diff --git a/reference/PAN-OS/addressed/11.2.0-h1.html b/reference/PAN-OS/addressed/11.2.0-h1.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.0-h1.html @@ -0,0 +1,61 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PLUG-16383
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the PAN_NET_FILE_TMP was not
+ found after an upgrade, which caused the firewall to enter maintenance
+ mode.
+
+ |
+
|
+ PAN-240174
+ |
+
+
+ Fixed an issue where, when LSVPN serial numbers and IP address
+ authentication were enabled, IPv6 address ranges and complete IPv6
+ addresses that were manually added to the IP address allow or exclude
+ list were not usable after a restart of the
+ gp_broker
+ process or the firewall.
+
+ |
+
|
+ PAN-230362
+ |
+
+
+ Fixed an issue where the firewall truncated the payload of a TCP Out
+ of Order segment with a FIN flag.
+
+ |
+
|
+ PAN-228386
+ |
+
+
+ Fixed an issue with session caching where the
+ reportd
+ process stopped responding due to null values.
+
+ |
+
|
+ PAN-227344
+ |
+
+
+ Fixed an issue on Panorama where
+ PDF Summary Reports (Monitor > PDF Reports > Manage PDF Summary) displayed no data and were blank when predefined widgets were
+ included in the summary report.
+
+ |
+
|
+ PAN-227305
+ |
+
+
+ Fixed an issue where SCEP certificate generation failed when a service
+ route was used to reach the SCEP server.
+
+ |
+
|
+ PAN-227224
+ |
+
+
+ (PA-1400 Series firewalls) Fixed an issue where
+ the firewall was unable to handle GRE packets for Point-to-Point
+ Tunneling Protocol (PPTP) connections.
+
+ |
+
|
+ PAN-226626
+ |
+
+
+ Fixed an issue where the firewall generated numerous
+ logrcvr
+ error messages related to netflow.
+
+ |
+
|
+ PAN-225394
+ |
+
+
+ Fixed an issue on the firewall where SNMP incorrectly reported high
+ packet descriptor usage.
+
+ |
+
|
+ PAN-225240
+ |
+
+
+ Fixed an issue where the OSPF neighbor state remained in
+ exstart when the OSPF network had
+ more than 40 routes.
+
+ |
+
|
+ PAN-225183
+ |
+
+
+ Fixed an issue where SSH tunnels were unstable due to ciphers used as
+ part of the high availability SSH configuration.
+
+ |
+
|
+ PAN-224772
+ |
+
+
+ Fixed a high memory usage issue with the
+ mongodb
+ process that caused an OOM condition.
+
+ |
+
|
+ PAN-224365
+ |
+
+
+ Fixed an issue where excessive network path monitoring messages were
+ generated in the system logs.
+
+ |
+
|
+ PAN-224067
+ |
+
+
+ Fixed an issue where cookie authentication did not work for
+ GlobalProtect when an authentication override domain was configured in
+ the SAML authentication profile.
+
+ |
+
|
+ PAN-223501
+ |
+
+
+ Fixed an issue where diagnostic information for the dataplane in the
+ dp-monitor.log file was not complete.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ Fixed an issue where Panorama was unbale to query any logs if the
+ Elasticsearch health status for any log collector was degraded.
+
+ |
+
|
+ PAN-220881
+ |
+
+
+ Fixed an issue where the CLI command
+ show logging-status did not
+ correctly display the last log created and forwarded timestamps.
+
+ |
+
|
+ PAN-220640
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ the firewall CPU percentage was miscalculated, and the values that
+ were displayed were incorrect.
+
+ |
+
|
+ PAN-219768
+ |
+
+
+ Fixed an issue where you were unable to filter Data Filtering logs
+ with Threat ID/NAME for custom data
+ patterns created over Panorama.
+
+ |
+
|
+ PAN-219585
+ |
+
+
+ Fixed an issue where enabling
+ syslog-ng debugs from the root
+ caused 100% disk utilization.
+
+ |
+
|
+ PAN-217510
+ |
+
+
+ Fixed an issue where inbound DHCP packets received by a DHCP client
+ interface that were not addressed to itself were silently dropped
+ instead of forwarded.
+
+ |
+
|
+ PAN-208567
+ |
+
+
+ Fixed an issue with email formatting where, when a scheduled email
+ contained two or more attachments, only one attachment was visible.
+
+ |
+
|
+ PAN-207003
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process netflow buffer was not reset which resulted in duplicate
+ netflow records.
+
+ |
+
|
+ PAN-202095
+ |
+
+
+ Fixed an issue on the web interface where the language setting is not
+ retained.
+
+ |
+
|
+ PLUG-16385
+ |
+
+
+ Fixed an issue where the file
+ PAN_NET_FILE_TMP was missing after the
+ upgrade causing the VM-Series firewall to go into maintenance mode.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-257919
+ |
+
+
+ Fixed an issue where, when using explicit proxy with SAML
+ authentication, initiating SAML authentication with a non-GET request
+ resulted in a 302 redirect response
+ instead of the expected
+ 200 ok response.
+
+ |
+
|
+ PAN-256343
+ |
+
+
+ Fixed an issue where, when Advanced Routing Engine was enabled and
+ OSPFv3 was configured, the CLI command
+ show advanced-routing ospf interface
+ caused traffic to be disrupted, and the interface and area information
+ did not display in CLI or the web interface.
+
+ |
+
|
+ PAN-255868
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall entered maintenance mode after enabling kernel data
+ collection during the silent reboot.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ Fixed an issue where changes to the gp-ip-mgmt service route did not
+ take effect after a commit.
+
+ |
+
|
+ PAN-255227
+ |
+
+
+ Fixed an issue where the the MAC address was sent to the DHCP server
+ instead of the hostname on macOS endpoints.
+
+ |
+
|
+ PAN-254236
+ |
+
+
+ Fixed an issue where Client Hello packets were dropped when SSL/TLS
+ handshake inspection was enabled.
+
+ |
+
|
+ PAN-249292
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where CPU usage was higher than expected after a
+ hotplug event when Accelerated Networking was enabled for the
+ management interface.
+
+ |
+
|
+ PAN-236909
+ |
+
+
+ Fixed an issue where, when you committed the first configuration
+ change after booting up the firewall, the external dynamic list file
+ download failed until the list was refreshed. This occurred when the
+ configuration was pushed with a certificate profile.
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ Fixed an issue on Panorama where
+ Commit and Push or
+ Push to Devices operations failed
+ when an external dynamic list was configured to check for updates
+ every 5 minutes due to the commit and external dynamic fetch processes
+ overlapping.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-306534
+ |
+
+
+ Fixed an issue were the
+ all_task
+ process repeatedly restarted due to memory pool corruption when
+ processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred
+ due to incorrect buffer length calculations during memory deallocation
+ when the query name field spanned multiple packets.
+
+ |
+
|
+ PAN-305480
+ |
+
+
+ Fixed an issue where the
+ pan_task
+ process stopped responding while processing DoH JSON format traffic
+ with DoH Security enabled, which caused missing cross-packet bytes in
+ the decoded DNS query type field, and the dataplane went down.
+
+ |
+
|
+ PAN-305301
+ |
+
+
+ Fixed an issue where GlobalProtect notifications in tunnels caused
+ processes to stop responding and the dataplane to restart due to the
+ session lookup returning an incorrect session, which resulted in the
+ data being sent through the wrong tunnel.
+
+ |
+
|
+ PAN-303836
+ |
+
+
+ Fixed an issue where the AIRS VM on session table reset intermittently
+ dropped packets, which resulted in packet loss on responses to egress
+ traffic.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-306306
+ |
+
+
+ (Panorama appliances in FIPS-CC mode only)
+ Fixed interdevice TLS communication failures that occurred with RSA
+ and RSA-PSS signature algorithms across multiple layer 7 application
+ services.
+
+ |
+
|
+ PAN-303051
+ |
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the
+ reportd
+ process due to retaining memory that was temporarily used for report
+ generation instead of releasing the memory for reuse, which resulted
+ in continuous accumulation and memory exhaustion.
+
+ |
+
|
+ PAN-302927
+ |
+
+
+ Fixed an issue where, after upgrading Panorama, the
+ Push to Devices option did not
+ display selected devices, and the
+ OK and
+ Cancel
+ buttons did not function as expected. Selecting
+ OK did not close the window, and
+ selecting Cancel returned to the
+ main push screen with the push selected devices displaying as empty.
+ Despite this, selecting Push or
+ Validate Device Group Push still
+ pushed to the previously canceled, non-displayed devices.
+
+ |
+
|
+ PAN-301801
+ |
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process
+ fluctuated intermittently between green and red states, which led to
+ interruptions in log collection. This issue occurred when the number
+ of shards exceeded the cluster's maximum supported threshold of
+ greater than 1000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-301691
+ |
+
+
+ Fixed an issue where BGP stopped responding with the error message
+ Too many open files when pushing
+ 1000 eBGP (External BGP) neighbor configurations. With this fix, the
+ number of file descriptors for the BGP process is increased from 1024
+ to 8192.
+
+ |
+
|
+ PAN-301456
+ |
+
+
+ Fixed an issue on Panorama where the
+ debug system reset-ztp CLI
+ command was unavailable.
+
+ |
+
|
+ PAN-300216
+ |
+
+
+ Fixed an issue where, when SD-WAN Direct Internet Access was
+ configured and traffic traversed the cellular interface without a NAT
+ policy rule, intermittent cellular modem connectivity issues occurred,
+ which caused the firewall to disconnect and reconnect to the cellular
+ network.
+
+
+ To use this fix, run the CLI command
+ set session teardown-upon-fwd-zonechange yes.
+
+ |
+
|
+ PAN-300138
+ |
+
+
+ Fixed an issue where DNS queries stalled or repeatedly time out due to
+ multiple DNS responses with different CNAME values causing evasion
+ false positive alerts.
+
+ |
+
|
+ PAN-299815
+ |
+
+
+ Fixed an issue on multi-vsys firewalls where a host was not removed
+ from the quarantine list after receiving a redistribution message from
+ Panorama. This occurred when Panorama was configured to redistribute
+ quarantine messages to a firewall cluster, and the GlobalProtect
+ configuration and redistribution were built out in a vsys other than
+ vsys1.
+
+ |
+
|
+ PAN-298387
+ |
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP
+ addresses did not display in traffic and threat logs.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade
+ due to the
+ fsck
+ command scanning drive partitions in parallel with the root partition,
+ which caused the process to take an extended amount of time.
+
+ |
+
|
+ PAN-297005
+ |
+
+
+ Fixed an issue where exporting custom reports resulted in empty CSV
+ files.
+
+ |
+
|
+ PAN-296977
+ |
+
+
+ Fixed an issue where the web interface became unresponsive when
+ attempting to view
+ Ethernet interface details after
+ applying a filter in
+
+
+ |
+
|
+ PAN-296694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to the
+ useridd
+ process repeatedly restarting during an IP-port data type writes to
+ the redis from multiple sources such as TSA or XML in a scale
+ environment.
+
+ |
+
|
+ PAN-296535
+ |
+
+
+ Fixed an issue on the firewall where BGP peers disconnected when more
+ than 500 BGP neighbors were configured in a single Logical Router
+
+ |
+
|
+ PAN-295899
+ |
+
+
+ Fixed an issue where DNS resolution failed on Linux machines running
+ GlobalProtect client version 6.2.6 when connected with DNS Security
+ enabled. This occurred because the firewall incorrectly discarded DNS
+ packets when processing multiple DNS requests or responses over the
+ same session, even when no malicious verdict was received.
+
+ |
+
|
+ PAN-276525
+ |
+
+
+ Resolved multiple issues affecting IPSec tunnels using NAT Traversal
+ (NAT-T) when a Dynamic NAT policy was configured (including Dynamic
+ NAT or DIPP). During rekey events, tunnels could go down or flap due
+ to incorrect session handling. This issue impacted both cluster and
+ standalone deployments.
+
+ |
+
|
+ PAN-209516
+ |
+
+
+ Fixed an issue where, when creating an interface, an error occurred
+ when you clicked OK without
+ providing a value in the Tag field
+ even though the field was not displayed as mandatory.
+
+ |
+
|
+ PAN-185731
+ |
+
+
+ Fixed an issue where the firewall was unable to parse the URL path and
+ host when the host header was located in a different packet, which
+ resulted in the firewall not logging the URL path in the first packet.
+
+
+ The fix is disabled by default. The following CLI commands can be used
+ to enable/disable the feature: set system setting ctd
+ url-crosspkt-host-path-caching enable set system setting ctd
+ url-crosspkt-host-path-caching disable set system setting ctd
+ url-crosspkt-host-path-caching default
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-307901
+ |
+
+
+ Fixed an issue where a leak in decryption counters caused resource
+ exhaustion, which led to a GlobalProtect service outage.
+
+ |
+
|
+ PAN-307702
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where traffic passing through AE layer 2 interfaces was
+ interrupted during HA failovers.
+
+ |
+
|
+ PAN-306451
+ |
+
+
+ (VM-Series firewalls on AWS environments only)
+ Fixed an issue where, after upgrading the firewall to an affected
+ release, GlobalProtect clients did not connect with IPSec and instead
+ connected using SSL due to traffic flow being disabled when checking
+ for health check packets.
+
+ |
+
|
+ PAN-306103
+ |
+
+
+ (PA-3400 and PA-5400 Series firewalls only)
+ Fixed an issue where the firewall dataplane frequently restarted when
+ lockless QoS was enabled
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Fixed an issue where traffic was incorrectly identified as
+ unknown-tcp/unknown-udp due to App-ID resource leak and eventually
+ dropped.
+
+ |
+
|
+ PAN-301409
+ |
+
+
+ Fixed an issue where Panorama failed to perform a selective push to a
+ managed device when device tags were added or modified on the policy
+ rules. The selective push failed with the error message
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+
|
+ PAN-301222
+ |
+
+
+ Fixed an issue where DNS Security logs incorrectly displayed a
+ sinkhole action for benign DNS categories due to the firewall saving
+ the drop or sinkhole action in session flags without discarding the
+ session.
+
+ |
+
|
+ PAN-300638
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall stopped responding due to an out-of-bounds read when
+ parsing TLS 1.3 clientHello messages with large TLS clientHello
+ extensions where the
+ supported_versions extension fell
+ outside the first TCP segment.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ Addressed a memory leak issue under sc3 and automatic commit recovery
+ (ACR) code path.
+
+ |
+
|
+ PAN-289723
+ |
+
+
+ Fixed an issue where the firewall web interface continuously loaded
+ and not display any output when viewing the Route Table or FIB table
+ (More Runtime Stats). This issue
+ occurred when L3 configurations were added to ethernet and AE
+ interfaces.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308902
+ |
+
+
+ Fixed an issue where, after upgrading to an affected release, the
+ firewall did not add mTLS websites that required client certificate
+ authentication via DN list to the ssl-decrypt exclude-cache list.
+
+ |
+
|
+ PAN-308654
+ |
+
+
+ Fixed an issue where the Elasticsearch Close Indices process closed
+ more indices than expected and dropped the number of open shards below
+ the minimum of 800 per Elasticsearch instance. This occurred because
+ the process did not correctly account for the number of Elasticsearch
+ instances when calculating the maximum number of allowed open shards.
+
+ |
+
|
+ PAN-304718
+ |
+
+
+ Fixed an issue where OSPF and BGP outages occurred due to an
+ all_task
+ process restart during clientless VPN content rewrite processing.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Fixed an issue where the firewall entered a non-functional state due
+ to segmentation fault within the
+ all_pktproc
+ process that was caused by a session that involved http2 cleartext
+ traffic
+
+ |
+
|
+ PAN-304496
+ |
+
+
+ Fixed an issue where, after unregistering an IP tag and registering a
+ different IP tag for the same IP address via XML API, the dynamic
+ address group membership was not updated on the dataplane, which
+ resulted in Security policy rules being enforced incorrectly.
+
+ |
+
|
+ PAN-303722
+ |
+
+
+ Fixed an issue on the firewall where configuring spyware and
+ vulnerability profiles in Security policy rules caused a memory leak
+ in the
+ devsrvr
+ process with each configuration commit.
+
+ |
+
|
+ PAN-302790
+ |
+
+
+ Fixed an issue where, with Sender Side Loop Detection enabled, BGP
+ WITHDRAWAL updates were not sent to peers after a route was removed,
+ which caused stale routes to persist in the BGP table of neighboring
+ firewalls.
+
+ |
+
|
+ PAN-288001
+ |
+
+
+ Fixed an issue where devices with 5G cellular modems did not support
+ the ATT FirstNet auto Access Point Name (APN).
+
+ |
+
|
+ PAN-285181
+ |
+
+
+ Fixed an issue where the wifclient ran out of memory when Enhanced
+ Application Logging was enabled and a sudden traffic increase caused a
+ surge in EAL messages sent through WIF.
