
termination request for SSL sessions, the dataplane experienced a slow
|
||||
buffer resource leak.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282968</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not identify the test threat
|
||||
file when the content was installed via a traditional bootstrap.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278322</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) Gateway Load
|
||||
Balancer (GWLB) deployments only</tt
|
||||
>) Fixed an issue where the firewall did not display the correct
|
||||
source user in traffic logs and session details.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-277629</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not match the correct policy for
|
||||
SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS
|
||||
10.2.9-h1 to PAN-OS 11.2.3.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268474</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where the PAN-DB URL Filtering license
|
||||
displayed as <span class="ph uicontrol">Valid</span> even when the
|
||||
firewall did not have the license, which caused traffic to drop.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-261999</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||
>) Fixed an issue where enabling flow basic on firewalls caused ARP
|
||||
entries to be removed on both firewalls.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260290</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Added support for new content size requirements on fixed model
|
||||
licenses.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,44 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267444</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where large file downloads or uploads failed or
|
||||
remained in an incomplete state when using DLP HTTP2 mirror mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255619</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an intermittent issue where file downloads from websites failed
|
||||
when decrypting HTTP/2 traffic.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,577 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290239</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>PA-455 firewalls in active/passive high availability (HA)
|
||||
configurations only</tt
|
||||
>) Fixed an issue where, after an upgrade, the TCP session for syslog
|
||||
forwarding did not resume after the syslog server service was disabled
|
||||
and then re-enabled, which caused logs to be dropped. This occurred
|
||||
when the syslog server was down for more than 16 minutes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289102</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
|
||||
PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
|
||||
CN-Series firewalls only</tt
|
||||
>) Fixed a race condition issue related to predict processing, which
|
||||
resulted in a dataplane restart and traffic loss.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287002</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
A fix was made to address
|
||||
<a
|
||||
class="xref"
|
||||
href="https://security.paloaltonetworks.com/CVE-2025-0133"
|
||||
title=""
|
||||
data-scope="external"
|
||||
data-format="html"
|
||||
data-type=""
|
||||
target="_blank"
|
||||
>CVE-2025-0133</a
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285894</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process stopped responding, which caused the firewall to reboot
|
||||
unexpectedly, and traffic failures occurred.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285651</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>Panorama appliances in active/passive HA configurations on
|
||||
Microsoft Azure environments only</tt
|
||||
>) Fixed an issue on Panorama that caused firewalls to disconnect
|
||||
unexpectedly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285590 </b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
|
||||
only</tt
|
||||
>) Fixed an issue where the firewall CPU usage reached 100% after
|
||||
upgrading to PAN-OS 11.1.6-h1.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284066</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after an upgrade, the SNMP polled values for
|
||||
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
|
||||
high number of errors that did not match the values in the CLI show
|
||||
interface command.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283789</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||
issue where, after an upgrade, the
|
||||
<span class="ph uicontrol">mac receive error</span> counter in
|
||||
<span class="ph uicontrol">receive incoming errors</span> increased,
|
||||
which resulted in SNMP alerts.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283467</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
|
||||
where the firewall unexpectedly rebooted and entered maintenance mode
|
||||
due to a ctd-agent out-of-memory (OOM) condition. This occurred during
|
||||
advanced services load testing and a high volume of IoT EAL log
|
||||
forwarding.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283331</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where selective pushes to managed devices failed when
|
||||
the <span class="ph uicontrol">User ID Master Device</span> was
|
||||
configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282069</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where Security policy rules were removed
|
||||
from device groups when you cloned or edited Security policy rules
|
||||
that used more than 63 characters.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-280532</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after disabling and re-enabling the external
|
||||
syslog server, the TCP session was not resumed, which caused all logs
|
||||
that were forwarded to the syslog server to be dropped.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279621</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where processes stopped responding when HTTPS Forward
|
||||
traffic was run.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-275077</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS Security intermittently logs malicious domain
|
||||
URLs as Alert instead of taking a Sinkhole action, even when
|
||||
configured to Sinkhole malicious DNS domains.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-274570</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>devsrvr</a
|
||||
>
|
||||
process restarted after a failed commit due to an invalid memory
|
||||
access.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-274314</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>PA-1400 Series, PA-3400 Series, and PA-5400 Series firewalls
|
||||
only</tt
|
||||
>) Fixed an issue where, when the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process restarted, control plane packets were dropped, which could
|
||||
impact LACP and pings to host interfaces.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272006</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not trigger a kernel core dump
|
||||
as a large core when the CPLD (Complex Programmable Logic Device) sent
|
||||
a Non-Maskable Interrupt (NMI) to the CPU.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271913</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on firewalls in HA configurations where, when using the
|
||||
Cloud Identity Engine (CIE), the firewall experienced consistent
|
||||
memory leaks on the active firewall, which caused unexpected
|
||||
failovers.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271273</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where dynamic update downloads failed when
|
||||
<span class="ph uicontrol">IPv6 firewalling</span> was enabled on the
|
||||
firewall and both IPv4 and IPv6 were configured on the management
|
||||
interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-270379</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where socket files created in the /tmp directory were
|
||||
not cleared.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269052</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where traffic was blocked by a URL filtering profile
|
||||
even though the Security policy rule did not have a URL filtering
|
||||
profile configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269027</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue related to external dynamic lists that caused commit
|
||||
times on the firewall to be higher than expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268708</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where PDF summary and email reports displayed IPv6
|
||||
addresses instead of IPv4 addresses.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268705</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an intermittent issue where the firewall failed to process FTP
|
||||
traffic after upgrading to PAN-OS 10.1.14.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268127</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where tagging devices in Panorama did not work as
|
||||
expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267444</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where large file downloads or uploads failed or
|
||||
remained in an incomplete state when using DLP HTTP2 mirror mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-266900</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the Panorama web interface where you were unable to
|
||||
click <span class="ph uicontrol">OK</span> after selecting an install
|
||||
package type and file from the dropdown and selecting a firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-265745</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall displayed incorrect MAC receive
|
||||
error counters for VMWare devices hosted in ESXi.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263973</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where log collectors had a low incoming log rate.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-261825</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where traffic was dropped when Data Loss Prevention or
|
||||
Advanced URL Filtering were enabled. This occurred when the payload
|
||||
size was greater than 3.5 KB.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-261673</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Microsoft Azure environments only</tt
|
||||
>) Fixed an issue where, when Accelerated Networking was enabled,
|
||||
traffic was dropped because of the
|
||||
<span class="ph systemoutput">flow_parse_ip_hdr</span> counter related
|
||||
to an Nvidia driver issue.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-261429</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<span class="ph systemoutput"
|
||||
>show auth radius-require-msg-authentic</span
|
||||
>
|
||||
CLI command displayed no output.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259706</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where the web interface was slower than
|
||||
expected or unresponsive when monitoring definitions were added in the
|
||||
Kubernetes plugin.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-258680</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where, when you removed Security profile
|
||||
groups from a Security policy rule via the CLI and committed the
|
||||
change, the Security policy rule was deleted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-257267</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
a warning message was displayed after a commit, and a critical system
|
||||
log was generated when the configuration size exceeded the maximum
|
||||
size.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255619 </b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an intermittent issue where file downloads from websites failed
|
||||
when decrypting HTTP/2 traffic.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254901</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where GlobalProtect user-to-IP address mapping was
|
||||
removed even though the tunnel for the specific user was up and
|
||||
traffic was being passed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-252669 </b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>ikemgr</a
|
||||
>
|
||||
process stopped responding with a SIGSEGV error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,544 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-270802</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after modifying a policy rule on Panorama,
|
||||
pushes to the Cloud NGFW failed with the error
|
||||
<span class="ph systemoutput">saas-user-list unexpected here</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268823</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where
|
||||
<span class="ph uicontrol">Monitor > Log Display</span> did not
|
||||
display all logs when you applied a filter.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267386</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where VPC IDs and Security keys were not mapped to the
|
||||
correct interfaces for Google IPS.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-266769</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the GlobalProtect gateway did not handle IP
|
||||
address changes of the inner gateway when the NGPA new protocol was
|
||||
enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-266581</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a failed SSL connection to a syslog server
|
||||
resulted in a
|
||||
<span class="ph systemoutput">/tmp/srvr.crt.xxxxxx</span> file not
|
||||
being removed, which caused index node (inode) exhaustion.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-266114</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when a new set of URL logs came in, the content
|
||||
of the earlier URL and traffic logs were lost.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-265785</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted due to a
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>sysd</a
|
||||
>
|
||||
variable being modified before it was created.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-264249</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where SNMP queries timed out when using
|
||||
SNMP.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-264246</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Authentication Portal did not work properly
|
||||
with session cookies when the request to the portal contained the
|
||||
header <span class="ph systemoutput">Sec-Fetch-Site=cross-site</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263680</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Prisma Access gateways consistently stopped
|
||||
responding with process restarts.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263559</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the dataplane stopped responding and the firewall
|
||||
unexpectedly rebooted due to multiple process restarts.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263287</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
The PAN-COMMON-MIB.my file was updated to support new object
|
||||
identifiers (OID) to poll interface use via SNMP with table
|
||||
identifiers.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-262340</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where FQDN resolution failed for address objects, and
|
||||
all FQDN traffic was denied by the interzone-default policy rule.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-262254</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall experienced an OOM condition and the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process stopped responding, which caused the firewall to drop
|
||||
interfaces from their respective aggregate groups.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-261489</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where an out-of-memory (OOM) condition caused a
|
||||
firewall outage.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260662</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where large file downloads were slower than expected
|
||||
when private IP address visibility was enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260512</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where accessing the IP address of the device address
|
||||
group objects from the user interface caused the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process to stop responding.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-260316</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process stopped responding and the firewall rebooted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259910</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall reported the same value over
|
||||
consecutive SNMP polls when asynchronous mode was enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259767</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where GlobalProtect users were unable to connect when
|
||||
the option
|
||||
<span class="ph uicontrol"
|
||||
>Block sessions if the certificate was not issued to the
|
||||
authenticating device</span
|
||||
>
|
||||
was enabled in the certificate profile.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259002</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where frequent external dynamic list updates caused the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process to restart.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-257736</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
||||
traffic to benign applications was was impacted by holding TCP
|
||||
sequential segments for MLC inspection and not releasing the full
|
||||
chain after a benign verdict was received.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-257601</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
||||
Networking Cards (NC) experienced an internal link fault which caused
|
||||
path monitoring failure on the Dataplane Processing Card (DPC).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-257327</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5440 firewalls only</tt>) Fixed an issue where a
|
||||
failover event occurred unexpectedly on the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-256077</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the GlobalProtect client would disconnect
|
||||
consistently due to keep-alive timeouts when using an SSL-only tunnel.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-254704</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>LSVPN Portal firewalls in active/passive HA configurations only</tt
|
||||
>) Fixed an issue where the satellite cookie key did not sync between
|
||||
LSVPN portal HA firewalls, which resulted in re-authentication of
|
||||
satellites with the portal during the event of HA failover.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-251973</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall did not detect evasions due to TCP
|
||||
checksum offloading not being enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250394</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a large amount of group data caused serialization
|
||||
errors and prevented synchronization.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-250371</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
process stopped responding, which caused commits to fail with the
|
||||
error message
|
||||
<span class="ph systemoutput"
|
||||
>Management server failed to send phase 1 to client logrcvr</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-240990</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where
|
||||
<span class="ph systemoutput">l3svc.py</span> displayed incorrect
|
||||
logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-239952</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>Firewalls in active/passive HA configurations only</tt
|
||||
>) Fixed an issue where HA sync messages from the active firewall took
|
||||
longer than expected to reach the passive firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-230893</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Added a CLI command to address an issue where system lock files
|
||||
blocked authentication.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-230825</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where link flaps occurred on Panorama appliances in HA
|
||||
configurations.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-225213</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where
|
||||
<span class="ph uicontrol">Push All Changes</span> displayed changes
|
||||
that were already committed in the push scope for another device group
|
||||
after performing a selective commit and selective push to the first
|
||||
device group.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-222542</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
|
||||
where Log Forward Cards (LFC) were incorrectly identified as
|
||||
distribution policies, which caused packet loss due to traffic, BFD,
|
||||
and other control packets being forwarded to the LFC.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-214773</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where RTP packets traversing inter-vsys were dropped on
|
||||
the outgoing vsys.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,32 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282022</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed the support limitation for the Panorama M-600 and M-700
|
||||
appliances.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,349 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294436</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
Fixed an issue where polling failed for ethernet interfaces due to the
|
||||
physical port counters read from the MAC being 0.
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293842</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the hybrid-SWG service proxy stopped working
|
||||
after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to
|
||||
establish the listening interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293673</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall stopped all tasks due to an OOM
|
||||
condition caused by a scheduled log export using FTP to an external
|
||||
FTP server.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292503</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where the source and destination NAT IP
|
||||
addresses did not display in traffic and threat logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291060</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where commits failed due to the configured connected
|
||||
gateway IPv6 address in the NAT64 policy exceeding the 31 character
|
||||
limit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290996</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SNMP walks returned a value of 0 for the CPS
|
||||
(Connections Per Second) per vsys on firewalls after upgrading to
|
||||
PAN-OS 11.1.6-h3, even when active connections were present.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290088</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a memory leak occurred related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process when pushing configurations from Panorama to a firewall. This
|
||||
occurred when the configurations contained shared policy rules.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289714</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Prisma Access only</tt>) Fixed an issue where
|
||||
persistent commit failures occurred due to a missing transformation
|
||||
script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289268</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
Fixed an issue where internet access through Secure Web Gateway (SWG)
|
||||
proxy nodes did not work when the default internet access policy rule
|
||||
source user was not <span class="ph uicontrol">known-user</span>.
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288939</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
process stopped responding due to an invalid SSL context being used
|
||||
for socket communication, which caused commits to fail.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284878</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>Firewalls in active/passive HA configurations only</tt
|
||||
>) Fixed an issue where commits failed due the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process restarting.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284003</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where clients did not receive a valid response when
|
||||
when searching a website due to a compression error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-280409</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the popup window did not appear as expected for
|
||||
Clientless VPN users.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279901</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
An issue was fixed where the firewall dropped fragmented TLS
|
||||
ClientHello packets, which blocked access to certain websites. This
|
||||
occurred because the packets arrived truncated, in varying sizes and
|
||||
orders, and the firewall's heuristics failed to handle them correctly.
|
||||
</div>
|
||||
<div class="p">
|
||||
To enable this fix, run:
|
||||
<span class="ph systemoutput"
|
||||
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
|
||||
yes</span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279690</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_pktproc</a
|
||||
>
|
||||
process stopped responding, which caused the firewall to unexpectedly
|
||||
restart.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279415</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where service routes configured to use a data plane
|
||||
interface incorrectly used the management plane interface for traffic
|
||||
transmission. This issue affected syslog and CRL status traffic when a
|
||||
custom service route was not configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276616</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where half-duplex settings on Ethernet
|
||||
were not visible.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271810</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where auto-negotiation advertised and negotiated 10/100
|
||||
half and full duplex.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268787</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where users were unable to log in to Panorama and the
|
||||
following error message was displayed:
|
||||
<span class="ph systemoutput"
|
||||
>Timed out while getting config lock. Please try again</span
|
||||
>. This occurred when pushing configurations to a large number of
|
||||
devices.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-255860</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-5200 firewalls only</tt>) Fixed an issue where
|
||||
the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_pktproc
|
||||
</a>
|
||||
process stopped responding when the firewall was under a heavy traffic
|
||||
load.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-252706</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the URL filtering response page for
|
||||
<span class="ph uicontrol">Continue</span> and
|
||||
<span class="ph uicontrol">Override</span> did not work with IPv6
|
||||
Router Advertisement (RA) or Multicast Listener Query (MLQ) for
|
||||
IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,300 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-310868</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where PA Explicit proxy blocked ICMP packets from
|
||||
flowing towards Envoy for Geneve due to the router not camping MSS
|
||||
when the MTU was lower in the path.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-307901</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a leak in decryption counters caused resource
|
||||
exhaustion, which led to a GlobalProtect service outage.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306502</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed two issues that impacted TLSv1.2 or earlier sessions when the
|
||||
traffic matched a decryption policy rule with the no-decrypt action:
|
||||
</div>
|
||||
<ul class="ul">
|
||||
<li class="li">
|
||||
Connections failed when both HTTP header insertion (<span
|
||||
class="ph uicontrol"
|
||||
>Objects > Security Profiles > URL Filtering > HTTP
|
||||
Header Insertion</span
|
||||
>) and
|
||||
<span class="ph uicontrol"
|
||||
>Send handshake messages to CTD for inspection</span
|
||||
>
|
||||
(<span class="ph uicontrol"
|
||||
>Device > Setup > Session > Decryption Settings > SSL
|
||||
Decryption Settings</span
|
||||
>) were enabled.
|
||||
</li>
|
||||
<li class="li">
|
||||
New sessions failed due to software packet buffer resource
|
||||
depletion, which occurred when
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>Log Successful SSL Handshake</a
|
||||
>
|
||||
was disabled in the decryption policy rule and the decryption
|
||||
profile attached to the rule had both
|
||||
<span class="ph uicontrol"
|
||||
>Block sessions with expired certificates</span
|
||||
>
|
||||
and
|
||||
<span class="ph uicontrol"
|
||||
>Block sessions with untrusted issuers</span
|
||||
>
|
||||
disabled.