+
+
+ To use this fix, run the CLI command
+ debug iot eal memory-gc native
+
+ |
+
|
+ PAN-278688
+ |
+
+
+ Fixed an issue where DNS Security threat logs were not displayed on
+ the firewall when packet capture was enabled and the domain name
+ length was 62 characters.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where an incorrect ASIC configuration caused silent packet drops or
+ application slowness when receiving a mix of jumbo and non-jumbo
+ packets.
+
+ |
+
|
+ PAN-269228
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused a split brain condition.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-318275
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall became unresponsive and did not automatically reboot,
+ which led to prolonged outages. With this fix, the Linux kernel
+ configuration will trigger a system panic and reboot.
+
+ |
+
|
+ PAN-316911
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-315912
+ |
+
+
+ Fixed an issue where the Maximum Segment Size (MSS) rewrite
+ functionality for packets ingressing through SD-WAN interfaces on
+ firewalls was not optimized.
+
+ |
+
|
+ PAN-314147
+ |
+
+
+ Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces
+ with member having different MTU.
+
+ |
+
|
+ PAN-313623
+ |
+
+
+ Fixed an issue where the
+ /opt/pancfg/mgmt/ssl/private/
+ directory on Palo Alto Networks devices with TPM support became 100%
+ utilized due to an accumulation of undeleted
+ .pub_pem files. This occurred
+ because executing the
+ show device-certificate status
+ CLI command initiated a process that generated these files but failed
+ to remove them, which prevented the fetching of new device
+ certificates.
+
+ |
+
|
+ PAN-313216
+ |
+
+
+ Fixed an issue where firewalls with Prisma Access incorrectly
+ displayed some traffic as unsanctioned in traffic logs for cloud
+ applications that were tagged as
+ sanctioned.
+
+ |
+
|
+ PAN-312706
+ |
+
+
+ Fixed an issue where the firewalls restarted due to a function lacking
+ a NULL-pointer sanity check.
+
+ |
+
|
+ PAN-311512
+ |
+
+
+ Fixed an issue where HIP (Host Information Profile) reports were
+ blocked on GlobalProtect when
+ Authentication Cookie Usage Restrictions
+ was enabled and the Prisma Access Agent protocol was in use. This
+ occurred because the system failed to correctly process HIP messages
+ that were relayed via IPSec tunnels with a Virtual IP as the source,
+ leading to their rejection.
+
+ |
+
|
+ PAN-309300
+ |
+
+
+ Fixed an issue where management plane system resources configuration
+ size exceeded 28 MB for over 4 hours, and the following error message
+ was displayed:
+ Configuration size reaching device capacity limit.
+
+ |
+
|
+ PAN-308786
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ traffic log queries using the
+ device_name filter returned no
+ results, and complex log queries that included negation operators
+ produced incorrect outputs.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Fixed an issue where packets were dropped on SD-WAN interfaces when a
+ proxy was enabled due to an MTU inconsistency where the firewall
+ failed to rewrite the maximum segment size in SYN/ACK packets based on
+ the SD-WAN virtual interface MTU.
+
+
+ Note: This fix does not apply when the traffic
+ egress interface is SD-WAN Direct Internet Access (DIA) interface
+ and proxy is enabled.
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ (Panorama managed firewalls only) Fixed an
+ issue where the firewall intermittently failed to maintain active log
+ forwarding streams to Strata Logging Service (SLS) even when duplicate
+ logging and enhanced application logging were enabled.
+
+ |
+
|
+ PAN-308418
+ |
+
+
+ Fixed an issue where, when Advanced DNS Security was enabled and
+ experienced unusually high loads, DNS resolution failures occurred
+ with the error
+ resources-unavailable.
+
+ |
+
|
+ PAN-306555
+ |
+
+
+ Fixed an issue where the firewall stopped responding, which led to
+ service outages.
+
+ |
+
|
+ PAN-304019
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall did not send traffic to SCM or SLS via a configured
+ explicit proxy IP address when the proxy username was not configured.
+
+ |
+
|
+ PAN-303745
+ |
+
+
+ Fixed an issue where inter-dataplane forwarding did not work for
+ sessions ingressing on Slot 2, which resulted in intermittent ping
+ failures to interfaces on Network Card 2 when traffic was forwarded to
+ Slot 3.
+
+
+ Note: With this fix, after a slot restart, the
+ global counter will still show dot1q errors for a short period.
+
+ |
+
|
+ PAN-302564
+ |
+
+
+ Fixed an issue on the firewall where a path monitoring failure
+ occurred and caused the dataplane to restart.
+
+ |
+
|
+ PAN-301653
+ |
+
+
+ Fixed an issue where DNS traffic sessions prematurely terminated with
+ the message
+ resources-unavailable. This occurred due to IPv4 fragmented DNS responses causing the
+ Advanced DNS Security module to incorrectly pack the DNS payload
+ multiple times when forwarding to the cloud for inspection.
+
+ |
+
|
+ PAN-302983
+ |
+
+
+ Fixed an issue where, after committing changes on Panorama, a shared
+ post-rule moved to the end of the
+ post shared rulebase on the
+ managed device instead of remaining at the top.
+
+ |
+
|
+ PAN-300837
+ |
+
+
+ Fixed an issue where firewalls experienced multiple reboots due to the
+ pan_task
+ process restarting with a SIGSEGV signal. This occurred because the
+ client-to-firewall side assumed TLS 1.3 for the firewall-server side.
+
+ |
+
|
+ PAN-300671
+ |
+
+
+ Fixed an issue where traffic reports that were generated with
+ destination/source and destination/source hostnames were not displayed
+ in IPv4 format.
+
+ |
+
|
+ PAN-300423
+ |
+
+
+ Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
+ and 6 remained stuck in a starting state with the error
+ Signal detected for port xeS5-DP0 but Link Down
+ alerts, which resulted in device instability.
+
+ |
+
|
+ PAN-299242
+ |
+
+
+ Fixed an issue where the firewall's SSL proxy sent an empty HTTP2
+ SETTINGS message to the client before confirming server support, which
+ caused some clients to incorrectly assume HTTP/2 support and not fall
+ back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad
+ Request frames from the server, which prevented the client from
+ correctly detecting the lack of HTTP/2 support.
+
+ |
+
|
+ PAN-298617
+ |
+
+
+ Optimized the commit workflow to reduce the size of the effective
+ configuration, resulting in lower memory consumption.
+
+ |
+
|
+ PAN-297708
+ |
+
+
+ Fixed an issue where a long-lived session with many Machine Learning
+ (ML) model triggers caused a memory leak of feature states associated
+ with the ML model runs. This resulted in Spyware_State failure
+ increases, allocation max outs, and impaired policy matching.
+
+ |
+
|
+ PAN-295802
+ |
+
+
+ Fixed an issue where a memory leak related to the
+ configd
+ process occurred.
+
+ |
+
|
+ PAN-295309
+ |
+
+
+ Fixed an issue where OSPF session using MD5 authentication experienced
+ intermittent flapping due to out-of-order packet processing.
+
+ |
+
|
+ PAN-293644
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the
+ configd
+ process stopped responding during an External Dynamic List (EDL)
+ refresh.
+
+ |
+
|
+ PAN-290938
+ |
+
+
+ Fixed an issue where multiple memory leaks occurred related to the
+ configd
+ process.
+
+ |
+
|
+ PAN-264762
+ |
+
+
+ Fixed an issue where the firewall showed the status of SFP+ interfaces
+ as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
+ connected.
+
+ |
+
|
+ PAN-263691
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a
+ memory leak in the
+ all_task
+ process.
+
+ |
+
|
+ PAN-250339
+ |
+
+
+ Added an improvement to automatically clean up idle HTTP connection
+ pools to address an issue where idle connection pools accumulated when
+ a circuit breaker limit was reached, which caused client requests to
+ fail with a 503
+ no_healthy_upstream error.
+
+ |
+
|
+ PAN-248913
+ |
+
+
+ Fixed an issue where the Elasticsearch client certificate was not auto
+ renewed, which caused it to enter a Red state, and logs were not
+ displayed in Panorama.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-304088
+ |
+
+
+ Fixed an issue where TCP traffic stopped working from Prisma Access
+ clients to TCP services behind the Service Connection (SC) after a
+ dataplane upgrade.
+
+ |
+
|
+ PAN-304075
+ |
+
+
+ Fixed an issue where the firewall did not detect evasions due to TCP
+ checksum offloading not being enabled.
+
+ |
+
|
+ PAN-303737
+ |
+
+
+ Fixed an issue where XML API commands failed with a
+ Method not found (policy_xml)
+ error in dagger.log. The issue was due to session-distribution
+ commands in dagger files handling.
+
+ |
+
|
+ PAN-303559
+ |
+
+
+ Fixed an issue where, after manuallly creating a device telemetry
+ bundle, the
+ hour_cli_output.txt file within
+ the bundle had a file size of 0 bytes. This occurred when checking the
+ bundle content after enabling device telemetry and setting the device
+ telemetry upload endpoint.
+
+ |
+
|
+ PAN-301828
+ |
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud
+ Manager and configured to use a proxy server for external connections,
+ the management server did not use the configured settings to connect
+ to the Cloud Management service.
+
+ |
+
|
+ PAN-300906
+ |
+
+
+ Fixed an issue where XML API commands failed with a
+ Method not found (policy_xml)
+ error in dagger.log. The issue was due to missing XML-related
+ functions for inline-cloud-proxy.
+
+ |
+
|
+ PAN-300096
+ |
+
+
+ Fixed an issue where a local commit on a firewall breaks template
+ stack overrides, preventing the enabling of LACP (Link Aggregation
+ Control Protocol). After a local commit, the LACP enable check was
+ unexpectedly unchecked, causing an outage. Attempting to re-enable
+ LACP through the web interface was unsuccessful, requiring manual
+ removal of the LACP configuration from the Panorama CLI.
+
+ |
+
|
+ PAN-299785
+ |
+
+
+ (PA-7500 and PA-5450 firewalls in FIPS-CC mode)
+ Fixed an issue where the affected firewalls would boot into
+ maintenance mode when a reboot was initiated from the web interface.
+ This was due to a device reboot triggering a power down to all slots,
+ leading to maintenance mode. A hard reboot would allow the firewall to
+ boot normally.
+
+ |
+
|
+ PAN-299772
+ |
+
+
+ (VM-Series firewalls in active/passive configurations only) Fixed an issue where, after an HA failover event, the newly active
+ firewall DHCP client interfaces failed to obtain IP addresses
+ automatically. This occurred because the DHCP client processes did not
+ initiate the necessary DHCP discover or renew requests
+
+ |
+
|
+ PAN-298872
+ |
+
+
+ (PA-400 Series firewalls in HA configurations only) Fixed an issue where ports went down after an HA failover.
+
+ |
+
|
+ PAN-298684
+ |
+
+
+ Fixed an issue where an Application Override policy rule was not
+ applied using an IPv4 source IP address with IPv6 enabled and
+ Network >
+ Zones >
+ Pre-NAT Identification enabled.
+
+ |
+
|
+ PAN-298654
+ |
+
+
+ Fixed an issue where the firewall generated false positive threat logs
+ during updates to a large domain list (EDL) when a DNS lookup for a
+ domain being added or removed occurred during the update process. This
+ resulted in a threat log being generated for a different, unrelated
+ domain that remained on the list.
+
+ |
+
|
+ PAN-298505
+ |
+
+
+ Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
+ the vsys ID changed in sequence, causing autocommit failures with
+ validation errors. This occurred when the multi-vsys firewall had
+ virtual systems created and pushed from Panorama, and the vsys ID was
+ not in a correct sequence because the unused vsys was deleted from
+ Panorama and pushed to devices.
+
+ |
+
|
+ PAN-298252
+ |
+
+
+ Fixed an issue where Data Loss Prevention (DLP) inspection of chunked
+ transfer encoding over TLS resulted in incomplete file downloads on
+ Outlook Web App (OWA) due to the WIF page size limit, which led to
+ corrupted or incomplete PDF attachments.
+
+ |
+
|
+ PAN-298241
+ |
+
+
+ Fixed an issue where the NAT IP address pool was exhausted, which led
+ to intermittent connectivity issues with call applications and
+ outbound call failures. This occurred due to the firewall not properly
+ releasing NAT dynamic ports back to the address pool.
+
+ |
+
|
+ PAN-297976
+ |
+
+
+ Fixed an issue where the firewall experienced extended boot times
+ after a reboot due to the
+ configd
+ process needing to rebuild the ACE catalog after detecting
+ discrepancies that were caused by duplicate application checking
+ between the ACE catalog and content.
+
+ |
+
|
+ PAN-297975
+ |
+
+
+ Fixed an issue where Panorama was unable to push the Trusted Root CA
+ configuration to Log Collectors via a Collector Group push due to the
+ Log Collector not supporting the
+ trusted-root-CA configuration.
+
+ |
+
|
+ PAN-297797
+ |
+
+
+ Fixed an issue where, during a refresh of a large External Dynamic
+ List (EDL), traffic that matched a domain on the list was incorrectly
+ identified as a different domain, which resulted in false positive
+ threat logs.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release,
+ the Visible Virtual System field referenced the vsys name instead of
+ the vsys ID, which caused inter-vsys routing to fail. This occurred
+ when a vsys display name matched one of the vsys IDs. If you're using
+ a multivsys environment, you must upgrade your firewalls to a fixed
+ PAN-OS version. The best practice is to upgrade both the firewalls and
+ Panorama to a fixed PAN-OS version.
+
+
|
+
|
+ PAN-297321
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where return packets from a phone gateway looped
+ between the HA pair instead of being encapsulated into the
+ GlobalProtect tunnel. This occurred when the inner session and the
+ outer IPSec tunnel terminated on different nodes, which led to
+ excessive retries and packet drops.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high
+ packet rates on the synthetic path in DPDK mode.
+
+ |
+
|
+ PAN-296752
+ |
+
+
+ Fixed an issue where the firewall experienced high management CPU
+ usage and repeatedly rebooted when attempting to retrieve SMART data.
+
+ |
+
|
+ PAN-296490
+ |
+
+
+ (Firewalls with FIPS-CC mode enabled only)
+ Fixed an issue where Panorama on GCP rebooted every hour after
+ upgrading.
+
+ |
+
|
+ PAN-296453
+ |
+
+
+ Fixed an issue where decryption exclusion lists were not working for
+ untrusted certificates, and SSL sessions were still being decrypted
+ even after adding them to the exclusion list. This occurred because
+ the firewall was not adding sessions to the exclude cache until after
+ receiving a non-RFC alert (BadCertificate) from the server. The fix
+ ensures that the first session is added to the exclude cache, allowing
+ subsequent sessions to skip decryption. This issue affects firewalls
+ configured as clients in server-client communication.
+
+ |
+
|
+ PAN-295644
+ |
+
+
+ Fixed an issue where Strata Logging Service (SLS) log forwarding
+ streams intermittently displayed as inactive.
+
+ |
+
|
+ PAN-295560
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors,
+ tunnel logs were not visible in Panorama or Splunk even though traffic
+ and threat logs were received.
+
+ |
+
|
+ PAN-295385
+ |
+
+
+ Fixed an issue where syslog forwarding dropped due to FQDN resolution
+ failures.
+
+ |
+
|
+ PAN-295257
+ |
+
+
+ Fixed an issue where, after onboarding a firewall to Panorama, IPsec
+ tunnels displayed IKEv2 in Panorama, even though the tunnels were
+ configured with IKEv1 locally on the firewall.
+
+ |
+
|
+ PAN-295221
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors,
+ Traffic and Threat logs were not forwarded to a Splunk server over
+ UDP.
+
+ |
+
|
+ PAN-294893
+ |
+
+
+ Fixed an issue where firewalls with the
+ Send handshake messages to CTD for inspection
+ setting enabled caused incorrect security policy rules to be matched.
+ Specifically, traffic not identified as openai-base or openai-chatgpt
+ applications was incorrectly matched by the
+ ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
+ response page for blocked URLs was not displayed.
+
+ |
+
|
+ PAN-294770
+ |
+
+
+ (Firewalls in active/passive HA configurations)
+ Fixed an issue on firewalls where, after failover, certain subnets
+ were missing from the Link State Database, which prevented OSPF routes
+ from being immediately learned due to a Type-7 to Type-5 LSA
+ translation conflict in the ABR when the same LSA was advertised by
+ two peers in the NSSA area.
+
+ |
+
|
+ PAN-294524
+ |
+
+
+ Fixed an issue where firewalls and Panorama management servers were
+ unable to view or download WildFire reports from a WF-500 appliance,
+ resulting in a 401 error in the report tab.
+
+ |
+
|
+ PAN-294161
+ |
+ + + | +
|
+ PAN-293985
+ |
+
+
+ Fixed an issue with the Panorama web interface where admin users were
+ unable to log in and received the error message
+ 504: Gateway Timeout.
+
+ |
+
|
+ PAN-293877
+ |
+
+
+ (Firewalls with Hub vsys (virtual system) configurations enabled
+ only) Fixed an issue where, when using the Hub vsys feature to
+ redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP
+ policy enforcement failed intermittently on the active secondary
+ firewall. This occurred when traffic destined for specific non-Hub
+ vsys was routed to the active secondary, and the HIP query was not
+ triggered due to an incorrect check for the HIP mask in the Hub vsys.
+
+ |
+
|
+ PAN-293848
+ |
+
+
+ Fixed an issue where Panorama failed to push the default value of
+ None for the secondary NTP server
+ address to managed firewalls, resulting in a commit validation error.
+ This occurred even when configuring the secondary NTP server address
+ as None in Panorama's web interface,
+ and affected both newly deployed and long-standing production
+ firewalls after upgrading.
+
+ |
+
|
+ PAN-293511
+ |
+
+
+ Fixed an issue where renaming a BGP filtering profile in Panorama does
+ not update the corresponding BGP peer group in the virtual router,
+ leading to commit failures.
+
+ |
+
|
+ PAN-293440
+ |
+
+
+ Fixed an issue where setting the
+ logdb-quota for the
+ desum log type to
+ 0 caused the /opt/panlogs
+ partition to reach capacity.
+
+ |
+
|
+ PAN-292447
+ |
+
+
+ Fixed an issue where Panorama did not display data in the
+ Feature Adoption tab in Strata Cloud
+ Manager due to the system creating and deleting a CLI user for each
+ interval instead of reusing a permanent CLI user for telemetry.
+
+ |
+
|
+ PAN-292393
+ |
+
+
+ Fixed an issue where TFTP file transfers intermittently timed out in
+ active-active HA pairs when the TFTP control channel was processed by
+ one firewall and the data channel was processed by the other. This
+ occurred because the firewall receiving the data channel failed to
+ match the predicted session due to asynchronous processing of HA
+ messages.
+
+ |
+
|
+ PAN-292261
+ |
+
+
+ Fixed an issue where the firewall repeatedly reported an unreachable
+ syslog server as back online when
+ the server remained unavailable. This resulted in misleading
+ alternating connection status messages in the system logs.
+
+ |
+
|
+ PAN-292242
+ |
+
+
+ Fixed an issue on M-200 and logging appliances where traffic logs were
+ intermittently truncated when forwarded using a TCP syslog
+ configuration. This issue occurred during the log forwarding stage due
+ to intermittent syslog drops caused by exceeding the forwarding queue
+ capacity.
+
+ |
+
|
+ PAN-292228
+ |
+
+
+ Fixed an issue where, after configuring dual stack GlobalProtect with
+ both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with
+ the error message
+ flow-basic error; packet dropped, tunnel resolution failure.
+
+ |
+
|
+ PAN-292019
+ |
+
+
+ Fixed an issue on the Panorama web interface where cloud applications
+ were not displayed under
+ Objects > Applications after a
+ new content upgrade and Cloud App Catalog download, and were only
+ visible in application groups, security policy rules, and the CLI.
+
+ |
+
|
+ PAN-291883
+ |
+
+
+ Fixed an issue where Prisma Access logs were not visible in the
+ Security Logging Service (SLS) and Panorama.
+
+ |
+
|
+ PAN-291792
+ |
+
+
+ (PA-7050 firewalls on vwire instances only)
+ Fixed an issue where Bidirectional Forwarding Detection (BFD) echo
+ packets were dropped due to the firewall dropping packets with the
+ same source and destination IP addresses.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ Fixed an issue where during a commit, the firewall experienced an
+ out-of-memory (OOM) condition due to a memory leak and displayed an
+ error message. This issue caused the device to stop responding and
+ reboot unexpectedly.
+
+ |
+
|
+ PAN-291661
+ |
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after
+ an upgrade, Elasticsearch intermittently entered into a Red state
+ before automatically recovering.
+
+ |
+
|
+ PAN-291660
+ |
+
+
+ Fixed an issue where the firewall incorrectly reported the speed of
+ 25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID.
+
+ |
+
|
+ PAN-291653
+ |
+
+
+ Fixed an issue where the GlobalProtect host ID field was
+ intermittently blank in traffic logs on Prisma Access, even when the
+ user was connected and had the correct host ID information. This
+ occurred when the IP address to host ID entry expired and the entry
+ was re-insterted without the dataplane flag being set.
+
+ |
+
|
+ PAN-291635
+ |
+
+
+ Fixed an issue where cookie surrogate cache entries remained
+ unresolved after an
+ idmgr
+ process reset due to the request not being retransmitted. This
+ occurred because the timestamp in the cache entry was refreshed even
+ when the UID was 0, which prevented the retransmission of the request
+ if the initial response was not received.
+
+ |
+
|
+ PAN-291067
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process periodically exceeded its virtual memory limit and restarted,
+ which led to intermittent outages.
+
+ |
+
|
+ PAN-290665
+ |
+
+
+ Fixed an issue with firewalls enabled with Security profiles where
+ certain traffic conditions caused high dataplane CPU utilization and
+ packet buffer exhaustion, which caused LACP flapping conditions.
+
+ |
+
|
+ PAN-290640
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments in HA
+ configurations only) Fixed an issue where, when an interface was configured with IPv6,
+ the firewall displayed the message
+ Unknown error during validation
+ after the client secret expired, which caused DNS resolution to fail
+ when resolving FQDNs and HA failovers to occur.
+
+ |
+
|
+ PAN-290455
+ |
+ + + | +
|
+ PAN-289716
+ |
+
+
+ Fixed an issue where return traffic was dropped on service connection
+ firewalls due to routing failover and asymmetric return in service
+ connection firewalls.
+
+ |
+
|
+ PAN-288388
+ |
+
+
+ Fixed an issue where, after an EDL certificate update or repository
+ migration, authentication failures caused the firewall to not fall
+ back to the last successfully cached EDL entries, which led to policy
+ rules that referenced the EDL to not be enforced.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Fixed an issue where, after upgrading the firewall, certain websites
+ weren't accessible when the accumulation proxy was enabled. The proxy
+ did not use the same DF bit state as the original traffic, causing it
+ to be fragmented and dropped elsewhere in the network.
+
+ |
+
|
+ PAN-287782
+ |
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP
+ values from AF11 to CS0 on traffic passing through the firewall, even
+ when QoS policy rules and DSCP rewrite settings were not configured.
+
+ |
+
|
+ PAN-287693
+ |
+
+
+ Fixed an issue where Panorama did not use the configured proxy
+ settings to check WildFire private cloud content and instead connected
+ directly to the WildFire device using the management interface. This
+ occurred even when
+ Use Proxy Settings for Private Cloud
+ was enabled.
+
+ |
+
|
+ PAN-287622
+ |
+
+
+ Fixed an issue where IPv6 traffic was affected after upgrading the
+ firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
+ enabled and a decryption policy configured for the traffic, the
+ firewall dropped packets due to receiving a
+ Packet Too Big ICMP message. This
+ occurred because the PathMTU information update was incorrect for the
+ TCB (pan-server) when the firewall was acting as a server.
+ Additionally, the flow label under the IPv6 header was set to zero
+ while the packet was being transmitted out of the firewall.
+
+ |
+
|
+ PAN-287387
+ |
+
+
+ Fixed an issue on Panorama where API jobs failed with the error
+ message
+ Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a
+ large number of address objects in a single set call.
+
+ |
+
|
+ PAN-285169
+ |
+
+
+ Fixed an issue on Panorama where Kerberos superusers were unable to
+ edit policy rules because the target device tab was grayed out.
+
+ |
+
|
+ PAN-283053
+ |
+
+
+ Fixed an issue where the firewall experienced high disk space
+ utilization, which caused the firewall to become non-functional.
+
+ |
+
|
+ PAN-282961
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly after a commit
+ due to a memory leak related to the
+ rasmgr
+ process and displayed the error message
+ Management server failed to send phase 1 to client l2ctrld
+ before rebooting.
+
+ |
+
|
+ PAN-282956
+ |
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 and later PAN-OS
+ releases where the portal and gateway configuration view did not
+ display rows and columns.
+
+ |
+
|
+ PAN-267450
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding with a SIGSEGV at
+ schedule_report_es_response.
+
+ |
+
|
+ PAN-263422
+ |
+
+
+ Fixed an issue where SaaS Policy Recommendations policy rules created
+ at the tenant level were not displayed on the firewall.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-316911
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-314142
+ |
+
+
+ Fixed an issue where establishing log forwarding connections to the
+ Strata Logging Service (SLS) took longer than expected, which resulted
+ in delayed log visibility on SLS.
+
+ |
+
|
+ PAN-313623
+ |
+
+
+ Fixed an issue where the
+ /opt/pancfg/mgmt/ssl/private/
+ directory on Palo Alto Networks devices with TPM support became 100%
+ utilized due to an accumulation of undeleted
+ .pub_pem files. This occurred
+ because executing the
+ show device-certificate status
+ CLI command initiated a process that generated these files but failed
+ to remove them, which prevented the fetching of new device
+ certificates.
+
+ |
+
|
+ PAN-313572
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the dataplane restarted due to a segmentation fault.
+
+ |
+
|
+ PAN-313258
+ |
+
+
+ Fixed an issue where PIM multicast routing failed on appliances with
+ advanced routing enabled.
+
+ |
+
|
+ PAN-312706
+ |
+
+
+ Fixed an issue where the firewalls restarted due to a function lacking
+ a NULL-pointer sanity check.
+
+ |
+
|
+ PAN-312618
+ |
+
+
+ Fixed an issue where the firewall was unable to activate GlobalProtect
+ client software and displayed
+ SW LIMIT messages related to
+ max-profiles and unsupported major and minor versions in the downgrade
+ list, which prevented successful software installation.
+
+ |
+
|
+ PAN-311524
+ |
+
+
+ Fixed an issue where config-lock was not displayed on the web
+ interface.
+
+ |
+
|
+ PAN-311412
+ |
+
+
+ Fixed an issue where the
+ show advanced-routing resource
+ CLI command failed to execute successfully when invoked through the
+ XML API and returned an error message.
+
+ |
+
|
+ PAN-311261
+ |
+
+
+ Fixed an issue where the firewall generated duplicate URL Filtering
+ logs due to an error condition when the new XFF feature was enabled.
+
+ |
+
|
+ PAN-311250
+ |
+
+
+ (Panorama appliances and Log Collectors only)
+ Fixed an issue where logs from multiple devices were not visible on
+ Panorama even though the Elasticsearch health status on the dedicated
+ Log Collectors appeared green.
+
+ |
+
|
+ PAN-311074
+ |
+
+
+ Fixed an issue where GRE tunnels took significantly longer to
+ establish when the hold timer was configured to a value of 10 or
+ higher, which resulted in a tunnel requiring more successful keepalive
+ packets than expected to transition to an
+ Up state.
+
+ |
+
|
+ PAN-311073
+ |
+
+
+ (Panorama managed firewalls in HA configurations only) Fixed an issue where firewalls incorrectly updated the modified
+ date and MD5 hash of policy rules during an HA sync commit job or a
+ subsequent local commit, even when no changes were made to the policy
+ rules.
+
+ |
+
|
+ PAN-310868
+ |
+
+
+ Fixed an issue where PA Explicit proxy blocked ICMP packets from
+ flowing towards Envoy for Geneve due to the router not camping MSS
+ when the MTU was lower in the path.
+
+ |
+
|
+ PAN-310499
+ |
+
+
+ Fixed an issue on Panorama where, while configuring an an Application
+ Filter with Generative AI tags, the web interface did not retain
+ application exclusions that were added across multiple pages until you
+ clicked OK.
+
+ |
+
|
+ PAN-310263
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ enabling TLS1.3 in a decryption profile prevented access to websites.
+
+ |
+
|
+ PAN-309853
+ |
+
+
+ (Firewalls with FIPS-CC enabled only) Fixed an
+ issue where, when attempting to make changes to the GlobalProtect
+ portal, an error message was displayed and configuration updates
+ failed.
+
+ |
+
|
+ PAN-309831
+ |
+
+
+ Fixed an issue where an AI Runtime Security Firewall rebooted when
+ processing Cursor traffic.
+
+ |
+
|
+ PAN-309826
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ files from SSL decrypted sessions were incorrectly forwarded to the
+ WildFire cloud for analysis even when
+ Allow Forwarding of Decryption Content
+ was disabled.
+
+ |
+
|
+ PAN-309459
+ |
+
+
+ Fixed an issue where on PA-5420 firewalls, configuring security rules
+ with a number of static IMSI/IMEI/NSSAI entries exceeding 5,000
+ resulted in a commit failure. This occurred because the firewall
+ incorrectly reported the maximum supported static IMSI/IMEI/NSSAI IDs
+ as 5,000 (as seen in the
+ cfg.mobile-nw-id.max-static-entries
+ system state variable), instead of the documented limit of 100,000 for
+ the platform.
+
+ |
+
|
+ PAN-309392
+ |
+
+
+ Fixed an issue where the scroll bar did not appear when editing
+ Destination Addresses for Policy
+ Based forwarding policy rules.
+
+ |
+
|
+ PAN-309379
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding on DPCs, which prevented logs from being
+ forwarded.
+
+ |
+
|
+ PAN-309300
+ |
+
+
+ Fixed an issue where management plane system resources configuration
+ size exceeded 28 MB for over 4 hours, and the following error message
+ was displayed:
+ Configuration size reaching device capacity limit.
+
+ |
+
|
+ PAN-309258
+ |
+
+
+ Fixed an issue where you were unable to delete a HIP object with
+ OR in the name, even though you were
+ able to successfully create and commit the object.
+
+ |
+
|
+ PAN-309009
+ |
+
+
+ Fixed an issue where log ingestion stopped on the Elasticsearch
+ cluster when the number of open shards was significantly higher than
+ the number of data nodes.
+
+ |
+
|
+ PAN-308902
+ |
+
+
+ Fixed an issue where, after upgrading to an affected release, the
+ firewall did not add mTLS websites that required client certificate
+ authentication via DN list to the ssl-decrypt exclude-cache list.
+
+ |
+
|
+ PAN-308786
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ traffic log queries using the
+ device_name filter returned no
+ results, and complex log queries that included negation operators
+ produced incorrect outputs.
+
+ |
+
|
+ PAN-308727
+ |
+
+
+ Fixed an issue where traffic logs for
+ Remote Networks displayed the source
+ zone as trust instead of the remote
+ network name.
+
+ |
+
|
+ PAN-308668
+ |
+
+
+ Fixed an issue on Prisma Access Remote Network firewalls where high
+ CPU utilization caused slowness and command timeouts.
+
+ |
+
|
+ PAN-308654
+ |
+
+
+ Fixed an issue where the Elasticsearch Close Indices process closed
+ more indices than expected and dropped the number of open shards below
+ the minimum of 800 per Elasticsearch instance. This occurred because
+ the process did not correctly account for the number of Elasticsearch
+ instances when calculating the maximum number of allowed open shards.
+
+ |
+
|
+ PAN-308606
+ |
+
+
+ Fixed an issue where traffic was blocked due to a mismatch between the
+ URL category specified in the Security policy rule and the URL filter
+ profile when custom URL categories with the same FQDN were configured.
+
+ |
+
|
+ PAN-308468
+ |
+
+
+ Fixed an issue where the firewall rebooted due to the
+ all_task
+ process restarting.
+
+ |
+
|
+ PAN-308418
+ |
+
+
+ Fixed an issue where, when Advanced DNS Security was enabled and
+ experienced unusually high loads, DNS resolution failures occurred
+ with the error
+ resources-unavailable.
+
+ |
+
|
+ PAN-308377
+ |
+
+
+ (PA-7050 firewalls in HA configurations only)
+ Fixed an issue where the firewall reached 100% disk utilization due to
+ the
+ logrcvr
+ process repeatedly restarting and dumping core files due to a blocked
+ hints processing thread, which caused a failover.
+
+ |
+
|
+ PAN-308261
+ |
+
+
+ Fixed an issue where the firewall failed to send SNMPv3 traps when the
+ SNMP destination was configured with an FQDN that resolved to multiple
+ IP address through DNS load balancing.
+
+ |
+
|
+ PAN-308085
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where, after resizing the VM, the HA2 link became
+ unstable. Frequent keep-alive failures occurred, and HA2 keep-alive
+ packets were simultaneously transmitted to multiple destination MAC
+ addresses and the peer firewall's interface MAC). This issue occurred
+ on firewalls with Accelerated Networking enabled.
+
+ |
+
|
+ PAN-308060
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where the BFD session went down and did not recover
+ even though the BGP remained in an established state, which caused the
+ firewall to cease route learning and advertisement with the peer, even
+ though BGP keep-alives were exchanged correctly.
+
+ |
+
|
+ PAN-307901
+ |
+
+
+ Fixed an issue where a leak in decryption counters caused resource
+ exhaustion, which led to a GlobalProtect service outage.