|
||||
</li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306103</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-3400 and PA-5400 Series firewalls only</tt>)
|
||||
Fixed an issue where the firewall dataplane frequently restarted when
|
||||
lockless QoS was enabled
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303959</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where traffic was incorrectly identified as
|
||||
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
|
||||
dropped.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302767</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where IPv6 IPsec WAN support was not available in
|
||||
Prisma Access.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301222</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS Security logs incorrectly displayed a
|
||||
sinkhole action for benign DNS categories due to the firewall saving
|
||||
the drop or sinkhole action in session flags without discarding the
|
||||
session.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300638</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the firewall stopped responding due to an out-of-bounds read when
|
||||
parsing TLS 1.3 clientHello messages with large TLS clientHello
|
||||
extensions where the
|
||||
<span class="ph systemoutput">supported_versions</span> extension fell
|
||||
outside the first TCP segment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297295</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||
>) Fixed an issue where the firewall repeatedly restarted due to high
|
||||
packet rates on the synthetic path in DPDK mode.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295803</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Addressed a memory leak issue under sc3 and automatic commit recovery
|
||||
(ACR) code path.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294488</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where certificate data was missing in decryption logs
|
||||
for <span class="ph uicontrol">No decrypt</span> policy rules and
|
||||
TLS1.2 traffic after upgrading, and the
|
||||
<tt class="ph tt">Subject Common Name</tt>,
|
||||
<span class="ph uicontrol">Issuer Common Name</span>,
|
||||
<span class="ph uicontrol">Certificate Start Date</span>,<span
|
||||
class="ph uicontrol"
|
||||
>
|
||||
Certificate End Date</span
|
||||
>, <span class="ph uicontrol">Certificate Serial Number</span>, and
|
||||
<span class="ph uicontrol">Certificate Fingerprint</span> fields were
|
||||
blank in the decryption logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-283563</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the GlobalProtect gateway firewall intermittently
|
||||
failed to assign an IP address to GlobalProtect clients from the DHCP
|
||||
server, even after successfully receiving a DHCP offer. This occurred
|
||||
when the DHCP retry and timeout settings were overwritten due to
|
||||
parsing results being stored in the same variable, which caused the
|
||||
last gateway configuration to take effect.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-271438</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall calculated available memory
|
||||
incorrectly on CENTOS devices, which caused the firewall to display
|
||||
high memory usage alerts even when sufficient memory was available.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267328</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process stopped responding, which caused the firewall to stop
|
||||
processing traffic.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259853</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when the DHCP server was enabled for
|
||||
GlobalProtect, the commit error message was not properly displayed
|
||||
when <span class="ph uicontrol">Any</span> was selected as the source
|
||||
interface in the service router configuration (<span
|
||||
class="ph menucascade"
|
||||
><span class="ph uicontrol">Device</span
|
||||
><span class="ph uicontrol">Setup</span
|
||||
><span class="ph uicontrol">Service</span
|
||||
><span class="ph uicontrol"
|
||||
>Service Router Configuration</span
|
||||
></span
|
||||
>).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-258039</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall displayed the incorrect rule name
|
||||
when a threat log was generated for Inline Cloud Analyzed CMD
|
||||
Injection Traffic Detection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,233 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308902</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading to an affected release, the
|
||||
firewall did not add mTLS websites that required client certificate
|
||||
authentication via DN list to the ssl-decrypt exclude-cache list.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308654</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Elasticsearch Close Indices process closed
|
||||
more indices than expected and dropped the number of open shards below
|
||||
the minimum of 800 per Elasticsearch instance. This occurred because
|
||||
the process did not correctly account for the number of Elasticsearch
|
||||
instances when calculating the maximum number of allowed open shards.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304718</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where OSPF and BGP outages occurred due to an
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process restart during clientless VPN content rewrite processing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304576</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall entered a non-functional state due
|
||||
to segmentation fault within the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_pktproc</a
|
||||
>
|
||||
process that was caused by a session that involved http2 cleartext
|
||||
traffic
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304496</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after unregistering an IP tag and registering a
|
||||
different IP tag for the same IP address via XML API, the dynamic
|
||||
address group membership was not updated on the dataplane, which
|
||||
resulted in Security policy rules being enforced incorrectly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303722</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where configuring spyware and
|
||||
vulnerability profiles in Security policy rules caused a memory leak
|
||||
in the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>devsrvr</a
|
||||
>
|
||||
process with each configuration commit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-288001</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where devices with 5G cellular modems did not support
|
||||
the ATT FirstNet auto Access Point Name (APN).
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285181</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the wifclient ran out of memory when Enhanced
|
||||
Application Logging was enabled and a sudden traffic increase caused a
|
||||
surge in EAL messages sent through WIF.
|
||||
</div>
|
||||
<div class="p">
|
||||
To use this fix, run the CLI command
|
||||
<span class="ph codeph">debug iot eal memory-gc native</span>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278688</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS Security threat logs were not displayed on
|
||||
the firewall when packet capture was enabled and the domain name
|
||||
length was 62 characters.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-273158</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
|
||||
where an incorrect ASIC configuration caused silent packet drops or
|
||||
application slowness when receiving a mix of jumbo and non-jumbo
|
||||
packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-269228</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process stopped responding, which caused a split brain condition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267614</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Panorama web interface was slower than
|
||||
expected due to high CPU utilization on the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>mongodb</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,525 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry"></td>
|
||||
<td class="entry relcol"></td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-316911</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||
only</tt
|
||||
>) Fixed an issue where a newly bootstrapped firewall required a
|
||||
management server restart, relicensing, or license push from Panorama
|
||||
to invoke the device certificate.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-315912</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Maximum Segment Size (MSS) rewrite
|
||||
functionality for packets ingressing through SD-WAN interfaces on
|
||||
firewalls was not optimized.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-314147</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces
|
||||
with member having different MTU.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313623</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
|
||||
directory on Palo Alto Networks devices with TPM support became 100%
|
||||
utilized due to an accumulation of undeleted
|
||||
<span class="ph systemoutput">.pub_pem</span> files. This occurred
|
||||
because executing the
|
||||
<span class="ph systemoutput">show device-certificate status</span>
|
||||
CLI command initiated a process that generated these files but failed
|
||||
to remove them, which prevented the fetching of new device
|
||||
certificates.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-313216</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls with Prisma Access incorrectly
|
||||
displayed some traffic as unsanctioned in traffic logs for cloud
|
||||
applications that were tagged as
|
||||
<span class="ph uicontrol">sanctioned</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-312706</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewalls restarted due to a function lacking
|
||||
a NULL-pointer sanity check.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-311512</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where HIP (Host Information Profile) reports were
|
||||
blocked on GlobalProtect when
|
||||
<span class="ph uicontrol"
|
||||
>Authentication Cookie Usage Restrictions</span
|
||||
>
|
||||
was enabled and the Prisma Access Agent protocol was in use. This
|
||||
occurred because the system failed to correctly process HIP messages
|
||||
that were relayed via IPSec tunnels with a Virtual IP as the source,
|
||||
leading to their rejection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-309300</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where management plane system resources configuration
|
||||
size exceeded 28 MB for over 4 hours, and the following error message
|
||||
was displayed:
|
||||
<span class="ph systemoutput"
|
||||
>Configuration size reaching device capacity limit</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308786</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
||||
traffic log queries using the
|
||||
<span class="ph uicontrol">device_name</span> filter returned no
|
||||
results, and complex log queries that included negation operators
|
||||
produced incorrect outputs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where packets were dropped on SD-WAN interfaces when a
|
||||
proxy was enabled due to an MTU inconsistency where the firewall
|
||||
failed to rewrite the maximum segment size in SYN/ACK packets based on
|
||||
the SD-WAN virtual interface MTU.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Note</b>: This fix does not apply when the traffic
|
||||
egress interface is SD-WAN Direct Internet Access (DIA) interface
|
||||
and proxy is enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
|
||||
issue where the firewall intermittently failed to maintain active log
|
||||
forwarding streams to Strata Logging Service (SLS) even when duplicate
|
||||
logging and enhanced application logging were enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308418</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when Advanced DNS Security was enabled and
|
||||
experienced unusually high loads, DNS resolution failures occurred
|
||||
with the error
|
||||
<span class="ph uicontrol">resources-unavailable</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306555</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall stopped responding, which led to
|
||||
service outages.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304019</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the firewall did not send traffic to SCM or SLS via a configured
|
||||
explicit proxy IP address when the proxy username was not configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303745</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where inter-dataplane forwarding did not work for
|
||||
sessions ingressing on Slot 2, which resulted in intermittent ping
|
||||
failures to interfaces on Network Card 2 when traffic was forwarded to
|
||||
Slot 3.
|
||||
</div>
|
||||
<div class="p">
|
||||
<b class="ph b">Note</b>: With this fix, after a slot restart, the
|
||||
global counter will still show dot1q errors for a short period.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302983</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after committing changes on Panorama, a shared
|
||||
post-rule moved to the end of the
|
||||
<span class="ph systemoutput">post shared rulebase</span> on the
|
||||
managed device instead of remaining at the top.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302564</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where a path monitoring failure
|
||||
occurred and caused the dataplane to restart.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301653</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS traffic sessions prematurely terminated with
|
||||
the message
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>resources-unavailable</a
|
||||
>. This occurred due to IPv4 fragmented DNS responses causing the
|
||||
Advanced DNS Security module to incorrectly pack the DNS payload
|
||||
multiple times when forwarding to the cloud for inspection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300837</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls experienced multiple reboots due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process restarting with a SIGSEGV signal. This occurred because the
|
||||
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300671</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where traffic reports that were generated with
|
||||
destination/source and destination/source hostnames were not displayed
|
||||
in IPv4 format.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300423</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
|
||||
and 6 remained stuck in a starting state with the error
|
||||
<span class="ph uicontrol"
|
||||
>Signal detected for port xeS5-DP0 but Link Down</span
|
||||
>
|
||||
alerts, which resulted in device instability.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299242</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall's SSL proxy sent an empty HTTP2
|
||||
SETTINGS message to the client before confirming server support, which
|
||||
caused some clients to incorrectly assume HTTP/2 support and not fall
|
||||
back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad
|
||||
Request frames from the server, which prevented the client from
|
||||
correctly detecting the lack of HTTP/2 support.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298617</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Optimized the commit workflow to reduce the size of the effective
|
||||
configuration, resulting in lower memory consumption.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297708</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a long-lived session with many Machine Learning
|
||||
(ML) model triggers caused a memory leak of feature states associated
|
||||
with the ML model runs. This resulted in Spyware_State failure
|
||||
increases, allocation max outs, and impaired policy matching.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295802</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a memory leak related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process occurred.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295309</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where OSPF session using MD5 authentication experienced
|
||||
intermittent flapping due to out-of-order packet processing.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293644</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||
issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process stopped responding during an External Dynamic List (EDL)
|
||||
refresh.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290938</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where multiple memory leaks occurred related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-264762</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall showed the status of SFP+ interfaces
|
||||
as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
|
||||
connected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-263691</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a
|
||||
memory leak in the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-248913</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Elasticsearch client certificate was not auto
|
||||
renewed, which caused it to enter a Red state, and logs were not
|
||||
displayed in Panorama.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,135 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291499</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||
only</tt
|
||||
>) Fixed an issue where newly deployed firewalls were unable to
|
||||
connect to the Palo Alto Networks Software License Server (SLS) until
|
||||
after a reboot, license fetch, or management server restart.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290241</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process became unresponsive, which caused User ID CLI commands to time
|
||||
out.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287688</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto
|
||||
Networks update server when using a customized service route with the
|
||||
source interface as <span class="ph uicontrol">MGT</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268680</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process stopped responding when a configuration merge operation
|
||||
changed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-268522</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall failed to connect to the update
|
||||
server with a customized service route when the source interface was
|
||||
set to <span class="ph uicontrol">MGT</span> and the source address
|
||||
was set as IPv4.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-241230</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the SNMP get request status value for Panorama
|
||||
connections was incorrect.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-216770</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when a firewall was managed by Strata Cloud
|
||||
Manager and configured to use a proxy server for external connections,
|
||||
the management server did not use the configured settings to connect
|
||||
to the Cloud Management service.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,349 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297458</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task_1</a
|
||||
>
|
||||
process crashed on the firewall when the wif service wasn't available
|
||||
because the wif detection ID was not in the current service table.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297261</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the proxy-protocol debug level was set to
|
||||
<span class="ph systemoutput">verbose</span> on Prisma Access
|
||||
instances, even when it was not explicitly configured, which caused
|
||||
excessive logging by the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296519</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a stream receiving a reconnect signal with an
|
||||
associated error in
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>Wifclient</a
|
||||
>
|
||||
caused the entire pool to close, which resulted in a complete
|
||||
disconnection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296478</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
|
||||
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
|
||||
JavaScript links, resulting in an authorization error. This occurred
|
||||
because the firewall was incorrectly injecting text into URLs when
|
||||
JavaScript buttons or dropdown menus were clicked within the
|
||||
Clientless VPN portal.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295812</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the throughput data on the Switch Card Module
|
||||
(SCM) was not accurately reported. This issue affected Standard SC
|
||||
USABN and USABN-2 when using Direct-IO deployment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294179</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where commit versions did not display
|
||||
correct data in the config audit page even after a refresh.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292202</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the system logs repeatedly displayed the alert
|
||||
<span class="ph systemoutput"
|
||||
>Clearing snmpd.log due to log overflow</span
|
||||
>
|
||||
due to the SNMP counters rolling over.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291631</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||
the firewall frequently rebooted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291288</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process restart related to page allocation failures.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-290449</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when multiple scheduled vulnerability reports
|
||||
were sent in the same email, only the first attached report was
|
||||
displayed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288726</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process stopped responding due to a Security policy rule ID being set
|
||||
to 0, which caused the last configuration retrieval to fail.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287423</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where content loading issues occurred on IPv6 websites
|
||||
due to the firewall incorrectly setting the IPv6 header flow label to
|
||||
0.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286299</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after
|
||||
being offboarded from Panorama, the firewall XML configuration file
|
||||
retained template information from the previous Panorama
|
||||
configuration. As a result, when the firewall and its configuration
|
||||
were imported to another Panorama appliance, all configurations in the
|
||||
<span class="ph uicontrol">Network</span> and
|
||||
<span class="ph uicontrol">Device</span> tabs became read-only.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-286231</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a simultaneous selective push from Panorama to
|
||||
multiple firewalls with different base configurations resulted in
|
||||
configuration corruption, which caused the firewall to go down.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285285</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where commits remained at 98% completion when static
|
||||
route configuration cleanup was in progress.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-284073</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall that caused commits to fail and the web
|
||||
interface to become inaccessible.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279706</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
|
||||
Panorama did not update all
|
||||
<span class="ph systemoutput">panreplay</span> database entries after
|
||||
performing a commit and full push to all devices.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-277034</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where WildFire reports were not fully displayed and
|
||||
were not downloadable due to static resources not being found.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-276484</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama did not display license information for
|
||||
Cloud NGFW firewalls under (<span class="ph uicontrol"
|
||||
>Device Deployment > Licenses</span
|
||||
>) due to the inability to perform batch-license refreshes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-259741</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall dropped GRE keepalive packets that
|
||||
were encapsulated under another GRE tunnel.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-251442</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted into maintenance mode if
|
||||
the authentication process restarted repeatedly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,708 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-304088</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where TCP traffic stopped working from Prisma Access
|
||||
clients to TCP services behind the Service Connection (SC) after a
|
||||
dataplane upgrade to an affected release.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-303559</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after manually creating a device telemetry
|
||||
bundle, the hour_cli_output.txt file within the bundle had a file size
|
||||
of 0 bytes. This occurred when checking the bundle content after
|
||||
enabling device telemetry and setting the device telemetry upload
|
||||
endpoint.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301828</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when a firewall was managed by Strata Cloud
|
||||
Manager and configured to use a proxy server for external connections,
|
||||
the management server did not use the configured settings to connect
|
||||
to the Cloud Management service.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300906</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where XML API commands failed with a
|
||||
<span class="ph systemoutput">Method not found (policy_xml)</span>
|
||||
error in dagger.log. The issue was due to missing XML-related
|
||||
functions for inline-cloud-proxy.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298505</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
|
||||
the vsys ID changed in sequence, causing autocommit failures with
|
||||
validation errors. This occurred when the multi-vsys firewall had
|
||||
virtual systems created and pushed from Panorama, and the vsys ID was
|
||||
not in a correct sequence because the unused vsys was deleted from
|
||||
Panorama and pushed to devices.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-298387</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where the source and destination NAT IP
|
||||
addresses did not display in traffic and threat logs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297972</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a dataplane crash occurred when traffic matched
|
||||
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
|
||||
Analysis features were not enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297775</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading, the
|
||||
<span class="ph uicontrol">Visible Virtual Systems</span> field
|
||||
started to reference the vsys name instead of the vsys ID, which
|
||||
caused inter-vsys routing to fail. This occurred when a vsys display
|
||||
name matched one of the vsys IDs.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297240</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where attempting to generate reports in a WildFire FIPS
|
||||
Private Cloud or WF-500 deployment returned 401 errors.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295560</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors,
|
||||
tunnel logs were not visible in Panorama or Splunk even though traffic
|
||||
and threat logs were received.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-295385</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where syslog forwarding dropped due to FQDN resolution
|
||||
failures.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295257</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after onboarding a firewall to Panorama, IPsec
|
||||
tunnels displayed IKEv2 in Panorama, even though the tunnels were
|
||||
configured with IKEv1 locally on the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295221</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors,
|
||||
Traffic and Threat logs were not forwarded to a Splunk server over
|
||||
UDP.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294893</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls with the
|
||||
<span class="ph uicontrol"
|
||||
>Send handshake messages to CTD for inspection</span
|
||||
>
|
||||
setting enabled caused incorrect security policy rules to be matched.