+
+ |
+
|
+ PAN-307893
+ |
+
+
+ Fixed an issue where the Strata Cloud Manager (SCM) web interface
+ failed to fetch External Dynamic List (EDL) details from Prisma Access
+ and displayed the error message
+ Could not fetch the EDL main info. This occurred because the XML query returned an external list
+ authentication failed response when the EDL entry lacked a valid
+ certificate.
+
+ |
+
|
+ PAN-307806
+ |
+
+
+ Fixed an issue where, after replacing the MPC (Management Processor
+ Card) on a firewall, the
+ logdb process incorrectly wrote
+ logs to the root partition instead of the /opt/panlogs partition,
+ which led to high root partition usage and a non-functional state.
+
+ |
+
|
+ PAN-307795
+ |
+
+
+ Fixed an issue where Panorama incorrectly generated system logs
+ indicating a lost connection to its peer after an upgrade even when
+ High Availability was not configured.
+
+ |
+
|
+ PAN-307773
+ |
+
+
+ Fixed an issue on Panorama where enabling Post-Quantum Pre-Shared Key
+ (PPK) within an IKE Gateway profile that was configured as a part of a
+ template stack failed or was inconsistent when attempted via the web
+ interface, even when the keys were properly configured.
+
+ |
+
|
+ PAN-307714
+ |
+
+
+ VM-Series firewalls only) Fixed an issue where
+ insufficient i-node space was available on the sysroot0 partition.
+
+ |
+
|
+ PAN-307702
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where traffic passing through AE layer 2 interfaces was
+ interrupted during HA failovers.
+
+ |
+
|
+ PAN-307597
+ |
+
+
+ Fixed an issue where BGP peering sessions between a hub firewall and a
+ satellite firewall over GlobalProtect LSVPN failed to connect.
+
+ |
+
|
+ PAN-307453
+ |
+
+
+ Fixed an issue for Panorama management servers where commit push
+ failed when
+ customer_info status was a
+ failure received from the
+ orchestrator, which prevented the system from processing and
+ validating the specified telemetry region correctly during the commit.
+
+ |
+
|
+ PAN-307072
+ |
+
+
+ Fixed an issue where SNMP interface speed reporting incorrectly
+ identified 5Gbps interfaces as 1Gbps interfaces during an SNMP walk.
+
+ |
+
|
+ PAN-307066
+ |
+
+
+ Fixed an issue where static DNS entries that were configured on the
+ firewall failed to resolve for client machines when DNS over TLS (DoT)
+ was enabled on the firewall DNS proxy for both client and server
+ settings.
+
+ |
+
|
+ PAN-306934
+ |
+
+
+ Fixed an issue where traffic was unexpectedly blocked due to a
+ misconfiguration with an empty or invalid application filter. The
+ firewall incorrectly interpreted the empty filter as
+ match all cloud-apps, which caused
+ the traffic to be denied.
+
+ |
+
|
+ PAN-306903
+ |
+
+
+ Fixed an issue on the firewall where, after upgrading, the system log
+ displayed the error message
+ Last config fetch FAILED. A commit is required for userid
+ functionality to work.
+
+ |
+
|
+ PAN-306886
+ |
+
+
+ Fixed an issue where the root partition on the firewall or Panorama
+ management server filled up due to a file leak in the logging process.
+
+ |
+
|
+ PAN-306884
+ |
+
+
+ Fixed an issue where after changing Panorama to logger mode, commits
+ failed due to the
+ panorama-admin role assigned to
+ plugin management configuration users.
+
+ |
+
|
+ PAN-306555
+ |
+
+
+ Fixed an issue where the firewall stopped responding, which led to
+ service outages.
+
+ |
+
|
+ PAN-306502
+ |
+
+
+ Fixed two issues that impacted TLSv1.2 or earlier sessions when the
+ traffic matched a decryption policy rule with the no-decrypt action:
+
+
|
+
|
+ PAN-306451
+ |
+
+
+ (VM-Series firewalls on AWS environments only)
+ Fixed an issue where, after upgrading the firewall to an affected
+ release, GlobalProtect clients did not connect with IPSec and instead
+ connected using SSL due to traffic flow being disabled when checking
+ for health check packets.
+
+ |
+
|
+ PAN-306306
+ |
+
+
+ (Panorama appliances in FIPS-CC mode only)
+ Fixed interdevice TLS communication failures that occurred with RSA
+ and RSA-PSS signature algorithms across multiple layer 7 application
+ services.
+
+ |
+
|
+ PAN-306226
+ |
+
+
+ Fixed an issue where the TLS handshake did not complete and the
+ session did not go through. This occurred if the HTTP header insertion
+ applied to an HTTP CONNECT request passing through the firewall, the
+ scan-handshake feature was enabled, the session matched a decryption
+ policy rule with the decrypt action, and if the TLS client hello was
+ in a single packet and TLS 1.2 or below.
+
+ |
+
|
+ PAN-306225
+ |
+
+
+ Fixed an issue on the firewall where the
+ sslmgr
+ process memory utilization continually increased due to memory
+ fragmentation.
+
+ |
+
|
+ PAN-306215
+ |
+
+
+ Fixed an issue where creating device groups in bulk via XML API took
+ significantly more time and the web interface stopped responding.
+
+ |
+
|
+ PAN-306103
+ |
+
+
+ (PA-3400 and PA-5400 Series firewalls only)
+ Fixed an issue where the firewall dataplane frequently restarted when
+ lockless QoS was enabled
+
+ |
+
|
+ PAN-305922
+ |
+
+
+ Fixed an issue on Panorama where the CLI output for the running
+ configuration intermittently inserted
+ set template stack commands
+ within certificate hash data.
+
+ |
+
|
+ PAN-305835
+ |
+
+
+ Fixed an issue where firewalls with Memory Integrity Checking
+ Architecture enabled rebooted unexpectedly due to accessing an invalid
+ memory address. This occurred because the forwarding data structure
+ index exceeded its designed limit.
+
+ |
+
|
+ PAN-305605
+ |
+
+
+ Fixed an issue where GlobalProtect gateway authentication failed due
+ to the firewall incorrectly bypassing SAML.
+
+ |
+
|
+ PAN-305557
+ |
+
+
+ Fixed an issue where LSVPN (Large Scale VPN) satellites failed to
+ authenticate to the gateway because the portal was providing a
+ zeroized certificate.
+
+ |
+
|
+ PAN-305552
+ |
+
+
+ Fixed an issue where DLP logs displayed an incorrect file type when
+ the firewall did not set the file type field.
+
+ |
+
|
+ PAN-305549
+ |
+
+
+ Fixed an issue where the firewall's service route functionality was
+ impacted due to a missing service route support code.
+
+ |
+
|
+ PAN-305502
+ |
+
+
+ Fixed an issue where Panorama was unable to forward logs to a syslog
+ server over TLSv1.3 when configured with SSL on a custom port. The
+ connection was established, but logs were not forwarded due to a
+ failure in the CRL check.
+
+ |
+
|
+ PAN-305412
+ |
+
+
+ Fixed an issue where the Logging Service License Status displayed a
+ license failure when the license status transitioned from valid to
+ expired and then back to valid even when the connection to the
+ Security Logging Service (SLS) was working.
+
+ |
+
|
+ PAN-305411
+ |
+
+
+ Fixed an issue where, after creating a logical interface with an
+ assigned IP address and adding it to a virtual router, the connected
+ route for the interface did not appear in the
+ show routing route CLI command
+ output. This occurred even when the interface was up and learning ARP
+ entries.
+
+ |
+
|
+ PAN-305374
+ |
+
+
+ Fixed an issue on Panorama where the first letter of a custom URL
+ category was not displayed in generated reports.
+
+ |
+
|
+ PAN-305301
+ |
+
+
+ Fixed an issue where the timing of GlobalProtect lifetime expiry or
+ inactivity logout notifications used for GlobalProtect SSL tunnels
+ could cause the
+ pan_task
+ process to stop responding and the dataplane to restart.
+
+ |
+
|
+ PAN-305188
+ |
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric
+ routing environments if the Client Hello was split into multiple
+ segments and arrived out of order.
+
+ |
+
|
+ PAN-305105
+ |
+
+
+ Fixed an issue where commits involving routing related network
+ configuration changes experienced slower than usual completion times
+ or remaining at 20% completion.
+
+ |
+
|
+ PAN-304840
+ |
+
+
+ Fixed an issue where multiple firewalls experienced high management
+ CPU utilization after upgrading to an affected release due to repeated
+ index regeneration occurring every 15 minutes, which caused periodic
+ CPU spikes above 90%.
+
+ |
+
|
+ PAN-304756
+ |
+
+
+ Fixed an issue on Panorama where, after you disabled the shared
+ optimization feature, a full configuration push to multi-vsys devices
+ caused a validation error.
+
+ |
+
|
+ PAN-304746
+ |
+
+
+ (Panorama appliances and Panorama virtual appliances only) Fixed an issue where the
+ configd
+ process restarted when committing and pushing configuration for a new
+ WildFire cluster.
+
+ |
+
|
+ PAN-304718
+ |
+
+
+ Fixed an issue where OSPF and BGP outages occurred due to an
+ all_task process restart during
+ clientless VPN content rewrite processing.
+
+ |
+
|
+ PAN-304696
+ |
+
+
+ Fixed an issue where the Cloud User-ID connection timed out because
+ the firewall took too long to process the OCSP response.
+
+ |
+
|
+ PAN-304689
+ |
+
+
+ Fixed an issue on Panorama where device group users were able to view
+ and commit configuration changes that had been created by Superusers
+ but not yet committed, even with access domains configured.
+
+ |
+
|
+ PAN-304636
+ |
+
+
+ Fixed an issue where BGP aggregate routes were not created and discard
+ routes were not installed in the routing table.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Fixed an issue where the firewall entered a non-functional state due
+ to segmentation fault within the
+ all_pktproc
+ process that was caused by a session that involved http2 cleartext
+ traffic.
+
+ |
+
|
+ PAN-304538
+ |
+
+
+ Fixed an issue where traffic logs did not populate the
+ Source EDL or
+ Destination EDL fields when traffic
+ matched a Security policy rule that used predefined external dynamic
+ lists.
+
+ |
+
|
+ PAN-304496
+ |
+
+
+ Fixed an issue where, after unregistering an IP tag and registering a
+ different IP tag for the same IP address via XML API, the dynamic
+ address group membership was not updated on the dataplane, which
+ resulted in Security policy rules being enforced incorrectly.
+
+ |
+
|
+ PAN-304397
+ |
+
+
+ Fixed an issue on the web interface where you were unable to test the
+ SCP server connection for Scheduled Log Exports, and the error message
+ key is invalid was displayed.
+
+ |
+
|
+ PAN-304229
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ disable Lifesize (Templates > Network > Network Profiles > IPSec
+ Crypto).
+
+ |
+
|
+ PAN-304205
+ |
+
+
+ Fixed an issue on Panorama where, after upgrading to an affected
+ release, a partial commit via the API did not push configuration
+ changes to managed firewalls, and a full commit was required to
+ synchronize the configuration.
+
+ |
+
|
+ PAN-304148
+ |
+
+
+ Fixed an issue where a large number of GlobalProtect users experienced
+ failed gateway pre-logins with the error
+ Failed to create SAML SSO request
+ during peak login times.
+
+ |
+
|
+ PAN-304088
+ |
+
+
+ Fixed an issue where TCP traffic stopped working from Prisma Access
+ clients to TCP services behind the Service Connection (SC) after a
+ dataplane upgrade to PAN-OS 10.2.10-h26.
+
+ |
+
|
+ PAN-304075
+ |
+
+
+ Fixed an issue where the firewall did not detect evasions due to TCP
+ checksum offloading not being enabled.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Fixed an issue where traffic was incorrectly identified as
+ unknown-tcp/unknown-udp due to App-ID resource leak and eventually
+ dropped.
+
+ |
+
|
+ PAN-303954
+ |
+
+
+ Fixed an issue where, when configuring Safenet HSMs in HA and
+ authentication HSM manually, the second HSM server failed to
+ authenticate due to the firewall overwriting the first HSM server's
+ certificate with the second HSM server's certificate.
+
+ |
+
|
+ PAN-303836
+ |
+
+
+ Fixed an issue where intermittent session-table resets on the AIRS VM
+ triggered packet drops, which led to packet loss in egress response
+ traffic.
+
+ |
+
|
+ PAN-303833
+ |
+
+
+ Fixed an issue where Panorama and managed devices incorrectly
+ displayed warning messages that indicated that an Advanced DNS
+ Security license and an Advanced Threat Prevention license were
+ required, even when a traditional DNS Security license was installed.
+
+ |
+
|
+ PAN-303826
+ |
+
+
+ Fixed an issue where scheduled software upgrades from the Software
+ Change Management (SCM) server to the firewall failed with a timeout
+ error during download.
+
+ |
+
|
+ PAN-303791
+ |
+
+
+ Fixed an issue where configuring a service route on a loopback
+ interface caused intermittent connectivity issues and disrupted
+ traffic due to the firewall being unable to resolve domain names.
+
+ |
+
|
+ PAN-303765
+ |
+
+
+ Fixed an issue on Panorama where selective pushes failed when a
+ scheduled job was deleted from the Panorama configuration.
+
+ |
+
|
+ PAN-303745
+ |
+
+
+ Fixed an issue where inter-dataplane forwarding did not work for
+ sessions ingressing on Slot 2, which resulted in intermittent ping
+ failures to interfaces on Network Card 2 when traffic was forwarded to
+ Slot 3.
+
+
+ Note: With this fix, after a slot restart, the global counter will
+ still show dot1q errors for a short period.
+
+ |
+
|
+ PAN-303722
+ |
+
+
+ Fixed an issue on the firewall where configuring spyware and
+ vulnerability profiles in Security policy rules caused a memory leak
+ in the
+ devsrvr
+ process with each configuration commit.
+
+ |
+
|
+ PAN-303671
+ |
+
+
+ Fixed an issue where third-party clients were unable to connect to the
+ GlobalProtect gateway after a successful login when the username was
+ entered in the domain\username format.
+
+ |
+
|
+ PAN-303663
+ |
+
+
+ Fixed an issue on the firewall where SolarWinds monitoring systems
+ reported 100% usage for
+ Slot1 Data Processor-0 Hardware Packet Buffers
+ due to an inaccurate reported packet buffer.
+
+ |
+
|
+ PAN-303627
+ |
+
+
+ Fixed an issue where, after committing a configuration change, the
+ firewall experienced traffic issues,
+ pan_task
+ crashes, and LACP interface failures.
+
+ |
+
|
+ PAN-303559
+ |
+
+
+ Fixed an issue where, after manuallly creating a device telemetry
+ bundle, the
+ hour_cli_output.txt file within
+ the bundle had a file size of 0 bytes. This occurred when checking the
+ bundle content after enabling device telemetry and setting the device
+ telemetry upload endpoint.
+
+ |
+
|
+ PAN-303508
+ |
+
+
+ Fixed an issue where the firewall failed to fetch the device
+ certificate during initial installation.
+
+ |
+
|
+ PAN-303487
+ |
+
+
+ Fixed an issue where Panorama appliances in FIPS-CC mode did not push
+ the configured values for
+ max-session-count and
+ max-session-time to managed
+ firewalls that were not in FIPS mode.
+
+ |
+
|
+ PAN-303390
+ |
+
+
+ Fixed an issue on the firewall where the DNS cache capacity was set to
+ an incorrect value, which caused the firewall to repeatedly send DNS
+ requests for FQDN objects even after receiving valid responses. This
+ resulted in the firewall not storing DNS responses in the cache for
+ more than 10-15 seconds despite the minimum FQDN refresh interval
+ being set to a higher value.
+
+ |
+
|
+ PAN-303379
+ |
+
+
+ Fixed an issue where the
+ show system resources CLI command
+ displayed incorrect CPU usage values that did not add up to 100%.
+
+ |
+
|
+ PAN-303156
+ |
+
+
+ Fixed an issue where the session timer for a custom application did
+ not transition from the initial 3-way handshake timer to the
+ application timeout when out-of-order 3-way handshake packets were
+ detected.
+
+ |
+
|
+ PAN-303051
+ |
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the
+ reportd
+ process due to retaining memory that was temporarily used for report
+ generation instead of releasing the memory for reuse, which resulted
+ in continuous accumulation and memory exhaustion.
+
+ |
+
|
+ PAN-302983
+ |
+
+
+ Fixed an issue where, after committing changes on Panorama, a shared
+ post-rule moved to the end of the
+ post shared rulebase on the
+ managed device instead of remaining at the top.
+
+ |
+
|
+ PAN-302927
+ |
+
+
+ Fixed an issue where, after upgrading Panorama, the
+ Push to Devices option did not
+ display selected devices, and the
+ OK and
+ Cancel buttons did not function as
+ expected. Selecting
+ Push to Devices did not populate any
+ results, and clicking OK after
+ selecting a device under
+ Edit selections did not work.
+ Despite this, selecting Push or
+ Validate Device Group Push still
+ pushed to the previously canceled, non-displayed devices.
+
+ |
+
|
+ PAN-302921
+ |
+
+
+ Fixed an issue where the
+ set auth radius-require-msg-authentic yes
+ and
+ show auth radius-require-msg-authentic
+ CLI commands were unavailable on Log Collectors.
+
+ |
+
|
+ PAN-302834
+ |
+
+
+ Fixed an issue where Panorama did not display decryption logs after a
+ certain date due to the decryption index being purged.
+
+ |
+
|
+ PAN-302811
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where network traffic was disrupted due to the
+ all_pktproc
+ process repeatedly restarting, which caused an HA failover.
+
+ |
+
|
+ PAN-302767
+ |
+
+
+ Fixed an issue where IPv6 IPsec WAN support was not available in
+ Prisma Access.
+
+ |
+
|
+ PAN-302737
+ |
+
+
+ Fixed an issue where API key generation failed after renewing an
+ expired API certificate, and the system continued to use the expired
+ certificate.
+
+ |
+
|
+ PAN-302703
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where Panorama was inaccessible with the error message
+ Timed out while getting config lock.
+
+ |
+
|
+ PAN-302567
+ |
+
+
+ Fixed an issue where firewalls incorrectly returned the message
+ API Error: Success with the error
+ code 403 instead of the correct message
+ API Error: Invalid Credential, when
+ Cisco-ISE server was used for MSCHAP-PEAP Radius auth.
+
+ |
+
|
+ PAN-302564
+ |
+
+
+ Fixed an issue on the firewall where a path monitoring failure
+ occurred and caused the dataplane to restart.
+
+ |
+
|
+ PAN-302551
+ |
+
+
+ Fixed an issue where the firewall displayed as disconnected in the SLS
+ due to the serial number not being retrieved
+
+ |
+
|
+ PAN-302428
+ |
+
+
+ Fixed an issue on Panorama where daily scheduled report emails for
+ custom reports were delivered with no content and instead incorrectly
+ displayed the message
+ No matching data found. With this
+ fix, the content is displayed correctly.
+
+ |
+
|
+ PAN-302317
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding after a commit, which cause the dataplane
+ to reboot repeatedly.
+
+ |
+
|
+ PAN-302254
+ |
+
+
+ Fixed an issue where the web interface made calls to retrieve cloud
+ authentication service regions even when creating a non-cloud
+ authentication service profile.
+
+ |
+
|
+ PAN-302127
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where adding a 26th floating IP address to an
+ aggregate ethernet interface in one vsys caused IPSec tunnels on
+ another vsys to stop working due to rekeying. This occurred due to the
+ routed
+ process not detecting the unchanged virtual address, uninstalling it,
+ and then reinstalling it, which ended the
+ ikemgr
+ connection on the virtual address.
+
+ |
+
|
+ PAN-302085
+ |
+
+
+ Fixed an issue where network values were not displayed in Panorama
+ with the error message
+ There is no value for the selected item. This was due to the device group passing vsysName in Panorama.
+
+ |
+
|
+ PAN-301975
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the passive firewall incorrectly triggered PBP alerts even
+ with low packet rates.
+
+ |
+
|
+ PAN-301965
+ |
+
+
+ Fixed an issue on Panorama where enabling Advanced Routing in a
+ template did not work.
+
+ |
+
|
+ PAN-301937
+ |
+
+
+ Fixed an issue where Microsoft Defender for Cloud detected cleartext
+ SSH private keys in the /var/appweb and /etc/appweb directories on
+ PA-VM firewalls deployed in Azure.
+
+ |
+
|
+ PAN-301912
+ |
+
+
+ Fixed an issue where Panorama stopped responding when deploying
+ dynamic updates to managed devices.
+
+ |
+
|
+ PAN-301848
+ |
+
+
+ Fixed an issue where websites were incorrectly categorized with high
+ severity alerts (Monitoring > URL Filtering) even though they were assessed as low risk. This occurred due to
+ session information being unavailable during logging.
+
+ |
+
|
+ PAN-301828
+ |
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud
+ Manager and configured to use a proxy server for external connections,
+ the management server did not use the configured settings to connect
+ to the Cloud Management service.
+
+ |
+
|
+ PAN-301801
+ |
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process
+ fluctuated intermittently between green and red states, which led to
+ interruptions in log collection. This issue occurred when the number
+ of shards exceeded the cluster's maximum supported threshold of
+ greater than 1000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-301733
+ |
+
+
+ Fixed an issue where the
+ show cloud-auth-service-regions
+ CLI command took longer than expected to complete due to timeouts
+ while fetching Cloud Authentication Service (CAS) regions.
+
+ |
+
|
+ PAN-301691
+ |
+
+
+ Fixed an issue where BGP stopped responding with the error message
+ Too many open files when pushing
+ 1000 eBGP (External BGP) neighbor configurations. With this fix, the
+ number of file descriptors for the BGP process is increased from 1024
+ to 8192.
+
+ |
+
|
+ PAN-301662
+ |
+
+
+ Fixed an issue where direct application URLs for Clientless VPN did
+ not work on one device in a high availability (HA) pair because the
+ RelayState in the SAML assertion was not encoded by the firewall.
+
+ |
+
|
+ PAN-301653
+ |
+
+
+ Fixed an issue where DNS traffic sessions prematurely terminated with
+ the message
+ resources-unavailable. This
+ occurred due to IPv4 fragmented DNS responses causing the Advanced DNS
+ Security module to incorrectly pack the DNS payload multiple times
+ when forwarding to the cloud for inspection.
+
+ |
+
|
+ PAN-301600
+ |
+
+
+ Fixed an issue on the firewall where, after upgrading Panorama, OSPF
+ adjacencies remained in the exchange start state, which resulted in an
+ incomplete routing table.
+
+ |
+
|
+ PAN-301456
+ |
+
+
+ Fixed an issue on Panorama where the
+ debug system reset-ztp CLI
+ command was unavailable.
+
+ |
+
|
+ PAN-301430
+ |
+
+
+ Fixed an issue where the web server did not specify the content type
+ in the header for font files, which could allow a browser to
+ misinterpret the content and potentially lead to cross-site scripting
+ (XSS) vulnerabilities.
+
+ |
+
|
+ PAN-301409
+ |
+
+
+ Fixed an issue where Panorama failed to perform a selective push to a
+ managed device when device tags were added or modified on the policy
+ rules. The selective push failed with the error message
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+
|
+ PAN-301386
+ |
+
+
+ Fixed an issue where BFD echo packets were dropped on Vwire interfaces
+ due to being incorrectly detected as a land attack when the source and
+ destination ports of the BFD packets were different.
+
+ |
+
|
+ PAN-301305
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the
+ all_task
+ process stopped responding and caused the passive firewall to reboot.
+
+ |
+
|
+ PAN-301290
+ |
+
+
+ Fixed an issue on the Panorama web interface where a custom
+ administrator with device group and template permissions was unable to
+ upgrade devices to non-preferred releases due to the options to
+ uncheck base and preferred releases not being displayed.
+
+ |
+
|
+ PAN-301222
+ |
+
+
+ Fixed an issue where DNS Security logs incorrectly displayed a
+ sinkhole action for benign DNS categories due to the firewall saving
+ the drop or sinkhole action in session flags without discarding the
+ session.
+
+ |
+
|
+ PAN-301186
+ |
+
+
+ Fixed an issue on the Panorama web interface where
+ Enable pushing device monitoring data to Panorama
+ was always checked, regardless of the actual configuration.
+
+ |
+
|
+ PAN-301113
+ |
+
+
+ Fixed an issue where the XML API returned the error
+ Access to this vsys is unauthorized
+ when generating a report for a specific vsys, even when the
+ administrator had access to that vsys. This was due to the API session
+ not correctly populating the
+ vsysvector field with the user's
+ allowed vsys.
+
+ |
+
|
+ PAN-301089
+ |
+
+
+ Fixed an issue where Kubernetes pod health checks failed when the
+ pan-fw annotation was added. When the annotation was present, health
+ check traffic from the host's public IP address range to the pod CIDR
+ range was tunneled to the firewall by the pan-cni, which resulted in
+ asymmetric flows and no response from the pod endpoints.
+
+ |
+
|
+ PAN-301018
+ |
+
+
+ Fixed an issue on Panorama where API queries for correlated category
+ logs incorrectly returned a count of 0.
+
+ |
+
|
+ PAN-301014
+ |
+
+
+ Fixed an issue where the GlobalProtect portal used an outdated
+ bootstrap version for clientless VPN.
+
+ |
+
|
+ PAN-300933
+ |
+
+
+ Fixed an issue on Panorama where, after downgrading to an affected
+ release, the commit-all operation
+ failed due to a missing downgrade script.
+
+ |
+
|
+ PAN-300922
+ |
+
+
+ Fixed an issue where the syslog connection was handled by the syslog
+ forwarding thread.
+
+ |
+
|
+ PAN-300916
+ |
+
+
+ Fixed an issue where Panorama management servers failed to forward
+ syslog messages via TLS to a syslog server when DNS resolution for
+ IPv6 addresses failed, and the system did not automatically fall back
+ to IPv4.
+
+ |
+
|
+ PAN-300906
+ |
+
+
+ Fixed an issue where XML API commands failed with a
+ Method not found (policy_xml)
+ error in dagger.log. The issue was due to missing XML-related
+ functions for inline-cloud-proxy.
+
+ |
+
|
+ PAN-300837
+ |
+
+
+ Fixed an issue where firewalls experienced multiple reboots due to the
+ pan_task
+ process restarting with a SIGSEGV signal. This occurred because the
+ client-to-firewall side assumed TLS 1.3 for the firewall-server side.
+
+ |
+
|
+ PAN-300833
+ |
+
+
+ Fixed an issue where the static default route remained active even
+ when the path or SaaS monitor was down when SD-WAN was used for local
+ internet breakout. This was due to missing validation handling in the
+ FRR routed code for link up/down status.
+
+ |
+
|
+ PAN-300671
+ |
+
+
+ Fixed an issue where traffic reports that were generated with
+ destination/source and destination/source hostnames were not displayed
+ in IPv4 format.
+
+ |
+
|
+ PAN-300664
+ |
+
+
+ Fixed an issue on the Panorama and firewall web interface where
+ Applications pages became unresponsive after activating the SaaS
+ Inline license.
+
+ |
+
|
+ PAN-300638
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall stopped responding due to an out-of-bounds read when
+ parsing TLS 1.3 clientHello messages with large TLS clientHello
+ extensions where the
+ supported_versions extension fell
+ outside the first TCP segment.
+
+ |
+
|
+ PAN-300637
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the firewall unexpectedly rebooted due to
+ repeated
+ varrcvr
+ process restarts.
+
+ |
+
|
+ PAN-300617
+ |
+
+
+ Fixed an issue where the Elasticsearch cluster status displayed as red
+ due to unassigned shards, which prevented logs from updating.
+
+ |
+
|
+ PAN-300555
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the HA1-A interface reported an incorrect SNMP down value
+ even when the interface was physically up on the active firewall.
+
+ |
+
|
+ PAN-300548
+ |
+
+
+ Fixed an issue where using the IKEv2 multiplier setting for VPN
+ re-authentication resulted in the firewall not re-authenticating at
+ the expected intervals when both sides initiated rekeying. The
+ internal re-authentication counter incremented when the local side
+ triggered the rekey, but not when the peer side triggered it.
+
+ |
+
|
+ PAN-300423
+ |
+
+
+ Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
+ and 6 remained stuck in a starting state with the error
+ Signal detected for port xeS5-DP0 but Link Down
+ alerts, which resulted in device instability.
+
+ |
+
|
+ PAN-300280
+ |
+
+
+ Fixed an issue where, on firewalls configured as an Area Border Router
+ (ABR) with a backbone area (0.0.0.0) and a stub area, external Type-5
+ Link State Advertisement (LSA) routes were not installed in the
+ routing table.
+
+ |
+
|
+ PAN-300186
+ |
+
+
+ Fixed an issue where the GlobalProtect portal exposed the internal IP
+ address of the gateway when accessed via the SAML20/SP/ACS endpoint.
+
+ |
+
|
+ PAN-300138
+ |
+
+
+ Fixed an issue where DNS queries stalled or repeatedly time out due to
+ multiple DNS responses with different CNAME values causing evasion
+ false positive alerts.
+
+ |
+
|
+ PAN-299915
+ |
+
+
+ Fixed an issue where the Elasticsearch cluster health status displayed
+ as red on dedicated log collectors due to an expired Elasticsearch CC
+ certificate, which prevented log visibility from Panorama.
+
+ |
+
|
+ PAN-299815
+ |
+
+
+ Fixed an issue on multi-vsys firewalls where a host was not removed
+ from the quarantine list after receiving a redistribution message from
+ Panorama. This occurred when Panorama was configured to redistribute
+ quarantine messages to a firewall cluster, and the GlobalProtect
+ configuration and redistribution were built out in a vsys other than
+ vsys1.
+
+ |
+
|
+ PAN-299785
+ |
+
+
+ (PA-7500 and PA-5450 firewalls in FIPS-CC mode)
+ Fixed an issue where the affected firewalls would boot into
+ maintenance mode when a reboot was initiated from the web interface.
+ This was due to a device reboot triggering a power down to all slots,
+ leading to maintenance mode. A hard reboot would allow the firewall to
+ boot normally.
+
+ |
+
|
+ PAN-299772
+ |
+
+
+ (VM-Series firewalls in active/passive configurations only) Fixed an issue where, after an HA failover event, the newly active
+ firewall DHCP client interfaces failed to obtain IP addresses
+ automatically. This occurred because the DHCP client processes did not
+ initiate the necessary DHCP discover or renew requests
+
+ |
+
|
+ PAN-299757
+ |
+
+
+ Fixed an issue where Router Advertisements for IPv6 were not sent at
+ the configured time intervals.
+
+ |
+
|
+ PAN-299751
+ |
+
+
+ Fixed an issue where the firewall was unable to connect to the
+ Subscription License Service (SLS) due to a public and private key
+ pair mismatch with the device certificate.
+
+ |
+
|
+ PAN-299738
+ |
+
+
+ Fixed an issue where excessive dataplane debug logs were generated due
+ to the
+ pan_task
+ process restarting, even without any dataplane debug logs or captures
+ being enabled by the administrator.
+
+ |
+
|
+ PAN-299706
+ |
+
+
+ Fixed an issue where the firewall repeatedly sent DNS requests for
+ FQDN objects despite even after receiving valid responses.
+
+ |
+
|
+ PAN-299705
+ |
+
+
+ Fixed an issue where API calls to commit changes on Panorama
+ intermittently failed when using the XML API with refresh=no, which caused changes to not be applied to the partial-commit
+ configuration.
+
+ |
+
|
+ PAN-299622
+ |
+
+
+ Fixed an issue where the MFA timestamp was not redistributed between
+ standalone firewalls behind an Azure load balancer after upgrading,
+ which resulted in users being prompted to reauthenticate multiple
+ times.
+
+ |
+
|
+ PAN-299615
+ |
+
+
+ Fixed an issue where, when the Network Packet Broker feature was
+ enabled, forward TLS (non-decrypted) traffic was not working as
+ expected when there were segmented client hellos and a no-decrypt rule
+ existed. This issue occurred when Zone Protection profiles were
+ configured for trust/untrust zones but not attached to NPB zones.
+
+ |
+
|
+ PAN-299495
+ |
+
+
+ Fixed an issue where the
+ show system setting ssl-decrypt certificate
+ CLI command did not display certificates when XML output was enabled.
+
+ |
+
|
+ PAN-299450
+ |
+
+
+ Fixed an issue where PAN-OS
+ logrotate did not rotate large
+ log files until the
+ cron.daily
+ process ran, which resulted in the root partition filling up.
+
+ |
+
|
+ PAN-299242
+ |
+
+
+ Fixed an issue where the firewall's SSL proxy sent an empty HTTP2
+ SETTINGS message to the client before confirming server support, which
+ caused some clients to incorrectly assume HTTP/2 support and not fall
+ back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad
+ Request frames from the server, which prevented the client from
+ correctly detecting the lack of HTTP/2 support.
+
+ |
+
|
+ PAN-299228
+ |
+
+
+ Fixed an issue where a session process consumed excessive CPU
+ resources, even when Data Loss Prevention (DLP) was not enabled. This
+ occurred due to the active threat list being iterated twice when
+ active threats were present in the session.
+
+ |
+
|
+ PAN-299193
+ |
+
+
+ Fixed an issue on the firewall where, after upgrading, autocommits
+ repeatedly failed until after a second reboot due to a timing issue
+ between content loading on the management plane card (MPC) and the log
+ receiver startup.
+
+ |
+
|
+ PAN-299161
+ |
+
+
+ Fixed an issue where the bytes number overflowed for a specific
+ application, which caused Network Monitor graphs to display an
+ unexpectedly large volume of traffic.