|
||||
Specifically, traffic not identified as openai-base or openai-chatgpt
|
||||
applications was incorrectly matched by the
|
||||
ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
|
||||
response page for blocked URLs was not displayed.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294524</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls and Panorama management servers were
|
||||
unable to view or download WildFire reports from a WF-500 appliance,
|
||||
resulting in a 401 error in the report tab.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294320</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>mprelay</a
|
||||
>
|
||||
process repeatedly restarted.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-294161</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process restarting and causing an HA failover. This occurred due to
|
||||
the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process timing out when running the CLI command
|
||||
<span class="ph systemoutput">show user user-id-agent config all</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292447</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where Panorama did not display data in the
|
||||
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
|
||||
Manager due to the system creating and deleting a CLI user for each
|
||||
interval instead of reusing a permanent CLI user for telemetry.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-291940</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall established multiple TCP connections
|
||||
to a syslog server, which caused logs to be dropped. This occurred
|
||||
because the firewall established a new TCP session for each transfer
|
||||
and the sessions were not closed, which resulted in a continuous
|
||||
increase in connections over time.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291716</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where during a commit, the firewall experienced an
|
||||
out-of-memory (OOM) condition due to a memory leak and displayed an
|
||||
error message. This issue caused the device to crash and reboot
|
||||
unexpectedly.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291653</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the GlobalProtect host ID field was
|
||||
intermittently blank in traffic logs on Prisma Access, even when the
|
||||
user was connected and had the correct host ID information. This
|
||||
occurred when the IP address to host ID entry expired and the entry
|
||||
was re-insterted without the dataplane flag being set.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291635</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where cookie surrogate cache entries remained
|
||||
unresolved after an
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>idmgr</a
|
||||
>
|
||||
process reset due to the request not being retransmitted. This
|
||||
occurred because the timestamp in the cache entry was refreshed even
|
||||
when the UID was 0, which prevented the retransmission of the request
|
||||
if the initial response was not received.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291283</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where a memory leak associated with the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process occurred during commits, which caused the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process to restart and the commit to fail.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291067</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>devsrvr</a
|
||||
>
|
||||
process periodically exceeded its virtual memory limit and restarted,
|
||||
which led to intermittent outages.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289859</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
|
||||
issue where Panorama failed to mount logging disks larger than 2TB due
|
||||
to a partitioning error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289405</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">VM-Series firewalls only</tt>) Added the CLI
|
||||
command
|
||||
<span class="ph systemoutput">no-refresh-discard-session</span> to
|
||||
address an issue where the discarded session time to live (TTL) did
|
||||
not refresh at the default value.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289383</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the MPLS interface eth1/6 went down and remained
|
||||
down, even after replacing the SFP with a supported one and adjusting
|
||||
duplex and speed settings.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289249</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a memory leak occurred on the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process when a WildFire update was initiated while device telemetry
|
||||
data collection was in progress. This resulted in an OOM condition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289109</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the Panorama web interface was slower than
|
||||
expected during configuration operations and a configuration lock time
|
||||
out occurred during a commit.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288097</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where on the firewall where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>routed</a
|
||||
>
|
||||
process stopped responding after changing the MTU or any link state
|
||||
parameters when OSPF and PIM were enabled on the same interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287803</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading, certain websites weren't
|
||||
accessible when the accumulation proxy was enabled. The proxy did not
|
||||
use the same DF bit state as the original traffic, causing it to be
|
||||
fragmented and dropped elsewhere in the network.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287782</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls configured in vwire mode modified DSCP
|
||||
values from AF11 to CS0 on traffic passing through the firewall, even
|
||||
when QoS policy rules and DSCP rewrite settings were not configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287622</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where IPv6 traffic was affected after upgrading the
|
||||
firewall. With SSL decryption enabled and a decryption policy
|
||||
configured for the traffic, the firewall dropped packets due to
|
||||
receiving a <span class="ph systemoutput">Packet Too Big</span> ICMP
|
||||
message. This occurred because the PathMTU information update was
|
||||
incorrect for the TCB (pan-server) when the firewall was acting as a
|
||||
server. Additionally, the flow label under the IPv6 header was set to
|
||||
zero while the packet was being transmitted out of the firewall.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287601</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where commits took longer than expected.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287387</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where API jobs failed with the error
|
||||
message
|
||||
<span class="ph systemoutput"
|
||||
>Server error: Timed out while getting config lock</span
|
||||
>. This occurred due to slow set request performance when setting a
|
||||
large number of address objects in a single set call.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-283053</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall experienced high disk space
|
||||
utilization, which caused the firewall to become non-functional.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-282277</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where an OOM condition on the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
process caused interface flapping, and the interface unexpectedly went
|
||||
down and then recovered without intervention.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-281776</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the Panorama web interface where the error message
|
||||
<span class="ph systemoutput"
|
||||
>PPPoEv6 Client Interface cannot be enabled with DHCPv6 client</span
|
||||
>
|
||||
was generated when overriding aggregate interfaces even when no DHCPv6
|
||||
or PPPoE was configured.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-278836</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after an upgrade, GlobalProtect attempted to use
|
||||
the embedded browser instead of the default browser for gateway
|
||||
authentication even when it was configured to use the default browser.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272245</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>dnsproxy</a
|
||||
>
|
||||
process stopped responding due to memory corruption caused by a race
|
||||
condition when the allow list downloading was impacted by a
|
||||
configuration change.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-267450</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process stopped responding with a SIGSEGV at
|
||||
<span class="ph systemoutput">schedule_report_es_response</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,96 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-306534</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue were the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process repeatedly restarted due to memory pool corruption when
|
||||
processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred
|
||||
due to incorrect buffer length calculations during memory deallocation
|
||||
when the query name field spanned multiple packets.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-305480</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process stopped responding while processing DoH JSON format traffic
|
||||
with DoH Security enabled, which caused missing cross-packet bytes in
|
||||
the decoded DNS query type field, and the dataplane went down.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-305301</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where GlobalProtect notifications in tunnels caused
|
||||
processes to stop responding and the dataplane to restart due to the
|
||||
session lookup returning an incorrect session, which resulted in the
|
||||
data being sent through the wrong tunnel.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292344</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted multiple times after an
|
||||
upgrade if the config contained an EDL (External Dynamic List) that
|
||||
didn't have an associated certificate profile.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -0,0 +1,578 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308727</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where traffic logs for
|
||||
<span class="ph uicontrol">Remote Networks</span> displayed the source
|
||||
zone as <span class="ph uicontrol">trust</span> instead of the remote
|
||||
network name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-308468</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task</a
|
||||
>
|
||||
process restarting.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-303051</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where a memory leak occurred related to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process due to retaining memory that was temporarily used for report
|
||||
generation instead of releasing the memory for reuse, which resulted
|
||||
in continuous accumulation and memory exhaustion.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-302927</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading Panorama, the
|
||||
<span class="ph uicontrol">Push to Devices</span> option did not
|
||||
display selected devices, and the
|
||||
<span class="ph uicontrol">OK</span> and
|
||||
<span class="ph uicontrol">Cancel</span>
|
||||
buttons did not function as expected. Selecting
|
||||
<span class="ph uicontrol">OK</span> did not close the window, and
|
||||
selecting <span class="ph uicontrol">Cancel</span> returned to the
|
||||
main push screen with the push selected devices displaying as empty.
|
||||
Despite this, selecting <span class="ph uicontrol">Push</span> or
|
||||
<span class="ph uicontrol">Validate Device Group Push</span> still
|
||||
pushed to the previously canceled, non-displayed devices.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301801</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Log Collectors where the Elasticsearch process
|
||||
fluctuated intermittently between green and red states, which led to
|
||||
interruptions in log collection. This issue occurred when the number
|
||||
of shards exceeded the cluster's maximum supported threshold of
|
||||
greater than 1000 shards per Elasticsearch instance.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301691</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where BGP stopped responding with the error message
|
||||
<span class="ph systemoutput">Too many open files</span> when pushing
|
||||
1000 eBGP (External BGP) neighbor configurations. With this fix, the
|
||||
number of file descriptors for the BGP process is increased from 1024
|
||||
to 8192.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-301456</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where the
|
||||
<span class="ph systemoutput">debug system reset-ztp</span> CLI
|
||||
command was unavailable.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300216</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when SD-WAN Direct Internet Access was
|
||||
configured and traffic traversed the cellular interface without a NAT
|
||||
policy rule, intermittent cellular modem connectivity issues occurred,
|
||||
which caused the firewall to disconnect and reconnect to the cellular
|
||||
network.
|
||||
</div>
|
||||
<div class="p">
|
||||
To use this fix, run the CLI command
|
||||
<span class="ph systemoutput"
|
||||
>set session teardown-upon-fwd-zonechange yes</span
|
||||
>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-300138</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS queries stalled or repeatedly time out due to
|
||||
multiple DNS responses with different CNAME values causing evasion
|
||||
false positive alerts.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-299772</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt"
|
||||
>VM-Series firewalls in active/passive configurations only</tt
|
||||
>) Fixed an issue where, after an HA failover event, the newly active
|
||||
firewall DHCP client interfaces failed to obtain IP addresses
|
||||
automatically. This occurred because the DHCP client processes did not
|
||||
initiate the necessary DHCP discover or renew requests
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297976</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall experienced extended boot times
|
||||
after a reboot due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>configd</a
|
||||
>
|
||||
process needing to rebuild the ACE catalog after detecting
|
||||
discrepancies that were caused by duplicate application checking
|
||||
between the ACE catalog and content.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b"> PAN-297610</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall became unresponsive after an upgrade
|
||||
due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>fsck</a
|
||||
>
|
||||
command scanning drive partitions in parallel with the root partition,
|
||||
which caused the process to take an extended amount of time.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297005</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where exporting custom reports resulted in empty CSV
|
||||
files.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296977</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the web interface became unresponsive when
|
||||
attempting to view
|
||||
<span class="ph uicontrol">Ethernet</span> interface details after
|
||||
applying a filter in
|
||||
<span class="ph menucascade"
|
||||
><span class="ph uicontrol">Network</span
|
||||
><span class="ph uicontrol">Interfaces</span></span
|
||||
>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296752</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">PA-1410 Firewalls only</tt>) Fixed an issue where
|
||||
the firewall experienced high management CPU usage and repeatedly
|
||||
rebooted when attempting to retrieve SMART data.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296694</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall rebooted due to the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>useridd</a
|
||||
>
|
||||
process repeatedly restarting during an IP-port data type writes to
|
||||
the redis from multiple sources such as TSA or XML in a scale
|
||||
environment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296535</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on the firewall where BGP peers disconnected when more
|
||||
than 500 BGP neighbors were configured in a single Logical Router
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295899</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where DNS resolution failed on Linux machines running
|
||||
GlobalProtect client version 6.2.6 when connected with DNS Security
|
||||
enabled. This occurred because the firewall incorrectly discarded DNS
|
||||
packets when processing multiple DNS requests or responses over the
|
||||
same session, even when no malicious verdict was received.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295342</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_comm</a
|
||||
>
|
||||
process stopped responding due to insufficient time allocated to read
|
||||
file descriptors when processing long messages.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295049</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>logrcvr</a
|
||||
>
|
||||
process stopped responding due to memory allocation errors during
|
||||
Redis communication.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-293985</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue with the Panorama web interface where admin users were
|
||||
unable to log in and received the error message
|
||||
<span class="ph uicontrol">504: Gateway Timeout</span>.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292770</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after reinstalling the device certificate,
|
||||
delayed telemetry data was displayed in AIOPS.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291661</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama appliances and Log Collectors where, after
|
||||
an upgrade, Elasticsearch intermittently entered into a Red state
|
||||
before automatically recovering.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-288388</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after an EDL certificate update or repository
|
||||
migration, authentication failures caused the firewall to not fall
|
||||
back to the last successfully cached EDL entries, which led to policy
|
||||
rules that referenced the EDL to not be enforced.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-287842</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>comm</a
|
||||
>
|
||||
process stopped responding due to missing heartbeats, which resulted
|
||||
in a system alert and HA communication loss on slot1.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-285169</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where Kerberos superusers were unable to
|
||||
edit policy rules because the target device tab was grayed out.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-281797</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where firewalls became unstable and stopped responding,
|
||||
which resulted in an OOM condition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-280917</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where the WildFire cloud URL contained an
|
||||
extra period character, which prevented the retrieval of WildFire
|
||||
analysis reports.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-279829</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where NAT pool leaks occurred during a test when RTSP
|
||||
traffic hit NAT rules.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-270554</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the GlobalProtect client (UWP) or metered hotspot
|
||||
connections triggered TLS resumption fo GlobalProtect portal
|
||||
authentication, which caused the portal authentication to fail with a
|
||||
<span class="ph systemoutput">valid cert required</span> error.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-264131</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>routed</a
|
||||
>
|
||||
process core failed the automation run.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-209516</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, when creating an interface, an error occurred
|
||||
when you clicked <span class="ph uicontrol">OK</span> without
|
||||
providing a value in the <span class="ph uicontrol">Tag</span> field
|
||||
even though the field was not displayed as mandatory.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-185731</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall was unable to parse the URL path and
|
||||
host when the host header was located in a different packet, which
|
||||
resulted in the firewall not logging the URL path in the first packet.
|
||||
</div>
|
||||
<div class="p">
|
||||
The fix is disabled by default. The following CLI commands can be used
|
||||
to enable/disable the feature: set system setting ctd
|
||||
url-crosspkt-host-path-caching enable set system setting ctd
|
||||
url-crosspkt-host-path-caching disable set system setting ctd
|
||||
url-crosspkt-host-path-caching default
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,280 @@
|
||||
<table class="table colsep rowsep table-striped">
|
||||
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||
|
||||
<colgroup>
|
||||
<col style="width: 25%" />
|
||||
<col style="width: 75%" />
|
||||
</colgroup>
|
||||
<thead class="thead">
|
||||
<tr class="row rowsep">
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||
</th>
|
||||
<th class="entry">
|
||||
<div class="p"><b class="ph b">Description</b></div>
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
|
||||
<tbody class="tbody">
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297972</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a dataplane crash occurred when traffic matched
|
||||
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
|
||||
Analysis features were not enabled.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297458</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>all_task_1</a
|
||||
>
|
||||
process crashed on the firewall when the wif service wasn't available
|
||||
because the wif detection ID was not in the current service table.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-297261</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the proxy-protocol debug level was set to
|
||||
<span class="ph systemoutput">verbose</span> on Prisma Access
|
||||
instances, even when it was not explicitly configured, which caused
|
||||
excessive logging by the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_task</a
|
||||
>
|
||||
process.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296519</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a stream receiving a reconnect signal with an
|
||||
associated error in
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>Wifclient</a
|
||||
>
|
||||
caused the entire pool to close, which resulted in a complete
|
||||
disconnection.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296478</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
|
||||
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
|
||||
JavaScript links, resulting in an authorization error. This occurred
|
||||
because the firewall was incorrectly injecting text into URLs when
|
||||
JavaScript buttons or dropdown menus were clicked within the
|
||||
Clientless VPN portal.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-296283</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where, on hardware platforms with the SaaS inline
|
||||
license, Additional Header Logging (AHL) hash table creation proceeded
|
||||
even when the feature was disabled through the CLI, potentially
|
||||
leading to crashes.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295944</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where static routes remained active in the FIB and RIB
|
||||
even when the associated physical port interface was down, which
|
||||
resulted in traffic being incorrectly routed through a non-operational
|
||||
interface.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295812</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the throughput data on the Switch Card Module
|
||||
(SCM) was not accurately reported. This issue affected Standard SC
|
||||
USABN and USABN-2 when using Direct-IO deployment.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-295342</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>pan_comm</a
|
||||
>
|
||||
process stopped responding due to insufficient time allocated to read
|
||||
file descriptors when processing long messages.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-292539</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
|
||||
the firewall generated incomplete or corrupted tech support files
|
||||
(TSF) due to high disk usage on the management plane.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-291940</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall established multiple TCP connections
|
||||
to a syslog server, which caused logs to be dropped. This occurred
|
||||
because the firewall established a new TCP session for each transfer
|
||||
and the sessions were not closed, which resulted in a continuous
|
||||
increase in connections over time.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-289249</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where a memory leak occurred on the
|
||||
<a
|
||||
class="term"
|
||||
href="#"
|
||||
title=""
|
||||
data-scope=""
|
||||
data-format="dita"
|
||||
data-type=""
|
||||
target="_self"
|
||||
>reportd</a
|
||||
>
|
||||
process when a WildFire update was initiated while device telemetry
|
||||
data collection was in progress. This resulted in an OOM condition.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-281721</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the firewall generated high-severity system
|
||||
alerts indicating that the configuration size exceeded the maximum
|
||||
recommended size, even when the configuration size was within the
|
||||
expected limits.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-277178</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue on Panorama where you were unable to delete a shared
|
||||
object due to the rulebase incorrectly referencing the shared object
|
||||
instead of the device group-specific object when the name was used.
|
||||
</div>
|
||||
<div class="p">
|
||||
To use this fix, delete the original shared object after cloning it to
|
||||
a device group with the same name.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="row rowsep">
|
||||
<td class="entry">
|
||||
<div class="p"><b class="ph b">PAN-272245</b></div>
|
||||
</td>
|
||||
<td class="entry relcol">
|
||||
<div class="p">
|
||||
Fixed an issue where the dnsproxy process crashed due to memory
|
||||
corruption caused by a race condition when allow list downloading was
|
||||
impacted by config change.