+
+ |
+
|
+ PAN-299027
+ |
+
+
+ (Panorama virtual appliances in Management Mode only) Fixed an issue where a maximum configuration size of 120 was
+ incorrectly enforced instead of 150 MB.
+
+ |
+
|
+ PAN-298945
+ |
+
+
+ Fixed an issue where OSCP HTTP POST requests were not formatted
+ correctly, which caused failures with strict responders.
+
+ |
+
|
+ PAN-298929
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where, after upgrading the ESXi host to version 8.0.3, the
+ firewall interface went down on the active firewall due to a behavior
+ change in ESXi 8.
+
+ |
+
|
+ PAN-298907
+ |
+
+
+ Fixed an issue on PA-VM in AWS where, in a two-arm deployment
+ integrated with Gateway Load Balancer (GWLB), the firewall did not
+ preserve the GENEVE source port for internet traffic, resulting in
+ increased latency. The fix ensures the firewall preserves the outer
+ UDP source port of GENEVE encapsulation when sending traffic back to
+ GWLB.
+
+ |
+
|
+ PAN-298872
+ |
+
+
+ (PA-400 Series firewalls in HA configurations only) Fixed an issue where ports went down after an HA failover.
+
+ |
+
|
+ PAN-298788
+ |
+
+
+ Fixed an issue where the /pancfg partition on the Azure Cloud NGFW
+ reached 100% utilization, which caused commit failures.
+
+ |
+
|
+ PAN-298684
+ |
+
+
+ Fixed an issue where an Application Override policy rule was not
+ applied using an IPv4 source IP address with IPv6 enabled and
+ Network >
+ Zones >
+ Pre-NAT Identification enabled.
+
+ |
+
|
+ PAN-298654
+ |
+
+
+ Fixed an issue where the firewall generated false positive threat logs
+ during updates to a large domain list (EDL) when a DNS lookup for a
+ domain being added or removed occurred during the update process. This
+ resulted in a threat log being generated for a different, unrelated
+ domain that remained on the list.
+
+ |
+
|
+ PAN-298617
+ |
+
+
+ Optimized the commit workflow to reduce the size of the effective
+ configuration, resulting in lower memory consumption.
+
+ |
+
|
+ PAN-298460
+ |
+
+
+ (Panorama appliances in HA configurations on Microsoft Azure
+ environments only) Fixed an issue on the web interface where the plugin versions that
+ were displayed when hovering the cursor over the Green Match icon were
+ inconsistent even though the Panorama web interface reported the
+ versions as matching.
+
+ |
+
|
+ PAN-298387
+ |
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP
+ addresses did not display in traffic and threat logs.
+
+ |
+
|
+ PAN-298288
+ |
+
+
+ Fixed an issue where traffic loss occurred when two aggregate ethernet
+ interfaces were configured as vwire with only one member link active
+ in the aggregate ethernet interface, which occurred due to an
+ incorrect logic in active port map of AE interfaces.
+
+ |
+
|
+ PAN-298279
+ |
+
+
+ Fixed an issue where Panorama administrators defined in a SAML
+ Identity Provider (IdP) were unable to authenticate if their username
+ exceeded 32 characters, and the system logs displayed the failed
+ authentication attempt with a truncated username.
+
+ |
+
|
+ PAN-298252
+ |
+
+
+ Fixed an issue where Data Loss Prevention (DLP) inspection of chunked
+ transfer encoding over TLS resulted in incomplete file downloads on
+ Outlook Web App (OWA) due to the WIF page size limit, which led to
+ corrupted or incomplete PDF attachments.
+
+ |
+
|
+ PAN-298241
+ |
+
+
+ Fixed an issue where the NAT IP address pool was exhausted, which led
+ to intermittent connectivity issues with call applications and
+ outbound call failures. This occurred due to the firewall not properly
+ releasing NAT dynamic ports back to the address pool.
+
+ |
+
|
+ PAN-298141
+ |
+
+
+ Fixed an issue where the firewall experienced recurring kernel
+ segfaults related to multiple processes, which led to a SIGSEGV error.
+
+ |
+
|
+ PAN-298000
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding after an upgrade, which led to high packet
+ buffer congestion and an OOM condition.
+
+ |
+
|
+ PAN-297976
+ |
+
+
+ Fixed an issue where the firewall experienced extended boot times
+ after a reboot due to the
+ configd
+ process needing to rebuild the ACE catalog after detecting
+ discrepancies that were caused by duplicate application checking
+ between the ACE catalog and content.
+
+ |
+
|
+ PAN-297972
+ |
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched
+ Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
+ Analysis features were not enabled.
+
+ |
+
|
+ PAN-297963
+ |
+
+
+ Fixed an issue where PA-400 Series firewalls were not properly caching
+ DNS responses for FQDN objects. The firewall was observed to
+ repeatedly send DNS requests for the same FQDN objects every 10-15
+ seconds, even after receiving valid responses, despite the minimum
+ FQDN refresh interval being set to a much higher value. This resulted
+ in excessive DNS queries originating from the firewall's management
+ interface.
+
+ |
+
|
+ PAN-297819
+ |
+
+
+ Fixed an issue where the firewall was unable to send device telemetry
+ files to Cortex Data Lake due to the firewall receiving an invalid
+ upload token.
+
+ |
+
|
+ PAN-297818
+ |
+
+
+ Fixed an issue on Panorama where exporting managed device information
+ that included a PA-450R-5G appliance resulted in the
+ Cellular Firmware field being
+ exported into multiple cells.
+
+ |
+
|
+ PAN-297797
+ |
+
+
+ Fixed an issue where, during a refresh of a large External Dynamic
+ List (EDL), traffic that matched a domain on the list was incorrectly
+ identified as a different domain, which resulted in false positive
+ threat logs.
+
+ |
+
|
+ PAN-297796
+ |
+
+
+ Fixed an issue on Panorama where the policy review feature in
+ Dynamic Updates failed to display
+ Security policy rules when the device group was set to
+ All.
+
+ |
+
|
+ PAN-297782
+ |
+
+
+ Fixed an issue on Panorama where reassociating a vsys from one device
+ group to another in a multi-vsys environment resulted in another vsys
+ from the same firewall being removed from the original device group.
+ This resulted in the device being moved into the
+ no device groups attached group, a
+ superuser was required to manually reattach the device.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release,
+ the Visible Virtual System field referenced the vsys name instead of
+ the vsys ID, which caused inter-vsys routing to fail. This occurred
+ when a vsys display name matched one of the vsys IDs. If you're using
+ a multivsys environment, you must upgrade your firewalls to a fixed
+ PAN-OS version. The best practice is to upgrade both the firewalls and
+ Panorama to a fixed PAN-OS version.
+
+
+ If you don't upgrade Panorama to a fixed version, you'll encounter
+ PAN-245064, where a commit on a multivsys firewall fails with the
+ message
+ vsys name should end with a number vsys is invalid
+ after you
+ Export or push device config bundle
+ from 11.1.1 Panorama.
+
+
+ After you upgrade Panorama to a fixed version, you'll encounter
+ PAN-214177, which causes an
+ Export or Push device config bundle
+ from Panorama to the firewall to fail. The workaround for PAN-214177
+ is to first push only the template configuration and then push the
+ device group configurations.
+
+ |
+
|
+ PAN-297774
+ |
+
+
+ Fixed an issue on the web interface where the TLS Version was
+ misspelled as TLS Vesrion (Device > Server Profiles > Email).
+
+ |
+
|
+ PAN-297761
+ |
+
+
+ Fixed an issue where the firewall incorrectly categorized some URLs as
+ not-resolved due to a conflict with Top Level Domain (TLD) data
+ handling in the PAN-DB URL cloud. This affected URLs under domains
+ marked as TLDs, which the firewall incorrectly assumed did not have
+ any category.
+
+ |
+
|
+ PAN-297749
+ |
+
+
+ Fixed an issue where the redistribution agent status was blank on the
+ web interface on both the firewall and Panorama, even though the CLI
+ showed the agent as connected.
+
+ |
+
|
+ PAN-297708
+ |
+
+
+ Fixed an issue where a long-lived session with many Machine Learning
+ (ML) model triggers caused a memory leak of feature states associated
+ with the ML model runs. This resulted in Spyware_State failure
+ increases, allocation max outs, and impaired policy matching.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade
+ due to the fsck command scanning
+ drive partitions in parallel with the root partition, which caused the
+ process to take an extended amount of time.
+
+ |
+
|
+ PAN-297609
+ |
+
+
+ Fixed an issue where the CLI command
+ debug user-id refresh user-id agent all
+ failed with the error message
+ Invalid agent name. Agent name should be 1 to 31 characters
+ long.
+
+ |
+
|
+ PAN-297540
+ |
+
+
+ (Panorama managed firewalls in HA configurations only) Fixed an issue where the HA-Link-Monitor configuration pushed from
+ Panorama was converted to a local configuration on the peer device
+ after an HA sync, which caused subsequent Panorama pushes of link
+ monitor changes to be flagged as overwritten, and a forced template
+ push or manual clearing of the configuration on the firewall was
+ required.
+
+ |
+
|
+ PAN-297458
+ |
+
+
+ Fixed an issue where the
+ all_task_1
+ process crashed on the firewall when the wif service wasn't available
+ because the wif detection ID was not in the current service table.
+
+ |
+
|
+ PAN-297412
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall rebooted unexpectedly due to a negative decoded length.
+
+ |
+
|
+ PAN-297370
+ |
+
+
+ Fixed an issue where pushing a new object from Panorama to a Cloud
+ NGFW Device Group unexpectedly removed existing Panorama-pushed policy
+ rules, even though the
+ Push Preview did not show any
+ deletions, which led to traffic disruptions.
+
+ |
+
|
+ PAN-297321
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where return packets from a phone gateway looped
+ between the HA pair instead of being encapsulated into the
+ GlobalProtect tunnel. This occurred when the inner session and the
+ outer IPSec tunnel terminated on different nodes, which led to
+ excessive retries and packet drops.
+
+ |
+
|
+ PAN-297320
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where scheduled configuration exports failed with an
+ invalid key error when connecting
+ to a SCP server using non-default SCP port. Also, additional CLIs were
+ added to delete the known-hosts file.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high
+ packet rates on the synthetic path in DPDK mode.
+
+ |
+
|
+ PAN-297263
+ |
+
+
+ (PA-5220 firewalls only) Fixed an issue where
+ the
+ ikemgr
+ process crashed intermittently, which caused IPSec tunnels to go down
+ randomly. With this fix, the IKE Security association data structures
+ are accessed in a thread-safe manner, and the
+ ikemgr
+ process does not reference an invalid memory pointer during teardown
+ operations.
+
+ |
+
|
+ PAN-297005
+ |
+
+
+ Fixed an issue where exporting custom reports resulted in empty CSV
+ files.
+
+ |
+
|
+ PAN-296977
+ |
+
+
+ Fixed an issue where the web interface became unresponsive when
+ attempting to view
+ Ethernet interface details after
+ applying a filter in
+ Network > Interfaces.
+
+ |
+
|
+ PAN-296752
+ |
+
+
+ (PA-1410 Firewalls only) Fixed an issue where
+ the firewall experienced high management CPU usage and repeatedly
+ rebooted when attempting to retrieve SMART data.
+
+ |
+
|
+ PAN-296749
+ |
+
+
+ Fixed an issue where email alerts sent from the firewall were marked
+ as spam due to the EHLO header containing only the firewall hostname
+ and not the fully qualified domain name (FQDN).
+
+ |
+
|
+ PAN-296694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to the
+ useridd
+ process repeatedly restarting during an IP-port data type writes to
+ the redis from multiple sources such as TSA or XML in a scale
+ environment.
+
+ |
+
|
+ PAN-296666
+ |
+
+
+ Fixed an issue where Prisma Access gateways did not pass usernames to
+ the WildFire portal, which caused the
+ Recipient User ID to display as
+ unknown on
+ wildfire.paloaltonetworks.com, even when the username was present in
+ the gateway logs.
+
+ |
+
|
+ PAN-296635
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process on passive Panorama management servers leaked memory due to
+ scheduled report handling from the Strata Logging Service (SLS). This
+ memory leak occurred daily, consuming available memory until the
+ process was restarted.
+
+ |
+
|
+ PAN-296616
+ |
+
+
+ Fixed an issue where, when a PBF policy rule with a monitoring profile
+ was configured, the intermediate firewall dropped the PBF monitoring
+ traffic, which caused the PBF rule to remain disabled on the local
+ firewall.
+
+ |
+
|
+ PAN-296598
+ |
+
+
+ Fixed an issue where EAL logs were not forwarded to the IoT Security
+ dashboard when the proxy server password contained special characters.
+
+ |
+
|
+ PAN-296535
+ |
+
+
+ Fixed an issue on the firewall where BGP peers disconnected when more
+ than 500 BGP neighbors were configured in a single Logical Router
+
+ |
+
|
+ PAN-296490
+ |
+
+
+ (Firewalls with FIPS-CC mode enabled only)
+ Fixed an issue where Panorama on GCP lost access to management
+ interface after an hour of uptime.
+
+ |
+
|
+ PAN-296478
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
+ GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
+ JavaScript links, resulting in an authorization error. This occurred
+ because the firewall was incorrectly injecting text into URLs when
+ JavaScript buttons or dropdown menus were clicked within the
+ Clientless VPN portal.
+
+ |
+
|
+ PAN-296453
+ |
+
+
+ Fixed an issue where decryption exclusion lists were not working for
+ untrusted certificates, and SSL sessions were still being decrypted
+ even after adding them to the exclusion list. This occurred because
+ the firewall was not adding sessions to the exclude cache until after
+ receiving a non-RFC alert (BadCertificate) from the server. The fix
+ ensures that the first session is added to the exclude cache, allowing
+ subsequent sessions to skip decryption. This issue affects firewalls
+ configured as clients in server-client communication.
+
+ |
+
|
+ PAN-296452
+ |
+
+
+ Fixed an issue where, when Panorama manages Prisma Access, filtering
+ GlobalProtect logs by IPv6 subnets displays all logs, including IPv4
+ logs.
+
+ |
+
|
+ PAN-296443
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the firewall had a lower maximum capacity for DIPP translated IP
+ addresses than the PA-5260, which caused configuration commit errors
+ during migration. With this fix, the maximum capacity on PA-5450
+ firewalls has been increased to 8000.
+
+ |
+
|
+ PAN-296397
+ |
+
+
+ Fixed an issue on the Panorama web interface where previewing changes
+ after a commit to shared objects were not accurately displayed in the
+ push scope.
+
+ |
+
|
+ PAN-296283
+ |
+
+
+ Fixed an issue where, on hardware platforms with the SaaS inline
+ license, Additional Header Logging (AHL) hash table creation proceeded
+ even when the feature was disabled through the CLI, potentially
+ leading to crashes.
+
+ |
+
|
+ PAN-296224
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where adding a 26th floating IP address to an
+ aggregate interface on one vsys caused IPSec tunnels in another vsys
+ to stop working due to rekeying issues.
+
+ |
+
|
+ PAN-296208
+ |
+
+
+ Fixed an issue where the firewall did not accept address groups in the
+ filter condition of a Log Forwarding Match list.
+
+ |
+
|
+ PAN-296206
+ |
+
+
+ Fixed an issue where the firewall incorrectly routed external Type-5
+ Link State Advertisements (LSAs) within a stub area when the firewall
+ was configured as an Area Border Router (ABR) in a stub area and
+ learned about an external prefix from another ABR connected to the
+ backbone area.
+
+ |
+
|
+ PAN-296202
+ |
+
+
+ (Firewalls in active/active HA configurations only) Added a log enhancement to capture an issue where, when a commit
+ operation was in progress, newly deployed IP address tags that used
+ the XML API were not immediately reflected in address group
+ resolution, which delayed IP address mapping to address groups and
+ caused traffic to be incorrectly allowed or denied.
+
+ |
+
|
+ PAN-296195
+ |
+
+
+ Fixed an issue where, in an SD-WAN Branch Multi-VR environment, ping
+ traffic initiated from the firewall's internal interface resulted in
+ improper zone mapping during session setup, which resulted in the
+ firewall being unable to reach the internet. This occurred due to the
+ ingress zone being incorrectly used as the egress zone.
+
+ |
+
|
+ PAN-296020
+ |
+
+
+ Fixed an issue where commit operations failed during phase 1 when
+ configuring a non-default value for the Graceful Restart Hello Delay
+ due to an FRR parse error if the configured value was between 1 and 9.
+
+ |
+
|
+ PAN-295958
+ |
+
+
+ Fixed an issue where multicast output interfaces (OIFs) were missing
+ for up to 5 minutes after an HA failover or routing process restart,
+ which impacted new multicast sessions. This occurred due to an age-out
+ process triggered by unicast graceful restart conditions.
+
+ |
+
|
+ PAN-295951
+ |
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where
+ CLI outputs incorrectly included XML formatting.
+
+ |
+
|
+ PAN-295944
+ |
+
+
+ Fixed an issue where static routes remained active in the FIB and RIB
+ even when the associated physical port interface was down, which
+ resulted in traffic being incorrectly routed through a non-operational
+ interface.
+
+ |
+
|
+ PAN-295899
+ |
+
+
+ Fixed an issue where DNS resolution failed on Linux machines running
+ GlobalProtect client version 6.2.6 when connected with DNS Security
+ enabled. This occurred because the firewall incorrectly discarded DNS
+ packets when processing multiple DNS requests or responses over the
+ same session, even when no malicious verdict was received.
+
+ |
+
|
+ PAN-295854
+ |
+
+
+ Fixed an issue where the firewall generated two URL logs for a single
+ session.
+
+ |
+
|
+ PAN-295838
+ |
+
+
+ Fixed an issue on IKEv1 tunnels where, if the peer IKE gateway was
+ unreachable, the IKE Phase-1 Security association (SA) was not cleared
+ by DPD until Phase-2 rekeying occurred or until it was manually
+ cleared via the CLI because the DPDs were not sent accurately
+ according to the configured interval due to a miscalculation of the
+ DPD timer. This resulted in the tunnel taking longer than expected to
+ recover.
+
+ |
+
|
+ PAN-295812
+ |
+
+
+ Fixed an issue where the throughput data on the Switch Card Module
+ (SCM) was not accurately reported. This issue affected Standard SC
+ USABN and USABN-2 when using Direct-IO deployment.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ Addressed a memory leak issue under sc3 and automatic commit recovery
+ (ACR) code path.
+
+ |
+
|
+ PAN-295802
+ |
+
+
+ Fixed an issue where a memory leak related to the
+ configd
+ process occurred.
+
+ |
+
|
+ PAN-295796
+ |
+
+
+ Fixed an issue where the firewall intermittently failed to forward
+ VXLAN GARP packets, which led to connectivity issues for wireless
+ clients in environments that used VXLAN tunnels for wireless access
+ points.
+
+ |
+
|
+ PAN-295766
+ |
+
+
+ (VM-Series firewalls in HA configurations only)
+ Fixed an issue where Panorama displayed incorrect packet buffer values
+ on the web interface and the CLI.
+
+ |
+
|
+ PAN-295728
+ |
+
+
+ Fixed an issue where configuring an OSPFv2 NSSA area range caused
+ OSPF-learned routes to become unreachable due to the incorrect
+ installation of a discard route when the NSSA range prefix matched an
+ existing OSPF route.
+
+ |
+
|
+ PAN-295662
+ |
+
+
+ Fixed an issue where Panorama displayed the URL instead of the file
+ name for vulnerability threat logs fetched from the Logging Service.
+
+ |
+
|
+ PAN-295644
+ |
+
+
+ Fixed an issue where Strata Logging Service (SLS) log forwarding
+ streams intermittently displayed as inactive.
+
+ |
+
|
+ PAN-295586
+ |
+
+
+ Fixed an issue where, after committing changes to a Certificate
+ Profile or other global configurations without any making changes to
+ the virtual system (vsys), the Data Redistribution include/exclude
+ lists were ignored on the firewall. This resulted in the firewall
+ receiving and processing User-ID information from all sources.
+
+ |
+
|
+ PAN-295578
+ |
+
+
+ Fixed an issue where GlobalProtect HIP data file download and
+ installation failed with the error message
+ An error occurred while processing request. Please try again after
+ some time or contact support
+ or No ETAG from response due to a
+ script exiting prematurely.
+
+ |
+
|
+ PAN-295560
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors,
+ tunnel logs were not visible in Panorama or Splunk even though traffic
+ and threat logs were received.
+
+ |
+
|
+ PAN-295484
+ |
+
+
+ Fixed an issue where SD-WAN did not generate system logs with
+ timestamps and reasons for degradation of Direct Internet Access
+ paths.
+
+ |
+
|
+ PAN-295470
+ |
+
+
+ Fixed an issue on the firewall where the
+ useridd
+ process continuously increased its memory consumption, which resulted
+ in an OOM condition that caused the firewall to restart.
+
+ |
+
|
+ PAN-295421
+ |
+
+
+ Fixed an issue where the CLI command outputs incorrectly included XML
+ formatting tags.
+
+ |
+
|
+ PAN-295385
+ |
+
+
+ Fixed an issue where syslog forwarding dropped due to FQDN resolution
+ failures.
+
+ |
+
|
+ PAN-295342
+ |
+
+
+ Fixed an issue where the
+ pan_comm
+ process stopped responding due to insufficient time allocated to read
+ file descriptors when processing long messages.
+
+ |
+
|
+ PAN-295257
+ |
+
+
+ Fixed an issue where, after onboarding a firewall to Panorama, IPsec
+ tunnels displayed IKEv2 in Panorama, even though the tunnels were
+ configured with IKEv1 locally on the firewall.
+
+ |
+
|
+ PAN-295245
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding because the client was unavailable.
+
+ |
+
|
+ PAN-295240
+ |
+
+
+ Fixed an issue where the source user field was intermittently missing
+ in traffic logs, even when the IP address-to-user mapping was
+ available. This occurred due to a race condition where the log
+ generation process preceded the creation of the IP address-to-user
+ mapping.
+
+ |
+
|
+ PAN-295221
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors from
+ PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
+ forwarded to a Splunk server over UDP.
+
+ |
+
|
+ PAN-295185
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ a custom administrator role with the permission
+ Network > QoS (Read Only) was
+ unable to create a QoS profile, even when the
+ Policies > QoS (Enabled) and
+ Network Profiles > QoS Profile (Enabled)
+ permissions were also set.
+
+ |
+
|
+ PAN-295095
+ |
+
+
+ Fixed an issue where, when you used a syslog forwarding profile with
+ the CEF format, an additional string was appended to the end of the
+ log message when viewing the log entry from the Universal Forwarder
+ directory.
+
+ |
+
|
+ PAN-294898
+ |
+
+
+ (Panorama appliances only) Fixed an issue
+ where, when performing device software deployment to dedicated log
+ collectors, the Validate option did
+ not display the required software versions. Additionally, attempting
+ to download images to multiple log collectors simultaneously failed.
+
+ |
+
|
+ PAN-294893
+ |
+
+
+ Fixed an issue where firewalls with the
+ Send handshake messages to CTD for inspection
+ setting enabled caused incorrect security policy rules to be matched
+ during the TLS handshake. Additionally, the expected response page for
+ blocked URLs was not displayed.
+
+ |
+
|
+ PAN-294770
+ |
+
+
+ (Firewalls in active/passive HA configurations)
+ Fixed an issue on firewalls where, after failover, certain subnets
+ were missing from the Link State Database, which prevented OSPF routes
+ from being immediately learned due to a Type-7 to Type-5 LSA
+ translation conflict in the ABR when the same LSA was advertised by
+ two peers in the NSSA area.
+
+ |
+
|
+ PAN-294524
+ |
+
+
+ Fixed an issue where firewalls and Panorama management servers were
+ unable to view or download WildFire reports from a WF-500 appliance,
+ resulting in a 401 error in the report tab.
+
+ |
+
|
+ PAN-294379
+ |
+
+
+ Fixed an issue where, when SD-WAN SaaS Application path monitoring
+ failed for all interfaces, the firewall stopped forwarding traffic
+ even if the ISP links and default gateway probing were still active.
+
+ |
+
|
+ PAN-294307
+ |
+
+
+ Fixed an issue on Panorama where a
+ configd
+ SIGSEGV crash occurred when renaming objects within policy rules,
+ objects, or zones.
+
+ |
+
|
+ PAN-294191
+ |
+
+
+ Fixed an issue where BGP did not generate a system log when the number
+ of prefixes received from a peer exceeded the configured threshold,
+ even with the Address Family Identifier and Peer Group settings
+ configured to trigger a warning.
+
+ |
+
|
+ PAN-294179
+ |
+
+
+ Fixed an issue where viewing, refreshing, and comparing config
+ versions in Config Audit caused the
+ configd
+ process to stop responding. If the page loaded successfully, some
+ commit versions displayed incorrect or missing data.
+
+ |
+
|
+ PAN-294161
+ |
+ + + | +
|
+ PAN-294123
+ |
+
+
+ Fixed an issue where the firewall removed all Infrastructure and Audit
+ logs, as well as logdb and search
+ engine quotas, when the configured retention period was reached
+ instead of only removing logs older than the configured retention
+ period.
+
+ |
+
|
+ PAN-293985
+ |
+
+
+ Fixed an issue with the Panorama web interface where admin users were
+ unable to log in and received the error message
+ 504: Gateway Timeout.
+
+ |
+
|
+ PAN-293953
+ |
+
+
+ Fixed an issue where the cellular interface LED indicator incorrectly
+ displayed a green light when the cellular interface was down due to a
+ failed packet data session.
+
+ |
+
|
+ PAN-293879
+ |
+
+
+ Fixed an issue on the firewall where the VM monitor source remained in
+ the Getting All status, which
+ prevented dynamic address groups from updating IP addresses for new
+ EC2 instances. This issue occurred due to a race condition where two
+ threads that simultaneously retrieved IP address tag information from
+ AWS VM monitoring sources became stuck while reading the XML file.
+
+ |
+
|
+ PAN-293877
+ |
+
+
+ (Firewalls with Hub vsys (virtual system) configurations enabled
+ only) Fixed an issue where, when using the Hub vsys feature to
+ redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP
+ policy enforcement failed intermittently on the active secondary
+ firewall. This occurred when traffic destined for specific non-Hub
+ vsys was routed to the active secondary, and the HIP query was not
+ triggered due to an incorrect check for the HIP mask in the Hub vsys.
+
+ |
+
|
+ PAN-293858
+ |
+
+
+ Fixed an issue where the file URL was not displayed on SCM LogViewer
+ when a file was downloaded. This issue affected logs with a subtype of
+ 'file'.
+
+ |
+
|
+ PAN-293848
+ |
+
+
+ Fixed an issue where Panorama failed to push the default value of
+ None for the secondary NTP server
+ address to managed firewalls, resulting in a commit validation error.
+ This occurred even when configuring the secondary NTP server address
+ as None in Panorama's web interface,
+ and affected both newly deployed and long-standing production
+ firewalls after upgrading.
+
+ |
+
|
+ PAN-293847
+ |
+
+
+ Fixed an issue where EAL logs for traffic matching the
+ intrazone-default security rule were not forwarded to the IoT Security
+ portal.
+
+ |
+
|
+ PAN-293825
+ |
+
+
+ Fixed an issue where packets with bad TCP checksums were transmitted
+ even when the
+ Strict TCP/IP checksum option was
+ enabled.
+
+ |
+
|
+ PAN-293708
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when a partial revert operation was
+ performed on a newly added rule in a rulebase that was empty in the
+ running configuration.
+
+ |
+
|
+ PAN-293707
+ |
+
+
+ Fixed an issue where the
+ iotd
+ process failed to install DPI Cloud server FQDN due to a configuration
+ parsing failure, caused by the configuration XML memory buffer not
+ being NULL terminated. This resulted in the accumulation of EAL logs
+ and DLP forwarding being stopped.
+
+ |
+
|
+ PAN-293686
+ |
+
+
+ Fixed an issue where importing a device state file was incorrectly
+ allowed during an existing commit job.
+
+ |
+
|
+ PAN-293673
+ |
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM
+ condition caused by a scheduled log export using FTP to an external
+ FTP server.
+
+ |
+
|
+ PAN-293644
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the
+ configd
+ process stopped responding during an External Dynamic List (EDL)
+ refresh.
+
+ |
+
|
+ PAN-293574
+ |
+
+
+ Fixed an issue on Panorama where Global Find returned incomplete and
+ inconsistent search results.
+
+ |
+
|
+ PAN-293561
+ |
+
+
+ Fixed an issue where users with a custom role-based administrator role
+ were unable to download the GlobalProtect client application via the
+ web interface even when the
+ GlobalProtect Client option was
+ enabled in the admin role profile.
+
+ |
+
|
+ PAN-293533
+ |
+
+
+ Fixed an issue where, in KVM environments, traffic did not work as
+ expected on Mellanox CX5 interfaces during multinic runs.
+
+ |
+
|
+ PAN-293511
+ |
+
+
+ Fixed an issue where renaming a BGP filtering profile in Panorama does
+ not update the corresponding BGP peer group in the virtual router,
+ leading to commit failures.
+
+ |
+
|
+ PAN-293440
+ |
+
+
+ Fixed an issue where setting the
+ logdb-quota for the
+ desum log type to
+ 0 caused the /opt/panlogs
+ partition to reach capacity.
+
+ |
+
|
+ PAN-293428
+ |
+
+
+ Fixed an issue where the interval of IKEv1 Dead Peer Detection (DPD)
+ R-U-THERE packets did not correspond to the configured value in the
+ IKE Gateway profile due to using the value configured for retry
+ instead.
+
+ |
+
|
+ PAN-293297
+ |
+
+
+ Fixed an issue on Panorama where a full push to device groups was
+ initiated instead of a selective push when using
+ Commit and Push Changes Made By in
+ the commit and push.
+
+ |
+
|
+ PAN-293281
+ |
+
+
+ Fixed an issue where the reported throughput and packet rate were
+ higher than the actual interface traffic due to a double counting
+ error.
+
+ |
+
|
+ PAN-293033
+ |
+
+
+ Fixed an issue on Panorama where
+ Push was disabled during a Selective
+ Push operation.
+
+ |
+
|
+ PAN-292980
+ |
+
+
+ Fixed an issue on the web interface where the
+ Connected status for a User-ID agent
+ in a non-User-ID Hub vsys displayed as blank if the same agent was
+ also configured in a User-ID Hub vsys.
+
+ |
+
|
+ PAN-292752
+ |
+
+
+ Fixed an issue where a command injection vulnerability could occur due
+ to improper input sanitization.
+
+ |
+
|
+ PAN-292580
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ the software deployment validation process did not display the
+ required software version for dedicated log collectors (DLCs), and
+ downloading software images to multiple DLCs failed.
+
+ |
+
|
+ PAN-292539
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the firewall generated incomplete or corrupted tech support files
+ (TSF) due to high disk usage on the management plane.
+
+ |
+
|
+ PAN-292529
+ |
+
+
+ Fixed an issue where HA configuration synchronization failed between
+ HA firewalls due to an empty interface node present only in the
+ passive firewall's running-config.xml file.
+
+ |
+
|
+ PAN-292471
+ |
+
+
+ Fixed an issue where the default route (0.0.0.0/0) advertised via the
+ Originate Default Route in BGP AFI
+ profiles did not appear in the output of the
+ show advanced-routing bgp peer advertised-routes
+ CLI command, even though it was being sent to the BGP peer.
+
+ |
+
|
+ PAN-292447
+ |
+
+
+ Fixed an issue where Panorama did not display data in the
+ Feature Adoption tab in Strata Cloud
+ Manager due to the system creating and deleting a CLI user for each
+ interval instead of reusing a permanent CLI user for telemetry.
+
+ |
+
|
+ PAN-292393
+ |
+
+
+ Fixed an issue where TFTP file transfers intermittently timed out in
+ active-active HA pairs when the TFTP control channel was processed by
+ one firewall and the data channel was processed by the other. This
+ occurred because the firewall receiving the data channel failed to
+ match the predicted session due to asynchronous processing of HA
+ messages.
+
+ |
+
|
+ PAN-292285
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where network outages of approximately 30 seconds
+ occurred after a failover due to a delay in establishing the BGP
+ connection between the new active firewall and one of its peers and a
+ second delay in advertising prefixes learned from the firewall to
+ another peer.
+
+ |
+
|
+ PAN-292242
+ |
+
+
+ Fixed an issue on M-200 and logging appliances where traffic logs were
+ intermittently truncated when forwarded using a TCP syslog
+ configuration. This issue occurred during the log forwarding stage due
+ to intermittent syslog drops caused by exceeding the forwarding queue
+ capacity.
+
+ |
+
|
+ PAN-292228
+ |
+
+
+ Fixed an issue where, after configuring dual stack GlobalProtect with
+ both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with
+ the error message
+ flow-basic error; packet dropped, tunnel resolution failure.
+
+ |
+
|
+ PAN-292079
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ the data on scheduled SaaS Application Usage Reports was different
+ than the data on on-demand reports generated via
+ Run Now.
+
+ |
+
|
+ PAN-292019
+ |
+
+
+ Fixed an issue on the Panorama web interface where cloud applications
+ were not displayed under
+ Objects > Applications after a
+ new content upgrade and Cloud App Catalog download, and were only
+ visible in application groups, security policy rules, and the CLI.
+
+ |
+
|
+ PAN-291984
+ |
+
+
+ Fixed an issue where SSH/SFTP traffic was intermittently blocked by
+ URL filtering due to the firewall incorrectly applying URL categories
+ from previous sessions.