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -6,4 +6,4 @@ version: 11.2.0-h1
|
||||
|
||||
## PAN-272809
|
||||
|
||||
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
|
||||
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
|
||||
|
||||
@@ -26,7 +26,7 @@ Fixed an issue with session caching where the reportd process stopped responding
|
||||
|
||||
## PAN-227344
|
||||
|
||||
Fixed an issue on Panorama where PDF Summary Reports (Monitor > PDF Reports > Manage PDF Summary) displayed no data and were blank when predefined widgets were included in the summary report.
|
||||
Fixed an issue on Panorama where **PDF Summary Reports** (**Monitor > PDF Reports > Manage PDF Summary**) displayed no data and were blank when predefined widgets were included in the summary report.
|
||||
|
||||
## PAN-227305
|
||||
|
||||
@@ -90,7 +90,7 @@ Fixed an issue where the firewall CPU percentage was miscalculated, and the valu
|
||||
|
||||
## PAN-219768
|
||||
|
||||
Fixed an issue where you were unable to filter Data Filtering logs with Threat ID/NAME for custom data patterns created over Panorama.
|
||||
Fixed an issue where you were unable to filter Data Filtering logs with **Threat ID/NAME** for custom data patterns created over Panorama.
|
||||
|
||||
## PAN-219585
|
||||
|
||||
|
||||
@@ -6,4 +6,4 @@ version: 11.2.1-h1
|
||||
|
||||
## PAN-272809
|
||||
|
||||
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
|
||||
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
|
||||
|
||||
@@ -6,7 +6,7 @@ version: 11.2.1
|
||||
|
||||
## PAN-257919
|
||||
|
||||
Fixed an issue where, when using explicit proxy with SAML authentication, initiating SAML authentication with a non-GET request resulted in a 302 redirect response instead of the expected 200 ok response.
|
||||
Fixed an issue where, when using explicit proxy with SAML authentication, initiating SAML authentication with a non-GET request resulted in a **302 redirect** response instead of the expected **200 ok** response.
|
||||
|
||||
## PAN-256343
|
||||
|
||||
@@ -46,4 +46,4 @@ Fixed an issue where, when you committed the first configuration change after bo
|
||||
|
||||
## PAN-164885
|
||||
|
||||
Fixed an issue on Panorama where Commit and Push or Push to Devices operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping.
|
||||
Fixed an issue on Panorama where **Commit and Push** or **Push to Devices** operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping.
|
||||
|
||||
@@ -18,7 +18,7 @@ Fixed an issue on Panorama where a memory leak occurred related to the reportd p
|
||||
|
||||
## PAN-302927
|
||||
|
||||
Fixed an issue where, after upgrading Panorama, the Push to Devices option did not display selected devices, and the OK and Cancel buttons did not function as expected. Selecting OK did not close the window, and selecting Cancel returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting Push or Validate Device Group Push still pushed to the previously canceled, non-displayed devices.
|
||||
Fixed an issue where, after upgrading Panorama, the **Push to Devices** option did not display selected devices, and the **OK** and **Cancel** buttons did not function as expected. Selecting **OK** did not close the window, and selecting **Cancel** returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting **Push** or **Validate Device Group Push** still pushed to the previously canceled, non-displayed devices.
|
||||
|
||||
## PAN-301801
|
||||
|
||||
@@ -60,7 +60,7 @@ Fixed an issue where exporting custom reports resulted in empty CSV files.
|
||||
|
||||
## PAN-296977
|
||||
|
||||
Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in NetworkInterfaces
|
||||
Fixed an issue where the web interface became unresponsive when attempting to view **Ethernet** interface details after applying a filter in **Network** > **Interfaces**
|
||||
|
||||
## PAN-296694
|
||||
|
||||
@@ -80,7 +80,7 @@ Resolved multiple issues affecting IPSec tunnels using NAT Traversal (NAT-T) whe
|
||||
|
||||
## PAN-209516
|
||||
|
||||
Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory.
|
||||
Fixed an issue where, when creating an interface, an error occurred when you clicked **OK** without providing a value in the **Tag** field even though the field was not displayed as mandatory.
|
||||
|
||||
## PAN-185731
|
||||
|
||||
|
||||
@@ -58,4 +58,4 @@ Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code
|
||||
|
||||
## PAN-289723
|
||||
|
||||
Fixed an issue where the firewall web interface continuously loaded and not display any output when viewing the Route Table or FIB table (More Runtime Stats). This issue occurred when L3 configurations were added to ethernet and AE interfaces.
|
||||
Fixed an issue where the firewall web interface continuously loaded and not display any output when viewing the Route Table or FIB table (**More Runtime Stats**). This issue occurred when L3 configurations were added to ethernet and AE interfaces.
|
||||
|
||||
@@ -38,7 +38,9 @@ Fixed an issue where devices with 5G cellular modems did not support the ATT Fir
|
||||
|
||||
## PAN-285181
|
||||
|
||||
Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature.
|
||||
Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF.
|
||||
|
||||
To use this fix, run the CLI command debug iot eal memory-gc native
|
||||
|
||||
## PAN-278688
|
||||
|
||||
@@ -55,7 +57,3 @@ Fixed an issue where an incorrect ASIC configuration caused silent packet drops
|
||||
## PAN-269228
|
||||
|
||||
Fixed an issue where the all_task process stopped responding, which caused a split brain condition.
|
||||
|
||||
## PAN-267614
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected due to high CPU utilization on the mongodb process.
|
||||
|
||||
@@ -58,7 +58,7 @@ Fixed an issue where ports went down after an HA failover.
|
||||
|
||||
## PAN-298684
|
||||
|
||||
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and Network > Zones > Pre-NAT Identification enabled.
|
||||
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and **Network** > **Zones** > **Pre-NAT Identification** enabled.
|
||||
|
||||
## PAN-298654
|
||||
|
||||
@@ -92,9 +92,8 @@ Fixed an issue where, during a refresh of a large External Dynamic List (EDL), t
|
||||
|
||||
Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual System field referenced the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. If you're using a multivsys environment, you must upgrade your firewalls to a fixed PAN-OS version. The best practice is to upgrade both the firewalls and Panorama to a fixed PAN-OS version.
|
||||
|
||||
If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama.
|
||||
|
||||
After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
|
||||
- If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama.
|
||||
- After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
|
||||
|
||||
## PAN-297321
|
||||
|
||||
@@ -150,7 +149,7 @@ Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and T
|
||||
|
||||
## PAN-294893
|
||||
|
||||
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
Fixed an issue where firewalls with the **Send handshake messages to CTD for inspection** setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
|
||||
## PAN-294770
|
||||
|
||||
@@ -170,7 +169,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the useridd proce
|
||||
|
||||
## PAN-293985
|
||||
|
||||
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
|
||||
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message **504: Gateway Timeout**.
|
||||
|
||||
## PAN-293877
|
||||
|
||||
@@ -182,7 +181,7 @@ Fixed an issue where, when using the Hub vsys feature to redistribute Host Infor
|
||||
|
||||
## PAN-293848
|
||||
|
||||
Fixed an issue where Panorama failed to push the default value of None for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as None in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
|
||||
Fixed an issue where Panorama failed to push the default value of **None** for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as **None** in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
|
||||
|
||||
## PAN-293511
|
||||
|
||||
@@ -194,7 +193,7 @@ Fixed an issue where setting the logdb-quota for the desum log type to 0 caused
|
||||
|
||||
## PAN-292447
|
||||
|
||||
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
|
||||
## PAN-292393
|
||||
|
||||
@@ -214,7 +213,7 @@ Fixed an issue where, after configuring dual stack GlobalProtect with both IPv4
|
||||
|
||||
## PAN-292019
|
||||
|
||||
Fixed an issue on the Panorama web interface where cloud applications were not displayed under Objects > Applications after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI.
|
||||
Fixed an issue on the Panorama web interface where cloud applications were not displayed under **Objects > Applications** after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI.
|
||||
|
||||
## PAN-291883
|
||||
|
||||
@@ -262,7 +261,7 @@ Fixed an issue with firewalls enabled with Security profiles where certain traff
|
||||
VM-Series firewalls on Microsoft Azure environments in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message Unknown error during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
|
||||
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message **Unknown error** during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
|
||||
|
||||
## PAN-290455
|
||||
|
||||
@@ -286,7 +285,7 @@ Fixed an issue where firewalls configured in vwire mode modified DSCP values fro
|
||||
|
||||
## PAN-287693
|
||||
|
||||
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when Use Proxy Settings for Private Cloud was enabled.
|
||||
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when **Use Proxy Settings for Private Cloud** was enabled.
|
||||
|
||||
## PAN-287622
|
||||
|
||||
|
||||
@@ -1743,7 +1743,9 @@ Fixed an issue where the firewall did not automatically recover after a machine
|
||||
|
||||
## PAN-285181
|
||||
|
||||
Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature.
|
||||
Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF.
|
||||
|
||||
To use this fix, run the CLI command debug iot eal memory-gc native
|
||||
|
||||
## PAN-285169
|
||||
|
||||
|
||||
@@ -6,4 +6,4 @@ version: 11.2.2-h2
|
||||
|
||||
## PAN-272809
|
||||
|
||||
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
|
||||
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
|
||||
|
||||
@@ -14,7 +14,7 @@ Fixed an issue where the varrcvr process stopped responding when files were bein
|
||||
|
||||
## PAN-255773
|
||||
|
||||
Fixed an issue where errors related to applications in Content-preview caused commit failures.
|
||||
Fixed an issue where errors related to applications in **Content-preview** caused commit failures.
|
||||
|
||||
## PAN-248508
|
||||
|
||||
|
||||
@@ -6,7 +6,7 @@ version: 11.2.3-h3
|
||||
|
||||
## PAN-272809
|
||||
|
||||
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
|
||||
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
|
||||
|
||||
## PAN-247230
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@ Fixed an issue where the firewall did not reset the maximum latency timer for ho
|
||||
|
||||
## PAN-268823
|
||||
|
||||
Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter.
|
||||
Fixed an issue where **Monitor > Log Display** did not display all logs when you applied a filter.
|
||||
|
||||
## PAN-264549
|
||||
|
||||
@@ -26,4 +26,4 @@ Fixed an issue where, after modifying a policy rule on Panorama, pushes to the C
|
||||
|
||||
## PAN-259078
|
||||
|
||||
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
|
||||
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**.
|
||||
|
||||
@@ -22,7 +22,7 @@ Fixed an issue where dereferencing a NULL pointer that occurred when App-ID stop
|
||||
|
||||
## PAN-262013
|
||||
|
||||
Fixed an issue where Prisma Access mobile users did not receive no such name DNS responses from the firewall and were timed out.
|
||||
Fixed an issue where Prisma Access mobile users did not receive **no such name** DNS responses from the firewall and were timed out.
|
||||
|
||||
## PAN-261991
|
||||
|
||||
@@ -42,7 +42,7 @@ Fixed an issue where the firewall decremented the TTL/Hop limit for BGPv6 packet
|
||||
|
||||
## PAN-260059
|
||||
|
||||
Fixed an issue where Device Telemetry Regions did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off.
|
||||
Fixed an issue where **Device Telemetry Regions** did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off.
|
||||
|
||||
## PAN-259964
|
||||
|
||||
@@ -150,7 +150,7 @@ Fixed an issue where BGP routes from the active firewall were lost when the pass
|
||||
|
||||
## PAN-256666
|
||||
|
||||
Fixed an issue where the configd process stopped responding when Commit and Push operations were performed on multiple device groups.
|
||||
Fixed an issue where the configd process stopped responding when **Commit and Push** operations were performed on multiple device groups.
|
||||
|
||||
## PAN-256385
|
||||
|
||||
@@ -170,7 +170,7 @@ Fixed an issue where the logd process repeatedly restarted due to a buffer overf
|
||||
|
||||
## PAN-256249
|
||||
|
||||
Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (Network > Network Profiles > IKE Gateways).
|
||||
Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (**Network > Network Profiles > IKE Gateways**).
|
||||
|
||||
## PAN-256223
|
||||
|
||||
@@ -182,7 +182,7 @@ Fixed an issue where the management interface and front panel port interface sta
|
||||
|
||||
## PAN-255895
|
||||
|
||||
Fixed an issue where Panorama administrators with the Panorama Administrator dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles.
|
||||
Fixed an issue where Panorama administrators with the **Panorama Administrator** dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles.
|
||||
|
||||
## PAN-255820
|
||||
|
||||
@@ -190,7 +190,7 @@ Fixed an issue where the WildFire signature generation check box in Panorama did
|
||||
|
||||
## PAN-255711
|
||||
|
||||
Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking OK on the configuration window due to the log type Correlation incorrectly being displayed (Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation).
|
||||
Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking **OK** on the configuration window due to the log type **Correlation** incorrectly being displayed (**Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation**).
|
||||
|
||||
## PAN-255611
|
||||
|
||||
@@ -254,7 +254,7 @@ Fixed an issue where the firewall required a restart when an SD-WAN policy rule
|
||||
|
||||
## PAN-254411
|
||||
|
||||
Fixed an issue where the configd process stopped responding, which caused ERR_CONNECTION_REFUSED error messages to be displayed in admin sessions.
|
||||
Fixed an issue where the configd process stopped responding, which caused **ERR_CONNECTION_REFUSED** error messages to be displayed in admin sessions.
|
||||
|
||||
## PAN-254373
|
||||
|
||||
@@ -278,7 +278,7 @@ Fixed an issue where the CLI command show running security-policy timed out when
|
||||
|
||||
## PAN-253819
|
||||
|
||||
Fixed an issue where a User Activity Report was not generated by Run Now or not emailed through the Email Schedule when the locale setting was not English.
|
||||
Fixed an issue where a **User Activity Report** was not generated by **Run Now** or not emailed through the **Email Schedule** when the locale setting was not English.
|
||||
|
||||
## PAN-253452
|
||||
|
||||
@@ -350,7 +350,7 @@ Fixed an issue where network issues between the firewall and the log collector c
|
||||
|
||||
## PAN-250597
|
||||
|
||||
Fixed an issue where Global Find for a Panorama pushed shared address object displayed Others in the results.
|
||||
Fixed an issue where Global Find for a Panorama pushed shared address object displayed **Others** in the results.
|
||||
|
||||
## PAN-250462
|
||||
|
||||
@@ -378,7 +378,7 @@ Fixed an issue on the firewall where the Certificate Name character limit was 31
|
||||
|
||||
## PAN-250127
|
||||
|
||||
Fixed an issue where commits failed with the error message set is not allowed when default originate was enabled with a route map that included a set action.
|
||||
Fixed an issue where commits failed with the error message set is not allowed when **default originate** was enabled with a route map that included a set action.
|
||||
|
||||
## PAN-250024
|
||||
|
||||
@@ -386,7 +386,7 @@ Fixed an issue related to the reportd process where you were unable to log in to
|
||||
|
||||
## PAN-250021
|
||||
|
||||
Fixed an issue where Change Summary and Preview Changes displayed inconsistent information when changing an admin user password.
|
||||
Fixed an issue where **Change Summary** and **Preview Changes** displayed inconsistent information when changing an admin user password.
|
||||
|
||||
## PAN-250005
|
||||
|
||||
@@ -422,7 +422,7 @@ Fixed an issue on Panorama where commits failed when Advanced Routing was enable
|
||||
|
||||
## PAN-248130
|
||||
|
||||
Fixed an issue where the AND operation under a Dynamic Address Group comparison did not work after upgrading the AWS plugin to 3.0.1.
|
||||
Fixed an issue where the **AND** operation under a Dynamic Address Group comparison did not work after upgrading the AWS plugin to 3.0.1.
|
||||
|
||||
## PAN-247857
|
||||
|
||||
@@ -434,7 +434,7 @@ Fixed an issue on the firewall where a dataplane process restarted when updating
|
||||
|
||||
## PAN-247754
|
||||
|
||||
Fixed an issue where successful Commit and Push operations performed by SAML authenticated users were not reflected on the firewall.
|
||||
Fixed an issue where successful **Commit and Push** operations performed by SAML authenticated users were not reflected on the firewall.
|
||||
|
||||
## PAN-247575
|
||||
|
||||
@@ -470,7 +470,7 @@ Fixed an issue where single TLS session packets were sent to multiple firewalls
|
||||
|
||||
## PAN-245892
|
||||
|
||||
Fixed an issue where Log Filtering (Monitor > Logs) was slower than expected.
|
||||
Fixed an issue where Log Filtering (**Monitor > Logs**) was slower than expected.
|
||||
|
||||
## PAN-245556
|
||||
|
||||
@@ -486,7 +486,7 @@ Fixed an issue where the firewall TLS/SSL service profile exclusion settings wer
|
||||
|
||||
## PAN-243387
|
||||
|
||||
Fixed an issue where sessions ended with the message resources-unavailable when traffic hit a Security profile.
|
||||
Fixed an issue where sessions ended with the message **resources-unavailable** when traffic hit a Security profile.
|
||||
|
||||
## PAN-243240
|
||||
|
||||
|
||||
@@ -6,4 +6,4 @@ version: 11.2.4-h1
|
||||
|
||||
## PAN-272809
|
||||
|
||||
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
|
||||
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
|
||||
|
||||
@@ -204,7 +204,7 @@ Fixed an issue where the firewall displayed inaccurate throughput utilization st
|
||||
|
||||
## PAN-259881
|
||||
|
||||
Fixed an issue on Panorama where traffic log details were not displayed under detailed log view.
|
||||
Fixed an issue on Panorama where traffic log details were not displayed under **detailed log view**.
|
||||
|
||||
## PAN-258757
|
||||
|
||||
@@ -224,7 +224,7 @@ Fixed an issue on Panorama where configuration locks were observed during a part
|
||||
|
||||
## PAN-246699
|
||||
|
||||
Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy rules stopped incrementing.
|
||||
Fixed an issue on Panorama where **Rule Usage** and **Apps Seen** under Security policy rules stopped incrementing.
|
||||
|
||||
## PAN-245064
|
||||
|
||||
@@ -232,4 +232,4 @@ Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy
|
||||
Multi-vsys firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
|
||||
Fixed an issue where commits failed on the firewall after selecting **Export or push device config bundle** on Panorama and a force push was required.
|
||||
|
||||
@@ -30,11 +30,13 @@ Fixed an issue where the logrcvr process stopped responding due to an invalid SS
|
||||
|
||||
## PAN-287688
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**.
|
||||
|
||||
## PAN-279901
|
||||
|
||||
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
|
||||
An issue was fixed where the firewall dropped fragmented TLS ClientHello packets, which blocked access to certain websites. This occurred because the packets arrived truncated, in varying sizes and orders, and the firewall's heuristics failed to handle them correctly.
|
||||
|
||||
To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes
|
||||
|
||||
## PAN-268680
|
||||
|
||||
@@ -42,7 +44,7 @@ Fixed an issue where the configd process stopped responding when a configuration
|
||||
|
||||
## PAN-268522
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4.
|
||||
|
||||
## PAN-255914
|
||||
|
||||
|
||||
@@ -82,7 +82,7 @@ Fixed an issue where content loading issues occurred on IPv6 websites due to the
|
||||
|
||||
## PAN-286299
|
||||
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only.
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tabs became read-only.
|
||||
|
||||
## PAN-285285
|
||||
|
||||
@@ -106,7 +106,7 @@ Fixed an issue where Panorama did not update all panreplay database entries afte
|
||||
|
||||
## PAN-276484
|
||||
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes.
|
||||
|
||||
## PAN-273453
|
||||
|
||||
|
||||
@@ -62,7 +62,7 @@ Fixed an issue where, after upgrading to PAN-OS 11.1.6-h6 the Eth1/2, Eth1/3, Et
|
||||
|
||||
## PAN-292447
|
||||
|
||||
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
|
||||
## PAN-291940
|
||||
|
||||
@@ -86,7 +86,7 @@ Fixed an issue on Panorama where API jobs failed with the error message Server e
|
||||
|
||||
## PAN-284279
|
||||
|
||||
Fixed an issue where the policy destination always defaulted to any, even when specific IP addresses and FQDNs were specified during policy import.
|
||||
Fixed an issue where the policy destination always defaulted to **any**, even when specific IP addresses and FQDNs were specified during policy import.
|
||||
|
||||
## PAN-284067
|
||||
|
||||
@@ -94,7 +94,7 @@ Fixed a cumulative memory leak in the devsrvr process that occurred whenever the
|
||||
|
||||
## PAN-281776
|
||||
|
||||
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
|
||||
Fixed an issue on the Panorama web interface where the error message **PPPoEv6 Client Interface cannot be enabled with DHCPv6 client** was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
|
||||
|
||||
## PAN-279829
|
||||
|
||||
|
||||
@@ -4,6 +4,6 @@ product: PAN-OS
|
||||
version: 11.2.4-h15
|
||||
---
|
||||
|
||||
## PAN-000000
|
||||
## BLANK-000000
|
||||
|
||||
A fix was made to address CVE-2026-0227.
|
||||
A fix was made to address [CVE-2026-0227](https://security.paloaltonetworks.com/CVE-2026-0227).
|
||||
|
||||
@@ -18,4 +18,4 @@ Fixed an issue where the firewall did not reset the maximum latency timer for ho
|
||||
|
||||
## PAN-259078
|
||||
|
||||
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
|
||||
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**.
|
||||
|
||||
@@ -14,15 +14,15 @@ Fixed an issue where upgrading Panorama and pushing configurations to the firewa
|
||||
|
||||
## PAN-273994
|
||||
|
||||
A fix was made to address CVE-2025-0111.
|
||||
A fix was made to address [CVE-2025-0111](https://security.paloaltonetworks.com/CVE-2025-0111).
|
||||
|
||||
## PAN-273971
|
||||
|
||||
A fix was made to address CVE-2025-0108.
|
||||
A fix was made to address [CVE-2025-0108](https://security.paloaltonetworks.com/CVE-2025-0108).
|
||||
|
||||
## PAN-273278
|
||||
|
||||
A fix was made to address CVE-2025-0109.
|
||||
A fix was made to address [CVE-2025-0109](https://security.paloaltonetworks.com/CVE-2025-0109).
|
||||
|
||||
## PAN-273197
|
||||
|
||||
@@ -94,7 +94,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the all_task proc
|
||||
|
||||
## PAN-265742
|
||||
|
||||
Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable.
|
||||
Fixed an issue on the Panorama web interface where the **OK** button on the GlobalProtect gateway configuration dialog box was not clickable.
|
||||
|
||||
## PAN-263987
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@ Fixed an issue where scheduled SaaS application usage reports were generated inc
|
||||
|
||||
## PAN-276177
|
||||
|
||||
Fixed an issue where App Acceleration did not work with Oracle databases.
|
||||
Fixed an issue where **App Acceleration** did not work with Oracle databases.
|
||||
|
||||
## PAN-274791
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@ Fixed an issue where large IPv6 packets were reassembled incorrectly on the fire
|
||||
|
||||
## PAN-282206
|
||||
|
||||
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
|
||||
Fixed an issue where configuring Secure Web Gateway (SWG) in **no-auth** mode led to latency when no decryption policy rules or **No-decrypt** policy rules were present.
|
||||
|
||||
## PAN-282022
|
||||
|
||||
@@ -26,7 +26,7 @@ Fixed the support limitation for the Panorama M-600 and M-700 appliances.
|
||||
|
||||
## PAN-280471
|
||||
|
||||
Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected.
|
||||
Fixed an issue where navigating **Panorama > Monitor > Logs** was slower than expected.
|
||||
|
||||
## PAN-279746
|
||||
|
||||
@@ -90,7 +90,7 @@ Fixed an issue on Panorama where the configd process stopped responding when fil
|
||||
|
||||
## PAN-271351
|
||||
|
||||
A fix was made to address CVE-2025-0116.
|
||||
A fix was made to address [CVE-2025-0116](https://security.paloaltonetworks.com/CVE-2025-0116).
|
||||
|
||||
## PAN-270224
|
||||
|
||||
@@ -158,7 +158,7 @@ Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr p
|
||||
|
||||
## PAN-257619
|
||||
|
||||
Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks.
|
||||
Fixed an issue on Panorama where the **Task Manager** took longer than expected to display managed firewall report tasks.
|
||||
|
||||
## PAN-257028
|
||||
|
||||
|
||||
@@ -26,7 +26,7 @@ Fixed an issue where the firewall did not match the correct policy for SSL forwa
|
||||
|
||||
## PAN-268474
|
||||
|
||||
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop.
|
||||
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as **Valid** even when the firewall did not have the license, which caused traffic to drop.
|
||||
|
||||
## PAN-261999
|
||||
|
||||
|
||||
@@ -22,7 +22,7 @@ Fixed a race condition issue related to predict processing, which resulted in a
|
||||
|
||||
## PAN-287002
|
||||
|
||||
A fix was made to address CVE-2025-0133.
|
||||
A fix was made to address [CVE-2025-0133](https://security.paloaltonetworks.com/CVE-2025-0133).
|
||||
|
||||
## PAN-285894
|
||||
|
||||
@@ -54,7 +54,7 @@ Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInE
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
|
||||
Fixed an issue where, after an upgrade, the **mac receive error** counter in **receive incoming errors** increased, which resulted in SNMP alerts.
|
||||
|
||||
## PAN-283467
|
||||
|
||||
@@ -66,7 +66,7 @@ Fixed an issue where the firewall unexpectedly rebooted and entered maintenance
|
||||
|
||||
## PAN-283331
|
||||
|
||||
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
|
||||
Fixed an issue where selective pushes to managed devices failed when the **User ID Master Device** was configured.
|
||||
|
||||
## PAN-282069
|
||||
|
||||
@@ -106,7 +106,7 @@ Fixed an issue on firewalls in HA configurations where, when using the Cloud Ide
|
||||
|
||||
## PAN-271273
|
||||
|
||||
Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
|
||||
Fixed an issue where dynamic update downloads failed when **IPv6 firewalling** was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
|
||||
|
||||
## PAN-270379
|
||||
|
||||
@@ -138,7 +138,7 @@ Fixed an issue where large file downloads or uploads failed or remained in an in
|
||||
|
||||
## PAN-266900
|
||||
|
||||
Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall.
|
||||
Fixed an issue on the Panorama web interface where you were unable to click **OK** after selecting an install package type and file from the dropdown and selecting a firewall.
|
||||
|
||||
## PAN-265745
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@ Fixed an issue where, after modifying a policy rule on Panorama, pushes to the C
|
||||
|
||||
## PAN-268823
|
||||
|
||||
Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter.
|
||||
Fixed an issue where **Monitor > Log Display** did not display all logs when you applied a filter.
|
||||
|
||||
## PAN-267386
|
||||
|
||||
@@ -82,7 +82,7 @@ Fixed an issue where the firewall reported the same value over consecutive SNMP
|
||||
|
||||
## PAN-259767
|
||||
|
||||
Fixed an issue where GlobalProtect users were unable to connect when the option Block sessions if the certificate was not issued to the authenticating device was enabled in the certificate profile.
|
||||
Fixed an issue where GlobalProtect users were unable to connect when the option **Block sessions if the certificate was not issued to the authenticating device** was enabled in the certificate profile.
|
||||
|
||||
## PAN-259002
|
||||
|
||||
@@ -158,7 +158,7 @@ Fixed an issue where link flaps occurred on Panorama appliances in HA configurat
|
||||
|
||||
## PAN-225213
|
||||
|
||||
Fixed an issue where Push All Changes displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group.
|
||||
Fixed an issue where **Push All Changes** displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group.
|
||||
|
||||
## PAN-222542
|
||||
|
||||
|
||||
@@ -98,11 +98,11 @@ Fixed an issue where the firewall was unable to generate a TSF file due to a ful
|
||||
|
||||
## PAN-268474
|
||||
|
||||
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop.
|
||||
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as **Valid** even when the firewall did not have the license, which caused traffic to drop.
|
||||
|
||||
## PAN-268419
|
||||
|
||||
Fixed an issue where Managed Devices > Summary displayed incorrect subcolumns.
|
||||
Fixed an issue where **Managed Devices > Summary** displayed incorrect subcolumns.
|
||||
|
||||
## PAN-268229
|
||||
|
||||
@@ -110,7 +110,7 @@ Fixed an issue where the firewall stopped responding during session setup for EC
|
||||
|
||||
## PAN-268228
|
||||
|
||||
Fixed an issue where Panorama administrators were unable to select Edit Selection when pushing changes to devices if they logged in using TACACS authentication.
|
||||
Fixed an issue where Panorama administrators were unable to select **Edit Selection** when pushing changes to devices if they logged in using TACACS authentication.
|
||||
|
||||
## PAN-268127
|
||||
|
||||
@@ -154,7 +154,7 @@ Fixed an issue where multicast streams were unstable with ECMP and dropped every
|
||||
|
||||
## PAN-266900
|
||||
|
||||
Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall.
|
||||
Fixed an issue on the Panorama web interface where you were unable to click **OK** after selecting an install package type and file from the dropdown and selecting a firewall.
|
||||
|
||||
## PAN-266704
|
||||
|
||||
@@ -190,7 +190,7 @@ Fixed an issue where BFD sessions took longer than expected to establish after a
|
||||
|
||||
## PAN-266167
|
||||
|
||||
Fixed an issue where the restart option for IPSec tunnels was greyed out (Network > IPSec Tunnels > IKE Info).
|
||||
Fixed an issue where the **restart** option for IPSec tunnels was greyed out (**Network > IPSec Tunnels > IKE Info**).
|
||||
|
||||
## PAN-266003
|
||||
|
||||
@@ -210,11 +210,11 @@ Added debug functionality in the packet-diag log to address an issue regarding p
|
||||
|
||||
## PAN-265742
|
||||
|
||||
Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable.
|
||||
Fixed an issue on the Panorama web interface where the **OK** button on the GlobalProtect gateway configuration dialog box was not clickable.
|
||||
|
||||
## PAN-265621
|
||||
|
||||
Fixed an issue where the restart option for IPSec tunnels was greyed out when you attempted to restart the tunnel from Network > IPSec Tunnels > IKE Info.
|
||||
Fixed an issue where the **restart** option for IPSec tunnels was greyed out when you attempted to restart the tunnel from **Network > IPSec Tunnels > IKE Info**.
|
||||
|
||||
## PAN-265462
|
||||
|
||||
@@ -234,7 +234,7 @@ Fixed an issue where multiple segments of HTTP proxy connect messages were not h
|
||||
|
||||
## PAN-265344
|
||||
|
||||
Fixed an issue where Import GlobalProtect Client Package did not work after clicking OK after selecting a valid package under Device > GlobalProtect Client > Upload).
|
||||
Fixed an issue where **Import GlobalProtect Client Package** did not work after clicking **OK** after selecting a valid package under **Device > GlobalProtect Client > Upload**).
|
||||
|
||||
## PAN-265179
|
||||
|
||||
@@ -270,15 +270,15 @@ Fixed an issue where OSPF adjacencies failed to come up when using a subinterfac
|
||||
PA-220 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where Device > Setup was not displayed on the web interface.
|
||||
Fixed an issue where **Device > Setup** was not displayed on the web interface.
|
||||
|
||||
## PAN-264678
|
||||
|
||||
Fixed an issue where Preview Changes did not display configuration changes in Commit and push > Push Scope.
|
||||
Fixed an issue where **Preview Changes** did not display configuration changes in **Commit and push** > **Push Scope**.
|
||||
|
||||
## PAN-264662
|
||||
|
||||
Fixed an issue where HTTP POST requests were blocked for URLs that had the block-continue category configured.
|
||||
Fixed an issue where HTTP POST requests were blocked for URLs that had the **block-continue** category configured.
|
||||
|
||||
## PAN-264289
|
||||
|
||||
@@ -306,7 +306,7 @@ Fixed an issue where log collectors had a low incoming log rate.
|
||||
PA-440 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the Auto option for the interface duplex setting.
|
||||
Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the **Auto** option for the interface duplex setting.
|
||||
|
||||
## PAN-263843
|
||||
|
||||
@@ -378,7 +378,7 @@ Fixed an issue on firewalls in HA configurations where OSPF neighbors were not e
|
||||
|
||||
## PAN-262415
|
||||
|
||||
Fixed an issue where a partial configuration load failed for configuration files that contained regenerate-hostkeys.
|
||||
Fixed an issue where a partial configuration load failed for configuration files that contained **regenerate-hostkeys**.
|
||||
|
||||
## PAN-261997
|
||||
|
||||
@@ -514,7 +514,7 @@ Fixed an issue where BGP Aggregate Advertise filters did not work as expected wh
|
||||
|
||||
## PAN-260193
|
||||
|
||||
Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to Use System Default.
|
||||
Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to **Use System Default**.
|
||||
|
||||
## PAN-260149
|
||||
|
||||
@@ -538,7 +538,7 @@ Fixed an issue where the firewalls behind an Amazon Web Services (AWS) Gateway L
|
||||
|
||||
## PAN-259881
|
||||
|
||||
Fixed an issue on Panorama where traffic log details were not displayed under detailed log view.
|
||||
Fixed an issue on Panorama where traffic log details were not displayed under **detailed log view**.
|
||||
|
||||
## PAN-259870
|
||||
|
||||
@@ -562,11 +562,11 @@ Fixed an issue on Panorama where the web interface was slower than expected or u
|
||||
|
||||
## PAN-259200
|
||||
|
||||
Fixed an issue where the firewall displayed truncated zone names in the Block IP List log when a zone name contained more than 14 characters.
|
||||
Fixed an issue where the firewall displayed truncated zone names in the **Block IP List** log when a zone name contained more than 14 characters.
|
||||
|
||||
## PAN-259078
|
||||
|
||||
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
|
||||
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**.
|
||||
|
||||
## PAN-258996
|
||||
|
||||
@@ -610,7 +610,7 @@ Fixed an issue on the Panorama web interface where Security policy rules loaded
|
||||
|
||||
## PAN-258188
|
||||
|
||||
Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the OK button did not work.
|
||||
Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the **OK** button did not work.
|
||||
|
||||
## PAN-258149
|
||||
|
||||
@@ -618,7 +618,7 @@ Fixed an issue where the firewall dropped the SYN-ACK when using the TCP Fast Op
|
||||
|
||||
## PAN-257961
|
||||
|
||||
Fixed an issue on Panorama where Test Security Policy Match failed when the From or To zone fields were populated.
|
||||
Fixed an issue on Panorama where **Test Security Policy Match** failed when the **From** or **To** zone fields were populated.
|
||||
|
||||
## PAN-257912
|
||||
|
||||
@@ -654,7 +654,7 @@ Fixed an issue where firewalls entered a non-functional state and displayed the
|
||||
|
||||
## PAN-257021
|
||||
|
||||
"Fixed an issue on the web interface where Match Evidence log details for Monitor > Correlated events did not populate."
|
||||
"Fixed an issue on the web interface where **Match Evidence** log details for **Monitor > Correlated events** did not populate."
|
||||
|
||||
## PAN-256960
|
||||
|
||||
@@ -662,7 +662,7 @@ Fixed an issue where a custom portal login page was not displayed correctly in t
|
||||
|
||||
## PAN-256725
|
||||
|
||||
Fixed an issue on the Panorama interface where Traffic and Unified event details loaded more slowly than expected.
|
||||
Fixed an issue on the Panorama interface where **Traffic** and **Unified** event details loaded more slowly than expected.
|
||||
|
||||
## PAN-256669
|
||||
|
||||
@@ -690,7 +690,7 @@ Fixed an issue where GTP sessions remained as allocated sessions on the passive
|
||||
|
||||
## PAN-256115
|
||||
|
||||
Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a disconnected status for the inter-log collector connection.
|
||||
Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a **disconnected** status for the inter-log collector connection.
|
||||
|
||||
## PAN-255930
|
||||
|
||||
@@ -762,7 +762,7 @@ Fixed an issue where multiple SSHD process restarts triggered a firewall reboot
|
||||
|
||||
## PAN-252801
|
||||
|
||||
Fixed an issue where the LSVPN tunnel monitoring status displayed as No data available after re-key events.
|
||||
Fixed an issue where the LSVPN tunnel monitoring status displayed as **No data available** after re-key events.
|
||||
|
||||
## PAN-252604
|
||||
|
||||
@@ -770,7 +770,7 @@ Fixed an issue where the clientless VPN did not carry authentication to other ta
|
||||
|
||||
## PAN-252370
|
||||
|
||||
Fixed an issue where services with the reserved keyword application-default were allowed.
|
||||
Fixed an issue where services with the reserved keyword **application-default** were allowed.
|
||||
|
||||
## PAN-252300
|
||||
|
||||
@@ -822,7 +822,7 @@ Fixed an issue where stale BGP routes were advertised to peers even when they we
|
||||
|
||||
## PAN-249533
|
||||
|
||||
Fixed an issue where an internal error message was displayed when you selected Exclude video traffic from the tunnel (Windows and macOS only).
|
||||
Fixed an issue where an internal error message was displayed when you selected **Exclude video traffic from the tunnel (Windows and macOS only)**.
|
||||
|
||||
## PAN-249384
|
||||
|
||||
@@ -878,7 +878,7 @@ Fixed an issue where the web interface stopped responding when you searched for
|
||||
|
||||
## PAN-242957
|
||||
|
||||
Fixed an issue where the Rule usage columns of overridden default policy rules on the Security policy page stopped responding.
|
||||
Fixed an issue where the **Rule usage** columns of overridden default policy rules on the Security policy page stopped responding.
|
||||
|
||||
## PAN-242602
|
||||
|
||||
@@ -910,7 +910,7 @@ Fixed an issue where some commands did not have executable permissions.
|
||||
|
||||
## PAN-212889
|
||||
|
||||
Fixed an issue on Panorama where different threat names were used when querying a threat under Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in Threat Monitor and filtering it in the global filters.
|
||||
Fixed an issue on Panorama where different threat names were used when querying a threat under **Threat Monitor** (**Monitor > App Scope**) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in **Threat Monitor** and filtering it in the global filters.
|
||||
|
||||
## PAN-199141
|
||||
|
||||
|
||||
@@ -46,7 +46,7 @@ Fixed an issue where large IPv6 packets were reassembled incorrectly on the fire
|
||||
|
||||
## PAN-282206
|
||||
|
||||
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
|
||||
Fixed an issue where configuring Secure Web Gateway (SWG) in **no-auth** mode led to latency when no decryption policy rules or **No-decrypt** policy rules were present.
|
||||
|
||||
## PAN-282069
|
||||
|
||||
@@ -62,7 +62,7 @@ Fixed an Issue where commits failed with the error invalid IPv6 x:x - must be gl
|
||||
|
||||
## PAN-280471
|
||||
|
||||
Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected.
|
||||
Fixed an issue where navigating **Panorama > Monitor > Logs** was slower than expected.
|
||||
|
||||
## PAN-279983
|
||||
|
||||
@@ -70,7 +70,7 @@ Fixed an issue where navigating Panorama > Monitor > Logs was slower than expect
|
||||
PA-1400 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue on the web interface where Enable Bonjour Reflector was not displayed (Network > Interfaces > Ethernet Interface).
|
||||
Fixed an issue on the web interface where **Enable Bonjour Reflector** was not displayed (**Network > Interfaces > Ethernet Interface**).
|
||||
|
||||
## PAN-279746
|
||||
|
||||
@@ -122,7 +122,7 @@ Fixed an issue where unexpected failovers occurred on firewalls running PAN-OS 1
|
||||
|
||||
## PAN-277751
|
||||
|
||||
Fixed an issue where a policy-based forwarding (PBF) rule with an action of no-pbf and a service of TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a result, traffic was matched by a lower rule with a service of any and an action of forward.
|
||||
Fixed an issue where a policy-based forwarding (PBF) rule with an action of **no-pbf** and a service of TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a result, traffic was matched by a lower rule with a service of **any** and an action of **forward**.
|
||||
|
||||
## PAN-277629
|
||||
|
||||
@@ -150,7 +150,7 @@ Fixed an issue where a session lost the PBF rule mapping after a configuration c
|
||||
|
||||
## PAN-276177
|
||||
|
||||
Fixed an issue where App Acceleration did not work with Oracle databases.
|
||||
Fixed an issue where **App Acceleration** did not work with Oracle databases.
|
||||
|
||||
## PAN-276090
|
||||
|
||||
@@ -200,7 +200,7 @@ Fixed an issue where the firewall did not log the correct NAT IP address and sou
|
||||
|
||||
## PAN-273129
|
||||
|
||||
Fixed an issue on the web interface where the negate option was visible when you clicked on the rule name, but not when you viewed the target options from the rulebase attribute.
|
||||
Fixed an issue on the web interface where the **negate** option was visible when you clicked on the rule name, but not when you viewed the target options from the **rulebase** attribute.
|
||||
|
||||
## PAN-273026
|
||||
|
||||
@@ -220,7 +220,7 @@ Fixed an issue where log forwarding to a UDP syslog server stopped when an unrea
|
||||
|
||||
## PAN-272538
|
||||
|
||||
Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and share-unused-objects-with-devices was set to off.
|
||||
Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and **share-unused-objects-with-devices** was set to off.
|
||||
|
||||
## PAN-272171
|
||||
|
||||
@@ -244,7 +244,7 @@ Fixed an issue where pushing changes to a prefix list used for BGP from Panorama
|
||||
|
||||
## PAN-271273
|
||||
|
||||
Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
|
||||
Fixed an issue where dynamic update downloads failed when **IPv6 firewalling** was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
|
||||
|
||||
## PAN-271181
|
||||
|
||||
@@ -364,7 +364,7 @@ Fixed an issue where the firewall displayed an OCSP/CRL check failure when acces
|
||||
|
||||
## PAN-257619
|
||||
|
||||
Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks.
|
||||
Fixed an issue on Panorama where the **Task Manager** took longer than expected to display managed firewall report tasks.
|
||||
|
||||
## PAN-255914
|
||||
|
||||
@@ -388,7 +388,7 @@ Fixed an issue where the Panorama web interface was slower than expected when op
|
||||
Multi-vsys firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
|
||||
Fixed an issue where commits failed on the firewall after selecting **Export or push device config bundle** on Panorama and a force push was required.
|
||||
|
||||
## PAN-233647
|
||||
|
||||
|
||||
@@ -42,7 +42,7 @@ Fixed an issue where persistent commit failures occurred due to a missing transf
|
||||
|
||||
## PAN-289268
|
||||
|
||||
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user .
|
||||
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not **known-user**.
|
||||
|
||||
## PAN-288939
|
||||
|
||||
@@ -66,7 +66,9 @@ Fixed an issue where the popup window did not appear as expected for Clientless
|
||||
|
||||
## PAN-279901
|
||||
|
||||
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
|
||||
An issue was fixed where the firewall dropped fragmented TLS ClientHello packets, which blocked access to certain websites. This occurred because the packets arrived truncated, in varying sizes and orders, and the firewall's heuristics failed to handle them correctly.
|
||||
|
||||
To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes
|
||||
|
||||
## PAN-279690
|
||||
|
||||
@@ -98,4 +100,4 @@ Fixed an issue where the all_pktproc process stopped responding when the firewal
|
||||
|
||||
## PAN-252706
|
||||
|
||||
Fixed an issue where the URL filtering response page for Continue and Override did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
|
||||
Fixed an issue where the URL filtering response page for **Continue** and **Override** did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
|
||||
|
||||
@@ -16,9 +16,8 @@ Fixed an issue where a leak in decryption counters caused resource exhaustion, w
|
||||
|
||||
Fixed two issues that impacted TLSv1.2 or earlier sessions when the traffic matched a decryption policy rule with the no-decrypt action:
|
||||
|
||||
Connections failed when both HTTP header insertion (Objects > Security Profiles > URL Filtering > HTTP Header Insertion) and Send handshake messages to CTD for inspection (Device > Setup > Session > Decryption Settings > SSL Decryption Settings) were enabled.
|
||||
|
||||
New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both Block sessions with expired certificates and Block sessions with untrusted issuers disabled.
|
||||
- Connections failed when both HTTP header insertion (**Objects > Security Profiles > URL Filtering > HTTP Header Insertion**) and **Send handshake messages to CTD for inspection** (**Device > Setup > Session > Decryption Settings > SSL Decryption Settings**) were enabled.
|
||||
- New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both **Block sessions with expired certificates** and **Block sessions with untrusted issuers** disabled.
|
||||
|
||||
## PAN-306103
|
||||
|
||||
@@ -66,7 +65,7 @@ Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code
|
||||
Subject Common Name
|
||||
```
|
||||
|
||||
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the , Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
|
||||
Fixed an issue where certificate data was missing in decryption logs for **No decrypt** policy rules and TLS1.2 traffic after upgrading, and the , **Issuer Common Name**, **Certificate Start Date**,**Certificate End Date**, **Certificate Serial Number**, and **Certificate Fingerprint** fields were blank in the decryption logs.
|
||||
|
||||
## PAN-283563
|
||||
|
||||
@@ -82,7 +81,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f
|
||||
|
||||
## PAN-259853
|
||||
|
||||
Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when Any was selected as the source interface in the service router configuration (DeviceSetupServiceService Router Configuration).
|
||||
Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when **Any** was selected as the source interface in the service router configuration (**Device** > **Setup** > **Service** > **Service Router Configuration**).
|
||||
|
||||
## PAN-258039
|
||||
|
||||
|
||||
@@ -34,7 +34,9 @@ Fixed an issue where devices with 5G cellular modems did not support the ATT Fir
|
||||
|
||||
## PAN-285181
|
||||
|
||||
Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature.
|
||||
Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF.
|
||||
|
||||
To use this fix, run the CLI command debug iot eal memory-gc native
|
||||
|
||||
## PAN-278688
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@ Fixed an issue where the useridd process became unresponsive, which caused User
|
||||
|
||||
## PAN-287688
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**.
|
||||
|
||||
## PAN-268680
|
||||
|
||||
@@ -26,7 +26,7 @@ Fixed an issue where the configd process stopped responding when a configuration
|
||||
|
||||
## PAN-268522
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4.
|
||||
|
||||
## PAN-241230
|
||||
|
||||
|
||||
@@ -58,7 +58,7 @@ Fixed an issue where content loading issues occurred on IPv6 websites due to the
|
||||
|
||||
## PAN-286299
|
||||
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only.
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tabs became read-only.
|
||||
|
||||
## PAN-286231
|
||||
|
||||
@@ -86,7 +86,7 @@ Fixed an issue where WildFire reports were not fully displayed and were not down
|
||||
|
||||
## PAN-276484
|
||||
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes.
|
||||
|
||||
## PAN-259741
|
||||
|
||||
|
||||
@@ -34,7 +34,7 @@ Fixed an issue where a dataplane crash occurred when traffic matched Inline Clou
|
||||
|
||||
## PAN-297775
|
||||
|
||||
Fixed an issue where, after upgrading, the Visible Virtual Systems field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs.
|
||||
Fixed an issue where, after upgrading, the **Visible Virtual Systems** field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs.
|
||||
|
||||
## PAN-297240
|
||||
|
||||
@@ -58,7 +58,7 @@ Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and T
|
||||
|
||||
## PAN-294893
|
||||
|
||||
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
Fixed an issue where firewalls with the **Send handshake messages to CTD for inspection** setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
|
||||
## PAN-294524
|
||||
|
||||
@@ -74,7 +74,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the useridd proce
|
||||
|
||||
## PAN-292447
|
||||
|
||||
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
|
||||
## PAN-291940
|
||||
|
||||
|
||||
@@ -6,7 +6,7 @@ version: 11.2.7-h8
|
||||
|
||||
## PAN-308727
|
||||
|
||||
Fixed an issue where traffic logs for Remote Networks displayed the source zone as trust instead of the remote network name.
|
||||
Fixed an issue where traffic logs for **Remote Networks** displayed the source zone as **trust** instead of the remote network name.
|
||||
|
||||
## PAN-308468
|
||||
|
||||
@@ -18,7 +18,7 @@ Fixed an issue on Panorama where a memory leak occurred related to the reportd p
|
||||
|
||||
## PAN-302927
|
||||
|
||||
Fixed an issue where, after upgrading Panorama, the Push to Devices option did not display selected devices, and the OK and Cancel buttons did not function as expected. Selecting OK did not close the window, and selecting Cancel returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting Push or Validate Device Group Push still pushed to the previously canceled, non-displayed devices.
|
||||
Fixed an issue where, after upgrading Panorama, the **Push to Devices** option did not display selected devices, and the **OK** and **Cancel** buttons did not function as expected. Selecting **OK** did not close the window, and selecting **Cancel** returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting **Push** or **Validate Device Group Push** still pushed to the previously canceled, non-displayed devices.
|
||||
|
||||
## PAN-301801
|
||||
|
||||
@@ -64,7 +64,7 @@ Fixed an issue where exporting custom reports resulted in empty CSV files.
|
||||
|
||||
## PAN-296977
|
||||
|
||||
Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in NetworkInterfaces
|
||||
Fixed an issue where the web interface became unresponsive when attempting to view **Ethernet** interface details after applying a filter in **Network** > **Interfaces**
|
||||
|
||||
## PAN-296752
|
||||
|
||||
@@ -96,7 +96,7 @@ Fixed an issue where the logrcvr process stopped responding due to memory alloca
|
||||
|
||||
## PAN-293985
|
||||
|
||||
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
|
||||
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message **504: Gateway Timeout**.
|
||||
|
||||
## PAN-292770
|
||||
|
||||
@@ -140,7 +140,7 @@ Fixed an issue where the routed process core failed the automation run.
|
||||
|
||||
## PAN-209516
|
||||
|
||||
Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory.
|
||||
Fixed an issue where, when creating an interface, an error occurred when you clicked **OK** without providing a value in the **Tag** field even though the field was not displayed as mandatory.
|
||||
|
||||
## PAN-185731
|
||||
|
||||
|
||||
@@ -34,7 +34,7 @@ Fixed a race condition issue related to predict processing, which resulted in a
|
||||
|
||||
## PAN-288930
|
||||
|
||||
Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.
|
||||
Fixed an issue where traffic from cloud applications intermittently matched an incorrect **cloud-apps** policy rule when ACE (App-ID Cloud Engine) was enabled.
|
||||
|
||||
## PAN-287818
|
||||
|
||||
@@ -54,7 +54,7 @@ Fixed an issue where ECMP incorrectly balanced sessions across links based on th
|
||||
|
||||
## PAN-286825
|
||||
|
||||
Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the inactivity-logout setting was deleted and set to a different value.
|
||||
Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the **inactivity-logout** setting was deleted and set to a different value.
|
||||
|
||||
## PAN-285894
|
||||
|
||||
@@ -102,7 +102,7 @@ Fixed an issue on Panorama where the web interface performance was slower than u
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
|
||||
Fixed an issue where, after an upgrade, the **mac receive error** counter in **receive incoming errors** increased, which resulted in SNMP alerts.
|
||||
|
||||
## PAN-283644
|
||||
|
||||
@@ -114,11 +114,11 @@ Fixed an issue where URL log ingestion decreased after an upgrade, and secondary
|
||||
|
||||
## PAN-283331
|
||||
|
||||
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
|
||||
Fixed an issue where selective pushes to managed devices failed when the **User ID Master Device** was configured.
|
||||
|
||||
## PAN-282697
|
||||
|
||||
Fixed an issue where traffic was delayed significantly when it used No Authentication Explicit Proxy and matched a decryption policy rule.
|
||||
Fixed an issue where traffic was delayed significantly when it used **No Authentication Explicit Proxy** and matched a decryption policy rule.
|
||||
|
||||
## PAN-282640
|
||||
|
||||
@@ -142,7 +142,7 @@ Fixed an issue where the Panorama web interface was slower than expected.
|
||||
|
||||
## PAN-282240
|
||||
|
||||
Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the OK button displayed a console exception error.
|
||||
Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the **OK** button displayed a console exception error.
|
||||
|
||||
## PAN-281885
|
||||
|
||||
@@ -228,7 +228,7 @@ Fixed an issue where accessing a URL from the browser returned the error message
|
||||
|
||||
## PAN-279400
|
||||
|
||||
Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
|
||||
Fixed an issue where, when **Restrict Certificate Extensions** was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
|
||||
|
||||
## PAN-279336
|
||||
|
||||
@@ -240,7 +240,7 @@ Fixed an issue where the configuration audit displayed inaccurate information af
|
||||
|
||||
## PAN-279065
|
||||
|
||||
Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.
|
||||
Fixed an issue where the firewall sent logs with **connection succeeded** to the syslog server every time a connection was established, which resulted in excessive logs.
|
||||
|
||||
## PAN-278981
|
||||
|
||||
@@ -280,11 +280,11 @@ Fixed an issue where the logrcvr process discarded logs due to a full queue.
|
||||
|
||||
## PAN-277464
|
||||
|
||||
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the SSL Command and Control action was not either allow or alert and server hello packets were out of order.
|
||||
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the **SSL Command and Control** action was not either **allow** or **alert** and server hello packets were out of order.
|
||||
|
||||
## PAN-277234
|
||||
|
||||
Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none.
|
||||
Fixed an issue where a device group import resulted in a Security policy rule being created with **Application** set to **none**.
|
||||
|
||||
## PAN-277147
|
||||
|
||||
@@ -320,7 +320,7 @@ Fixed an issue where Panorama stopped forwarding logs to a syslog server after u
|
||||
|
||||
## PAN-275713
|
||||
|
||||
Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
|
||||
Fixed an issue where the dscd process stopped responding when **Endpoint Serial Number** was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
|
||||
|
||||
## PAN-275133
|
||||
|
||||
@@ -392,7 +392,7 @@ Fixed an issue where packets were dropped initially when a SYN cookie with activ
|
||||
|
||||
## PAN-273597
|
||||
|
||||
Fixed an issue where logs in the cloud database displayed in the Not-Resolved category but not in the local database.
|
||||
Fixed an issue where logs in the cloud database displayed in the **Not-Resolved** category but not in the local database.
|
||||
|
||||
## PAN-273453
|
||||
|
||||
@@ -522,7 +522,7 @@ Fixed an issue where the firewall redirected the user to the first application i
|
||||
Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.
|
||||
Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the **mac receive error** counter increased without an error even though traffic was not impacted.
|
||||
|
||||
## PAN-268708
|
||||
|
||||
@@ -530,7 +530,7 @@ Fixed an issue where PDF summary and email reports displayed IPv6 addresses inst
|
||||
|
||||
## PAN-268614
|
||||
|
||||
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.
|
||||
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the **Highlight Unused Rules** checkbox.
|
||||
|
||||
## PAN-268489
|
||||
|
||||
@@ -610,7 +610,7 @@ Fixed an issue where a commit for a policy and configuration dump overlapped, wh
|
||||
|
||||
## PAN-261074
|
||||
|
||||
Fixed an issue where the firewall delayed video file transfers over SMB when Exclude Video Traffic from the Tunnel feature was enabled and no applications were added to the list.
|
||||
Fixed an issue where the firewall delayed video file transfers over SMB when **Exclude Video Traffic** from the Tunnel feature was enabled and no applications were added to the list.
|
||||
|
||||
## PAN-260229
|
||||
|
||||
@@ -670,7 +670,7 @@ Fixed an issue on Panorama where a core file was generated by /usr/local/bin/log
|
||||
|
||||
## PAN-254524
|
||||
|
||||
Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed.
|
||||
Fixed an issue on Panorama where, when the **Commit and Push** button was clicked during a selective **Commit and Push** operation, the window stopped responding, which caused the operation to be delayed.
|
||||
|
||||
## PAN-253127
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@ Fixed an issue where the logrcvr process stopped responding due to memory alloca
|
||||
|
||||
## PAN-294488
|
||||
|
||||
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the Subject Common Name, Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
|
||||
Fixed an issue where certificate data was missing in decryption logs for **No decrypt** policy rules and TLS1.2 traffic after upgrading, and the **Subject Common Name**, **Issuer Common Name**, **Certificate Start Date**, **Certificate End Date**, **Certificate Serial Number**, and **Certificate Fingerprint** fields were blank in the decryption logs.
|
||||
|
||||
## PAN-294436
|
||||
|
||||
@@ -46,7 +46,7 @@ Fixed an issue where, after upgrading the firewall having an IKE gateway that us
|
||||
Panorama virtual appliances in FIPS mode only
|
||||
```
|
||||
|
||||
Fixed an issue where plugin installs failed with the error invalid image after manually uploading the plugin package from the Customer Support Portal (CSP).
|
||||
Fixed an issue where plugin installs failed with the error **invalid image** after manually uploading the plugin package from the Customer Support Portal (CSP).
|
||||
|
||||
## PAN-292503
|
||||
|
||||
@@ -142,7 +142,7 @@ Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections P
|
||||
Panorama virtual appliances only
|
||||
```
|
||||
|
||||
Fixed an issue on the web interface where you were unable to export the Threat Map.
|
||||
Fixed an issue on the web interface where you were unable to export the **Threat Map**.
|
||||
|
||||
## PAN-290900
|
||||
|
||||
@@ -150,11 +150,11 @@ Fixed an issue where Panorama in FIPS-CC mode failed to push IKEv2 Post-Quantum
|
||||
|
||||
## PAN-290702
|
||||
|
||||
Fixed an issue where Log Quotas incorrectly displayed a value that was higher than possible.
|
||||
Fixed an issue where **Log Quotas** incorrectly displayed a value that was higher than possible.
|
||||
|
||||
## PAN-290694
|
||||
|
||||
Fixed an issue on the Panorama web interface where you were unable to push shared objects to devices if an HA failover occurred during a configuration push.
|
||||
Fixed an issue on the Panorama web interface where you were unable to **push** shared objects to devices if an HA failover occurred during a configuration push.
|
||||
|
||||
## PAN-290691
|
||||
|
||||
@@ -166,15 +166,15 @@ Fixed an issue where, when multiple scheduled vulnerability reports were were se
|
||||
|
||||
## PAN-290241
|
||||
|
||||
Fixed an issue where the useridd process became unresponsive, which caused User ID CLI commands to time out.
|
||||
Fixed an issue where the **useridd** process became unresponsive, which caused User ID CLI commands to time out.
|
||||
|
||||
## PAN-290191
|
||||
|
||||
Fixed an issue where BGP learned routes were not advertised when Legacy Routing was used and an export policy rule was configured to match the next hop of the learned route.
|
||||
Fixed an issue where BGP learned routes were not advertised when **Legacy Routing** was used and an export policy rule was configured to match the next hop of the learned route.
|
||||
|
||||
## PAN-290157
|
||||
|
||||
Fixed an issue on Panorama where the configd process stopped responding when filtering in the Config Audit window, which caused Panorama to restart unexpectedly.
|
||||
Fixed an issue on Panorama where the configd process stopped responding when filtering in the **Config Audit** window, which caused Panorama to restart unexpectedly.
|
||||
|
||||
## PAN-290088
|
||||
|
||||
@@ -226,7 +226,7 @@ Fixed an issue related to external URL lists where pushing configuration changes
|
||||
|
||||
## PAN-289573
|
||||
|
||||
Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.
|
||||
Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the **Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access** setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.
|
||||
|
||||
## PAN-289532
|
||||
|
||||
@@ -266,7 +266,7 @@ Fixed an issue on the Panorama web interface where a template name or device gro
|
||||
|
||||
## PAN-289268
|
||||
|
||||
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user.
|
||||
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not **known-user**.
|
||||
|
||||
## PAN-289239
|
||||
|
||||
@@ -370,7 +370,7 @@ Fixed an issue where the maximum registered IP address for was incorrectly set t
|
||||
|
||||
## PAN-287842
|
||||
|
||||
Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
|
||||
Fixed an issue where the **comm** process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
|
||||
|
||||
## PAN-287838
|
||||
|
||||
@@ -386,11 +386,11 @@ Fixed an issue where SAML authentication failed, which caused the GlobalProtect
|
||||
|
||||
## PAN-287734
|
||||
|
||||
Fixed an issue where the error message Scan ERR: Internal Err 1002 was generated unexpectedly when WIF shared memory use was high.
|
||||
Fixed an issue where the error message **Scan ERR: Internal Err 1002** was generated unexpectedly when WIF shared memory use was high.
|
||||
|
||||
## PAN-287688
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**.
|
||||
|
||||
## PAN-287621
|
||||
|
||||
@@ -474,7 +474,7 @@ Fixed an issue where the device-group-tags CLI command used an unnecessary confi
|
||||
VM-Series firewalls only AWS environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not send ICMP unreachable - Fragmentation Needed message when it received packets larger than the MTU.
|
||||
Fixed an issue where the firewall did not send **ICMP unreachable - Fragmentation Needed** message when it received packets larger than the MTU.
|
||||
|
||||
## PAN-286818
|
||||
|
||||
@@ -486,7 +486,7 @@ Fixed an issue where closing an SSH session to a Panorama using Ctrl+D did not g
|
||||
Panorama virtual appliances in HA configurations on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where plugin versions displayed when hovering over the Green Match icon were inconsistent even though the web interface reported the versions as matching.
|
||||
Fixed an issue where plugin versions displayed when hovering over the **Green Match** icon were inconsistent even though the web interface reported the versions as matching.
|
||||
|
||||
## PAN-286734
|
||||
|
||||
@@ -502,7 +502,7 @@ Added uplink counters to enhance debug capability for traffic drops.
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where the Require SSL/TLS secured connection in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.
|
||||
Fixed an issue where the **Require SSL/TLS secured connection** in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.
|
||||
|
||||
## PAN-286669
|
||||
|
||||
@@ -526,7 +526,7 @@ Fixed an issue on Panorama where logs were not forwarded to syslog servers due t
|
||||
|
||||
## PAN-286475
|
||||
|
||||
Fixed an issue where the option to sort sequence numbers was missing from Filters prefix list in the advanced routing filters.
|
||||
Fixed an issue where the option to sort sequence numbers was missing from **Filters prefix list** in the advanced routing filters.
|
||||
|
||||
## PAN-286443
|
||||
|
||||
@@ -538,7 +538,7 @@ Fixed an issue where, when getting transceiver information from ESCC for SFP 25G
|
||||
|
||||
## PAN-286299
|
||||
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tab became read-only.
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tab became read-only.
|
||||
|
||||
## PAN-286231
|
||||
|
||||
@@ -562,7 +562,7 @@ Fixed an issue where the XML API returned an error when attempting to view debug
|
||||
|
||||
## PAN-285834
|
||||
|
||||
Fixed an issue on Panorama where Policy recommendation displayed Unable to read data for certain profiles due to a large response size.
|
||||
Fixed an issue on Panorama where **Policy recommendation** displayed **Unable to read data** for certain profiles due to a large response size.
|
||||
|
||||
## PAN-285818
|
||||
|
||||
@@ -606,7 +606,7 @@ Fixed an issue where commits remained at 98% completion when static route config
|
||||
|
||||
## PAN-284907
|
||||
|
||||
Fixed an issue where the Panorama web interface displayed No Data when viewing configuration logs to see changes before and after a configuration change.
|
||||
Fixed an issue where the Panorama web interface displayed **No Data** when viewing configuration logs to see changes before and after a configuration change.
|
||||
|
||||
## PAN-284878
|
||||
|
||||
@@ -638,7 +638,7 @@ Fixed an issue where, when a firewall had more than 4,400 logical interfaces, co
|
||||
|
||||
## PAN-284441
|
||||
|
||||
Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message Network Connection is unreachable.
|
||||
Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message **Network Connection is unreachable**.
|
||||
|
||||
## PAN-284380
|
||||
|
||||
@@ -702,7 +702,7 @@ Fixed an issue where HTTP/2 child streams were blocked by strict-ip-check zone p
|
||||
|
||||
## PAN-283613
|
||||
|
||||
Fixed an issue on the web interface where the IP Tag Quota(%) value displayed as 2 even when changed.
|
||||
Fixed an issue on the web interface where the **IP Tag** **Quota(%)** value displayed as 2 even when changed.
|
||||
|
||||
## PAN-283575
|
||||
|
||||
@@ -726,7 +726,7 @@ Fixed an issue where the SAML single log out (SLO) URL was not correctly display
|
||||
|
||||
## PAN-283333
|
||||
|
||||
Fixed an issue where threat logs displayed logs from the N/A threat category when a random string was used for the category-of-threatid filter in threat logs.
|
||||
Fixed an issue where threat logs displayed logs from the **N/A** threat category when a random string was used for the **category-of-threatid** filter in threat logs.
|
||||
|
||||
## PAN-283316
|
||||
|
||||
@@ -738,7 +738,7 @@ Fixed an issue where the OSPFv3 area nssa default-information-originate CLI comm
|
||||
|
||||
## PAN-283206
|
||||
|
||||
Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking Send Test Log.
|
||||
Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking **Send Test Log**.
|
||||
|
||||
## PAN-283168
|
||||
|
||||
@@ -774,7 +774,7 @@ Fixed an issue where firewalls in air-gapped environments attempted to connect t
|
||||
|
||||
## PAN-282454
|
||||
|
||||
Fixed an issue where, when you added the Virtual System Name column under Unified Logs, the column did not remain visible in the table if you closed and re-opened the tab.
|
||||
Fixed an issue where, when you added the **Virtual System Name** column under **Unified Logs**, the column did not remain visible in the table if you closed and re-opened the tab.
|
||||
|
||||
## PAN-282277
|
||||
|
||||
@@ -786,7 +786,7 @@ Fixed an issue where firewalls became unstable and stopped responding, which res
|
||||
|
||||
## PAN-281776
|
||||
|
||||
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
|
||||
Fixed an issue on the Panorama web interface where the error message **PPPoEv6 Client Interface cannot be enabled with DHCPv6 client** was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
|
||||
|
||||
## PAN-281596
|
||||
|
||||
@@ -810,11 +810,11 @@ Fixed an issue on Panorama managed firewalls where, when the service route confi
|
||||
|
||||
## PAN-281096
|
||||
|
||||
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to all, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
|
||||
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to **all**, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
|
||||
|
||||
## PAN-281017
|
||||
|
||||
Fixed an issue where shared objects were displayed in the Push Scope after pushing the configuration from Panorama to managed firewalls.
|
||||
Fixed an issue where shared objects were displayed in the **Push Scope** after pushing the configuration from Panorama to managed firewalls.
|
||||
|
||||
## PAN-280910
|
||||
|
||||
@@ -846,7 +846,7 @@ Fixed an issue in the URL filtering logs where the columns and the displayed con
|
||||
|
||||
## PAN-280013
|
||||
|
||||
Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter ip notin 0.0.0.0.
|
||||
Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter **ip notin 0.0.0.0**.
|
||||
|
||||
## PAN-279829
|
||||
|
||||
@@ -870,7 +870,7 @@ Fixed an issue where threat names were displayed differently on the web interfac
|
||||
|
||||
## PAN-279584
|
||||
|
||||
Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when Reboot device after install was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent.
|
||||
Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when **Reboot device after install** was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent.
|
||||
|
||||
## PAN-279415
|
||||
|
||||
@@ -886,7 +886,7 @@ Fixed an issue where changes made to the management interface permitted IP addre
|
||||
|
||||
## PAN-279195
|
||||
|
||||
Fixed an issue on Panorama where Device Health displayed the device memory as 0%.
|
||||
Fixed an issue on Panorama where **Device Health** displayed the device memory as 0%.
|
||||
|
||||
## PAN-278836
|
||||
|
||||
@@ -902,7 +902,7 @@ Fixed an issue where the configd process restarted during a configuration push f
|
||||
|
||||
## PAN-278507
|
||||
|
||||
Fixed an issue where the OCSP Signing purpose was not included in the Extended Key Usage field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error Missing OCSP signing purpose in the ExtendedKeyUsage.
|
||||
Fixed an issue where the OCSP Signing purpose was not included in the **Extended Key Usage** field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error **Missing OCSP signing purpose in the ExtendedKeyUsage**.
|
||||
|
||||
## PAN-278364
|
||||
|
||||
@@ -926,7 +926,7 @@ Fixed an issue where the number of registered IP Tags on Panorama did not match
|
||||
VM-Series firewalls in AWS environments only
|
||||
```
|
||||
|
||||
Fixed an issue where HA failover mode incorrectly changed from interface move to secondary IP move after a reboot.
|
||||
Fixed an issue where HA failover mode incorrectly changed from **interface move** to **secondary IP move** after a reboot.
|
||||
|
||||
## PAN-277759
|
||||
|
||||
@@ -938,7 +938,7 @@ Fixed an issue that caused the request system private-data-reset CLI command to
|
||||
|
||||
## PAN-277682
|
||||
|
||||
Fixed an issue where moving an address object from a device group to shared and renaming it did not reflect in the address group, which caused commits to fail.
|
||||
Fixed an issue where moving an address object from a device group to **shared** and renaming it did not reflect in the address group, which caused commits to fail.
|
||||
|
||||
## PAN-277617
|
||||
|
||||
@@ -978,7 +978,7 @@ Fixed an issue on Panorama where the logd process stopped responding unexpectedl
|
||||
|
||||
## PAN-276795
|
||||
|
||||
Fixed an issue where the GlobalProtect client displayed an error message when you clicked Check Now and Preferred Releases and Base Releases were unchecked (Device > Software).
|
||||
Fixed an issue where the GlobalProtect client displayed an error message when you clicked **Check Now** and **Preferred Releases** and **Base Releases** were unchecked (**Device > Software**).
|
||||
|
||||
## PAN-276694
|
||||
|
||||
@@ -1002,11 +1002,11 @@ Fixed an issue where Panorama stopped responding when running reports.
|
||||
|
||||
## PAN-276484
|
||||
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes.
|
||||
|
||||
## PAN-276412
|
||||
|
||||
Fixed an issue where you were unable to download XML files from Panorama > Summary > Backups.
|
||||
Fixed an issue where you were unable to download XML files from **Panorama > Summary > Backups**.
|
||||
|
||||
## PAN-276352
|
||||
|
||||
@@ -1014,15 +1014,15 @@ Fixed an issue where multicast flows were dropped due to a missing sysd variable
|
||||
|
||||
## PAN-276321
|
||||
|
||||
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as unknown, which prevented access to resources based on AD group membership.
|
||||
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as **unknown**, which prevented access to resources based on AD group membership.
|
||||
|
||||
## PAN-276144
|
||||
|
||||
Fixed an issue on the web interface where the Response Page action column was not accessible.
|
||||
Fixed an issue on the web interface where the **Response Page** **action** column was not accessible.
|
||||
|
||||
## PAN-276033
|
||||
|
||||
Fixed an issue on Panorama managed firewalls where SAML identity provider and Clientless Apps objects did not have override or revert options.
|
||||
Fixed an issue on Panorama managed firewalls where **SAML identity provider** and **Clientless Apps** objects did not have override or revert options.
|
||||
|
||||
## PAN-276000
|
||||
|
||||
@@ -1038,7 +1038,7 @@ Fixed an issue where the Log Collector service did not start on a new Log Collec
|
||||
|
||||
## PAN-275601
|
||||
|
||||
Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the Validate option, the upload failed with the error Failed to create multi-upload job. No valid software deploy targets found.
|
||||
Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the **Validate** option, the upload failed with the error **Failed to create multi-upload job. No valid software deploy targets found**.
|
||||
|
||||
## PAN-275451
|
||||
|
||||
@@ -1066,7 +1066,7 @@ Fixed an issue where you were unable to to adjust the frequency of the Advanced
|
||||
|
||||
## PAN-274907
|
||||
|
||||
Fixed an issue on Panorama where Config Audit Commit Date displayed the timestamp of the configuration edit instead of the commit time.
|
||||
Fixed an issue on Panorama where **Config Audit Commit Date** displayed the timestamp of the configuration edit instead of the commit time.
|
||||
|
||||
## PAN-274650
|
||||
|
||||
@@ -1106,11 +1106,11 @@ Fixed an issue on Panorama where the request batch license info CLI command disp
|
||||
|
||||
## PAN-274038
|
||||
|
||||
Fixed an issue where you were unable to use the s_encrypted field in custom reports for the Panorama threat log database.
|
||||
Fixed an issue where you were unable to use the **s_encrypted** field in custom reports for the Panorama threat log database.
|
||||
|
||||
## PAN-273991
|
||||
|
||||
Fixed an issue where the transmit power for a cable that was used on port 44 displayed as N/A.
|
||||
Fixed an issue where the transmit power for a cable that was used on port 44 displayed as **N/A**.
|
||||
|
||||
## PAN-273969
|
||||
|
||||
@@ -1134,7 +1134,7 @@ Fixed an issue where firewalls configured with a VPN tunnel stopped responding w
|
||||
|
||||
## PAN-273010
|
||||
|
||||
Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the Rule Changes field of the Security policy rule.
|
||||
Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the **Rule Changes** field of the Security policy rule.
|
||||
|
||||
## PAN-273008
|
||||
|
||||
@@ -1154,15 +1154,15 @@ Fixed an issue where you were unable to export the GlobalProtect client software
|
||||
|
||||
## PAN-272790
|
||||
|
||||
Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an scp export failed error. This was due to the system attempting to retrieve the file from an incorrect directory.
|
||||
Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an **scp export failed** error. This was due to the system attempting to retrieve the file from an incorrect directory.
|
||||
|
||||
## PAN-272743
|
||||
|
||||
Fixed an issue where non-captive portal traffic was not visible under Traffic Logs when the traffic was denied by an authentication rule and the session was discarded.
|
||||
Fixed an issue where non-captive portal traffic was not visible under **Traffic Logs** when the traffic was denied by an authentication rule and the session was discarded.
|
||||
|
||||
## PAN-272726
|
||||
|
||||
Fixed an issue on the web interface where the URL Filtering change category feature did not work.
|
||||
Fixed an issue on the web interface where the **URL Filtering** change category feature did not work.
|
||||
|
||||
## PAN-272505
|
||||
|
||||
@@ -1170,7 +1170,7 @@ Fixed an issue where GlobalProtect cookie authentication failed with the error U
|
||||
|
||||
## PAN-272469
|
||||
|
||||
Fixed an issue where the DNS exception displayed 0 instead of no result in the anti-spyware profile when no threat ID was available for a DNS Security category.
|
||||
Fixed an issue where the DNS exception displayed **0** instead of **no result** in the anti-spyware profile when no threat ID was available for a DNS Security category.
|
||||
|
||||
## PAN-272408
|
||||
|
||||
@@ -1222,7 +1222,7 @@ A CLI counter was added to indicate a full suppression queue.
|
||||
|
||||
## PAN-271412
|
||||
|
||||
Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as #43; on the GlobalProtect client after upgrading to a PAN-OS 10.2 release.
|
||||
Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as **#43;** on the GlobalProtect client after upgrading to a PAN-OS 10.2 release.
|
||||
|
||||
## PAN-271301
|
||||
|
||||
@@ -1242,7 +1242,7 @@ Fixed an issue where the firewall displayed an incorrect maximum translated IP c
|
||||
|
||||
## PAN-271061
|
||||
|
||||
Fixed an issue on the web interface where you were unable to add Threat IDs to Signature Exceptions.
|
||||
Fixed an issue on the web interface where you were unable to add Threat IDs to **Signature Exceptions**.
|
||||
|
||||
## PAN-270747
|
||||
|
||||
@@ -1266,11 +1266,11 @@ Fixed an issue threat reports were empty when generated from Panorama, but displ
|
||||
|
||||
## PAN-269843
|
||||
|
||||
Fixed an issue where the firewall dropped non-SYN TCP packets even when the Reject non-SYN TCP option was set to No when a session rematch was triggered.
|
||||
Fixed an issue where the firewall dropped non-SYN TCP packets even when the **Reject non-SYN TCP** option was set to **No** when a session rematch was triggered.
|
||||
|
||||
## PAN-269716
|
||||
|
||||
Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option toTrue.
|
||||
Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option to True.
|
||||
|
||||
## PAN-269659
|
||||
|
||||
@@ -1310,7 +1310,7 @@ Fixed an issue where the aggressive clean-up threshold for disk space was set to
|
||||
|
||||
## PAN-269176
|
||||
|
||||
Fixed an issue where the domain-edl column was empty in the threat log even when a threat was detected as a DNS alert.
|
||||
Fixed an issue where the **domain-edl** column was empty in the threat log even when a threat was detected as a DNS alert.
|
||||
|
||||
## PAN-269155
|
||||
|
||||
@@ -1342,7 +1342,7 @@ Fixed an issue where the configd process stopped responding when a configuration
|
||||
|
||||
## PAN-268606
|
||||
|
||||
Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking connect or login.
|
||||
Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking **connect** or **login**.
|
||||
|
||||
## PAN-268597
|
||||
|
||||
@@ -1354,7 +1354,7 @@ Fixed an issue where the web interface was slower than expected when logging in
|
||||
|
||||
## PAN-268522
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4.
|
||||
|
||||
## PAN-268426
|
||||
|
||||
@@ -1376,11 +1376,9 @@ Fixed an issue where importing a device configuration into Panorama failed with
|
||||
|
||||
To use this fix:
|
||||
|
||||
Enable the configuration. Commit failures may occur if the device is not able to support the number of objects.
|
||||
|
||||
Export and push the device group only.
|
||||
|
||||
Push the template.
|
||||
1. Enable the configuration. Commit failures may occur if the device is not able to support the number of objects.
|
||||
2. Export and push the device group only.
|
||||
3. Push the template.
|
||||
|
||||
Note: This fix is supported on PAN-OS 10.2 and later releases.
|
||||
|
||||
@@ -1390,7 +1388,7 @@ Fixed an issue where commits failed with a validation error when you changed the
|
||||
|
||||
## PAN-267912
|
||||
|
||||
Fixed an issue on the Panorama web interface where Application and Category was not able to be selected under Test Policy Match.
|
||||
Fixed an issue on the Panorama web interface where **Application** and **Category** was not able to be selected under **Test Policy Match**.
|
||||
|
||||
## PAN-267830
|
||||
|
||||
@@ -1406,7 +1404,7 @@ Fixed an issue where the Panorama web interface was slower than expected due to
|
||||
Firewalls in HA configuration only
|
||||
```
|
||||
|
||||
Fixed an issue where the Network pre-negotiation enabled page did not display on the firewall dashboard.
|
||||
Fixed an issue where the **Network pre-negotiation enabled** page did not display on the firewall dashboard.
|
||||
|
||||
## PAN-267381
|
||||
|
||||
@@ -1426,7 +1424,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where BGP route refreshes occurred when a commit was performed if AS Set was enabled for BGP aggregate routes.
|
||||
Fixed an issue where BGP route refreshes occurred when a commit was performed if **AS Set** was enabled for BGP aggregate routes.
|
||||
|
||||
## PAN-267045
|
||||
|
||||
@@ -1438,7 +1436,7 @@ Fixed an issue where the firewall generated AAAA DNS queries when IPv6 firewalli
|
||||
|
||||
## PAN-266905
|
||||
|
||||
Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a no-decrypt policy.
|
||||
Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a **no-decrypt** policy.
|
||||
|
||||
## PAN-266698
|
||||
|
||||
@@ -1506,7 +1504,7 @@ Fixed an issue where the routed process core failed the automation run.
|
||||
|
||||
## PAN-264040
|
||||
|
||||
Fixed an issue where AAAA DNS queries went out even when IPv6 firewalling was disabled.
|
||||
Fixed an issue where AAAA DNS queries went out even when **IPv6 firewalling** was disabled.
|
||||
|
||||
## PAN-263699
|
||||
|
||||
@@ -1558,7 +1556,7 @@ Fixed an issue where Voice over WiFi (VoWiFi) stopped working after switching fr
|
||||
|
||||
## PAN-261936
|
||||
|
||||
Fixed an issue where WildFire submission logs were not displayed when filtered by Sender Address.
|
||||
Fixed an issue where WildFire submission logs were not displayed when filtered by **Sender Address**.
|
||||
|
||||
## PAN-261602
|
||||
|
||||
@@ -1566,7 +1564,7 @@ Fixed an issue where GlobalProtect Decryption logs were not forwarded to Panoram
|
||||
|
||||
## PAN-260879
|
||||
|
||||
Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the Secure Communication Settings.
|
||||
Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the **Secure Communication Settings**.
|
||||
|
||||
## PAN-260790
|
||||
|
||||
@@ -1582,7 +1580,7 @@ Fixed an issue where daily email reports generated from the custom report did no
|
||||
|
||||
## PAN-260581
|
||||
|
||||
Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to None.
|
||||
Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to **None**.
|
||||
|
||||
## PAN-260540
|
||||
|
||||
@@ -1606,7 +1604,7 @@ Fixed an issue where the firewall dropped GRE keepalive packets that were encaps
|
||||
|
||||
## PAN-259343
|
||||
|
||||
Fixed an issue on the Panorama web interface where the Configuration tab did not accurately display changes made to URL filtering profiles.
|
||||
Fixed an issue on the Panorama web interface where the **Configuration** tab did not accurately display changes made to URL filtering profiles.
|
||||
|
||||
## PAN-259284
|
||||
|
||||
@@ -1638,7 +1636,7 @@ Fixed an issue where the firewall dataplane stopped responding, which caused BGP
|
||||
|
||||
## PAN-257616
|
||||
|
||||
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
||||
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message **Failed to generate selective push configuration. Schema validation failed. Please try a full push**.
|
||||
|
||||
## PAN-257362
|
||||
|
||||
@@ -1654,11 +1652,11 @@ Fixed an issue where the mp-monitor logs did not print disk SMART data.
|
||||
|
||||
## PAN-257074
|
||||
|
||||
Fixed an issue on the Panorama web interface where the template sync status showed Out-of-Sync for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum.
|
||||
Fixed an issue on the Panorama web interface where the template sync status showed **Out-of-Sync** for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum.
|
||||
|
||||
## PAN-256560
|
||||
|
||||
Fixed an issue where exporting a Custom Report to CSV format did not display the full report if it contained non-ASCII characters.
|
||||
Fixed an issue where exporting a **Custom Report** to CSV format did not display the full report if it contained non-ASCII characters.
|
||||
|
||||
## PAN-256552
|
||||
|
||||
@@ -1746,7 +1744,7 @@ Fixed an issue where the class of service (CoS) priority bit was not modified, c
|
||||
|
||||
## PAN-252706
|
||||
|
||||
Fixed an issue where the URL filtering response page for Continue and Override did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
|
||||
Fixed an issue where the URL filtering response page for **Continue** and **Override** did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
|
||||
|
||||
## PAN-252699
|
||||
|
||||
@@ -1786,17 +1784,17 @@ Fixed an issue on the Panorama web interface where you were unable to add static
|
||||
|
||||
## PAN-242777
|
||||
|
||||
Fixed and issue where users previously reported limitations due to session count caps when utilizing Web Proxy features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific PA-5400F series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
|
||||
Fixed and issue where users previously reported limitations due to session count caps when utilizing **Web Proxy** features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific **PA-5400F** series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
|
||||
|
||||
The supported session limits are:
|
||||
|
||||
| Platform | Max Sessions |
|
||||
| --- | --- |
|
||||
| PA-5410 | 95K |
|
||||
| PA-5420 | 95K |
|
||||
| PA-5430 | 95K |
|
||||
| PA-5440 | 225K |
|
||||
| PA-5445 | 250K |
|
||||
| -------- | ------------ |
|
||||
| PA-5410 | 95K |
|
||||
| PA-5420 | 95K |
|
||||
| PA-5430 | 95K |
|
||||
| PA-5440 | 225K |
|
||||
| PA-5445 | 250K |
|
||||
|
||||
## PAN-241953
|
||||
|
||||
@@ -1812,7 +1810,7 @@ Fixed an issue where the SNMP get request status value for Panorama connections
|
||||
|
||||
## PAN-238208
|
||||
|
||||
Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error Session is invalid if the session is not available for the cookie.
|
||||
Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error **Session is invalid** if the session is not available for the cookie.
|
||||
|
||||
## PAN-234993
|
||||
|
||||
|
||||
Reference in New Issue
Block a user