+
+ |
+
|
+ PAN-291945
+ |
+
+
+ Fixed an issue on PA-5220 firewalls where denied traffic logs
+ incorrectly displayed a byte count of 0. This occurred because the
+ bytes_sent value was stored in the most significant bits of
+ u_bytes_sent, resulting in a zero value when a small value was
+ assigned to u_bytes_sent.
+
+ |
+
|
+ PAN-291940
+ |
+
+
+ Fixed an issue where the firewall established multiple TCP connections
+ to a syslog server, which caused logs to be dropped. This occurred
+ because the firewall established a new TCP session for each transfer
+ and the sessions were not closed, which resulted in a continuous
+ increase in connections over time.
+
+ |
+
|
+ PAN-291915
+ |
+
+
+ Fixed an issue on the firewall where the PDT process experienced a
+ memory leak due to frequent dumping of fabric traffic statistics,
+ which resulted in high CPU utilization and instability.
+
+ |
+
|
+ PAN-291804
+ |
+
+
+ Fixed an issue on Panorama where deleting objects resulted in errors
+ indicating references in Security policy rules.
+
+ |
+
|
+ PAN-291792
+ |
+
+
+ (PA-7050 firewalls on vwire instances only)
+ Fixed an issue where Bidirectional Forwarding Detection (BFD) echo
+ packets were dropped due to the firewall dropping packets with the
+ same source and destination IP addresses.
+
+ |
+
|
+ PAN-291781
+ |
+
+
+ Fixed an issue on Panorama where the CLI command
+ show ntp displayed the error
+ message
+ server error: op command for client dagger timed out as client is
+ not available
+ even when connectivity to the NTP server was active.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ Fixed an issue where during a commit, the firewall experienced an
+ out-of-memory (OOM) condition due to a memory leak and displayed an
+ error message. This issue caused the device to stop responding and
+ reboot unexpectedly.
+
+ |
+
|
+ PAN-291661
+ |
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after
+ an upgrade, Elasticsearch intermittently entered into a Red state
+ before automatically recovering.
+
+ |
+
|
+ PAN-291653
+ |
+
+
+ Fixed an issue where the GlobalProtect host ID field was
+ intermittently blank in traffic logs on Prisma Access, even when the
+ user was connected and had the correct host ID information. This
+ occurred when the IP address to host ID entry expired and the entry
+ was re-inserted without the dataplane flag being set.
+
+ |
+
|
+ PAN-291650
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to an OOM
+ condition.
+
+ |
+
|
+ PAN-291635
+ |
+
+
+ Fixed an issue where cookie surrogate cache entries remained
+ unresolved after an
+ idmgr
+ process reset due to the request not being retransmitted. This
+ occurred because the timestamp in the cache entry was refreshed even
+ when the UID was 0, which prevented the retransmission of the request
+ if the initial response was not received.
+
+ |
+
|
+ PAN-291247
+ |
+
+
+ Fixed an issue where checksum values changed when downloading files
+ through TFTP on firewalls using subinterfaces.
+
+ |
+
|
+ PAN-291174
+ |
+
+
+ Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
+ did not work when connected through GlobalProtect due to the firewall
+ blocking 200 OK responses. This occurred because of incorrect NAT
+ translations for the 200 OK message from the server.
+
+ |
+
|
+ PAN-291067
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process periodically exceeded its virtual memory limit and restarted,
+ which led to intermittent outages.
+
+ |
+
|
+ PAN-291009
+ |
+
+
+ Fixed an issue where, after a web server returned a 401 or 403 error,
+ the firewall was unable to decrypt HTTP/2 traffic, and the firewall
+ rejected all subsequent streams from the client.
+
+ |
+
|
+ PAN-290954
+ |
+
+
+ Fixed an issue where the web server used a low HTTP Strict Transport
+ Security (HSTS) max-age value of 86400 seconds for the
+ log.query.expression.js.php page.
+
+ |
+
|
+ PAN-290948
+ |
+
+
+ Fixed an issue where the proxy hid the Cache-Control header, which
+ prevented context switching.
+
+ |
+
|
+ PAN-290938
+ |
+
+
+ Fixed an issue where multiple memory leaks occurred related to the
+ configd
+ process.
+
+ |
+
|
+ PAN-290851
+ |
+
+
+ Fixed an issue where the Agent User Override Key was incorrectly
+ available for configuration on Panorama management servers when
+ running in FIPS-CC mode.
+
+ |
+
|
+ PAN-290783
+ |
+
+
+ Fixed an issue where the
+ debug dataplane nat sync-ippool
+ command may not accurately account for all allocated ports or
+ display/sync leaks when multiple NAT rules use the same IP pool. This
+ could result in inaccurate reporting of leaked ports. The fix modifies
+ the implementation to directly compare the original pool against the
+ temporary pool across all vsys.
+
+ |
+
|
+ PAN-290728
+ |
+
+
+ Fixed an issue where modifying an interface IP address on an existing
+ vsys caused a default vsys1 to be
+ created, which led to commit failures due to the maximum supported
+ number of vsys being reached.
+
+ |
+
|
+ PAN-290681
+ |
+
+
+ Fixed an issue on Panorama and Panorama managed firewalls where
+ template settings reverted during a device group push when
+ Include Device and Network Templates
+ was checked, even if no changes were made to the template. This caused
+ the SAML IDP server profile certificate to revert to an older, invalid
+ certificate, and resulted in GlobalProtect users being unable to
+ authenticate via SAML.
+
+ |
+
|
+ PAN-290665
+ |
+
+
+ Fixed an issue with firewalls enabled with Security profiles where
+ certain traffic conditions caused high dataplane CPU utilization and
+ packet buffer exhaustion, which caused LACP flapping conditions.
+
+ |
+
|
+ PAN-290663
+ |
+
+
+ (Panorama managed firewalls in HA configurations only) Fixed an issue where the firewall did not enforce serial number
+ validation during HA deployment or replacement, which resulted in
+ pairs being established even when the serial numbers configured on
+ Panorama did not not match the serial number of the devices.
+
+ |
+
|
+ PAN-290640
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments in HA
+ configurations only) Fixed an issue where, when an interface was configured with IPv6,
+ the firewall displayed the message
+ Unknown error during validation
+ after the client secret expired, which caused DNS resolution to fail
+ when resolving FQDNs and HA failovers to occur.
+
+ |
+
|
+ PAN-290449
+ |
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports
+ were sent in the same email, only the first attached report was
+ displayed.
+
+ |
+
|
+ PAN-290157
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when filtering in the
+ Config Audit window, which caused
+ Panorama to restart unexpectedly.
+
+ |
+
|
+ PAN-289852
+ |
+
+
+ Fixed an issue where websites did not load when accumulation proxy was
+ enabled.
+
+ |
+
|
+ PAN-289757
+ |
+
+
+ Fixed an issue where policy rule imports were blocked when
+ any was in the source device column,
+ which prevented the use of inbound policy rule recommendations.
+ Additionally, when the source profile name was missing for inbound
+ behaviors, a default policy rule name was not able to be generated.
+
+ |
+
|
+ PAN-289736
+ |
+
+
+ Fixed an issue where partial-revert operations were taking a long
+ time, causing config lock timeout issues and resulting in frequent
+ error messages being displayed:
+ Timed out while getting config lock. Please try again.
+
+ |
+
|
+ PAN-289723
+ |
+
+
+ Fixed an issue where the firewall web interface continuously loaded
+ and not display any output when viewing the Route Table or FIB table
+ (More Runtime Stats). This issue
+ occurred when L3 configurations were added to ethernet and AE
+ interfaces.
+
+ |
+
|
+ PAN-289706
+ |
+
+
+ Fixed an issue where the
+ authd
+ process crashed intermittently on VM-Series firewalls due to
+ authentication sequence failures. The crashes occurred during memory
+ management operations within a library while releasing memory to its
+ central cache.
+
+ |
+
|
+ PAN-289578
+ |
+
+
+ Fixed an issue on Panorama managed firewalls where the source user,
+ source device vendor, source MAC address, and OS version information
+ were not visible in traffic logs and SCM when the user and device
+ access control lists were empty.
+
+ |
+
|
+ PAN-289249
+ |
+
+
+ Fixed an issue where a memory leak occurred on the
+ reportd
+ process when a WildFire update was initiated while device telemetry
+ data collection was in progress. This resulted in an OOM condition.
+
+ |
+
|
+ PAN-289067
+ |
+
+
+ Fixed an issue where, after upgrading Panorama in a High Availability
+ (HA) pair, the configuration logs stopped synchronizing from the
+ primary Panorama to the secondary Panorama. This issue occurred
+ because the log forwarding flag was permanently disabled due to the
+ connection state not being active when the
+ log-fwd-ctrl message was
+ received.
+
+ |
+
|
+ PAN-288938
+ |
+
+
+ Fixed an issue on the Panorama web interface where the search bar
+ suddenly was not displayed, or the filter/clear filter icon moved to
+ the left of the search bar.
+
+ |
+
|
+ PAN-288869
+ |
+
+
+ Fixed an issue where custom administrators with visibility into
+ specific vsys logs were able to view logs for all vsys.
+
+ |
+
|
+ PAN-288388
+ |
+
+
+ Fixed an issue where, after an EDL certificate update or repository
+ migration, authentication failures caused the firewall to not fall
+ back to the last successfully cached EDL entries, which led to policy
+ rules that referenced the EDL to not be enforced.
+
+ |
+
|
+ PAN-288381
+ |
+
+
+ Fixed an issue where data interfaces unexpectedly went down and then
+ up after an HA failover, which caused intermittent traffic disruption.
+
+ |
+
|
+ PAN-288175
+ |
+
+
+ Addressed a stack buffer overflow memory leak under plugin management
+ code path.
+
+ |
+
|
+ PAN-288141
+ |
+
+
+ Fixed an issue where the
+ debug data-plane sync ippool CLI
+ command did not work for Per Destination IP Pool (PDIPP) and caused a
+ memory leak.
+
+ |
+
|
+ PAN-288139
+ |
+
+
+ Fixed an issue where the firewall incorrectly identified ports as
+ leaking when the session was not active even though the ports were
+ allocated.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
+ certain websites weren't accessible when the accumulation proxy was
+ enabled. The proxy did not use the same DF bit state as the original
+ traffic, causing it to be fragmented and dropped elsewhere in the
+ network.
+
+ |
+
|
+ PAN-287782
+ |
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP
+ values from AF11 to CS0 on traffic passing through the firewall, even
+ when QoS policy rules and DSCP rewrite settings were not configured.
+
+ |
+
|
+ PAN-287713
+ |
+
+
+ Fixed an issue on Panorama where, after uninstalling a plugin, commit
+ validation failed with the error message
+ interface '-' is not a valid reference
+ due to cloud service plugin configuration errors.
+
+ |
+
|
+ PAN-287693
+ |
+
+
+ Fixed an issue where Panorama did not use the configured proxy
+ settings to check WildFire private cloud content and instead connected
+ directly to the WildFire device using the management interface. This
+ occurred even when
+ Use Proxy Settings for Private Cloud
+ was enabled.
+
+ |
+
|
+ PAN-287599
+ |
+
+
+ Fixed an issue where the prefix value for a BGP neighbor caused the
+ firewall to leak routes to a different BGP peer.
+
+ |
+
|
+ PAN-287581
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall did not process and transmit HA
+ path monitoring probes received from another HA cluster when the
+ firewall acted as a gateway for internal monitoring IP addresses used
+ in the HA path monitoring group, which caused HA flapping due to path
+ monitoring failures.
+
+ |
+
|
+ PAN-287392
+ |
+
+
+ Fixed the issue on the web interface where
+ ACC graphs displayed
+ No data to display when a filter was
+ applied to Source IP or
+ Destination IP.
+
+ |
+
|
+ PAN-287387
+ |
+
+
+ Fixed an issue on Panorama where API jobs failed with the error
+ message
+ Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a
+ large number of address objects in a single set call.
+
+ |
+
|
+ PAN-287165
+ |
+
+
+ Fixed an issue on the firewall CLI where autocomplete did not work for
+ zones in the
+ clear session all CLI command.
+ Additionally, the CLI was unable to clear sessions for a specific IP
+ subnet.
+
+ |
+
|
+ PAN-287086
+ |
+
+
+ Fixed an issue where PA-3420 firewalls experienced unexpected reboots
+ due to the
+ all_task_7
+ process crashing with signal 6, leading to a non-functional state.
+
+ |
+
|
+ PAN-287034
+ |
+
+
+ Fixed an issue where sequence numbers were skipped for all types of
+ logs on the firewall due to audit logs being generated but not written
+ to disk when Audit Tracking was enabled.
+
+ |
+
|
+ PAN-286865
+ |
+
+
+ Fixed an issue where, when you upgraded log collectors via Panorama
+ (Device Deployment), the software
+ installation on the log collector remained at 0%.
+
+ |
+
|
+ PAN-286297
+ |
+
+
+ Fixed an issue where the firewall did not respond to ARP requests when
+ a subinterface was configured with source address translation using
+ the Translated Address option.
+
+ |
+
|
+ PAN-285758
+ |
+
+
+ Fixed an issue where the firewall web interface became unresponsive
+ while adding a description that contained 1062 bytes of character data
+ in a Security policy rule instead of displaying an error message when
+ the description exceeded the maximum allowed length.
+
+ |
+
|
+ PAN-285208
+ |
+
+
+ Fixed an issue where the firewall did not automatically recover after
+ a machine check exception (MCE) occurred.
+
+ |
+
|
+ PAN-285181
+ |
+
+
+ Fixed an issue where the wifclient ran out of memory when Enhanced
+ Application Logging was enabled and a sudden traffic increase caused a
+ surge in EAL messages sent through WIF.
+
+
+ To use this fix, run the CLI command
+ debug iot eal memory-gc native
+
+ |
+
|
+ PAN-285169
+ |
+
+
+ Fixed an issue on Panorama where Kerberos superusers were unable to
+ edit policy rules because the target device tab was grayed out.
+
+ |
+
|
+ PAN-284801
+ |
+
+
+ Fixed an issue where the OpenConfig plugin was automatically installed
+ on VM Panorama and firewalls after upgrading.
+
+ |
+
|
+ PAN-284417
+ |
+
+
+ Fixed an issue where proxied traffic was shown as decrypted even when
+ no applicable decryption policy rule was configured. Additionally, the
+ show session CLI command and the
+ session browser web interface incorrectly displayed cleartext proxy
+ sessions as decrypted.
+
+ |
+
|
+ PAN-283704
+ |
+
+
+ Fixed an issue where the PAN-OS DoS protection feature by default
+ blacklisted specific IP addresses, which caused outbound traffic
+ domain resolution to fail for clusters.
+
+ |
+
|
+ PAN-283311
+ |
+
+
+ Fixed an issue where log forwarding to all syslog servers failed if
+ one syslog server that used TLS as the protocol became unreachable.
+
+ |
+
|
+ PAN-283237
+ |
+
+
+ Fixed an issue where traffic logs incorrectly displayed the action as
+ allow for traffic matching a
+ Security policy rule configured with the action set to
+ deny. This issue occurred due to the
+ child session being used for policy rule lookup when a configuration
+ update triggered a rematch if the FTP-data application was not in the
+ rule.
+
+ |
+
|
+ PAN-283101
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the
+ show wildfire status CLI command
+ displayed an incorrect maximum file size of 4 KB for WildFire script
+ uploads even though the configured value was different.
+
+ |
+
|
+ PAN-283053
+ |
+
+
+ Fixed an issue where the firewall experienced high disk space
+ utilization, which caused the firewall to become non-functional.
+
+ |
+
|
+ PAN-282961
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly after a commit
+ due to a memory leak related to the
+ rasmgr
+ process and displayed the error message
+ Management server failed to send phase 1 to client l2ctrld
+ before rebooting.
+
+ |
+
|
+ PAN-282956
+ |
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 and later PAN-OS
+ releases where the portal and gateway configuration view did not
+ display rows and columns.
+
+ |
+
|
+ PAN-282687
+ |
+
+
+ Fixed an issue on Panorama where performing a selective revert of
+ configuration changes resulted in all configuration changes being
+ reverted.
+
+ |
+
|
+ PAN-281721
+ |
+
+
+ Fixed an issue where the firewall generated high-severity system
+ alerts indicating that the configuration size exceeded the maximum
+ recommended size, even when the configuration size was within the
+ expected limits.
+
+ |
+
|
+ PAN-281588
+ |
+
+
+ Fixed an issue where packet buffer depletion occurred due to the a
+ high number of
+ tcp_pkt_queued packets when Jumbo
+ was enabled.
+
+ |
+
|
+ PAN-280917
+ |
+
+
+ Fixed an issue on Panorama where the WildFire cloud URL contained an
+ extra period character, which prevented the retrieval of WildFire
+ analysis reports.
+
+ |
+
|
+ PAN-280536
+ |
+
+
+ Fixed an issue where firewalls that were connected to the same Cloud
+ Identity Engine displayed inconsistent group membership information,
+ with some firewalls showing only a subset of users belonging to a
+ group. This occurred due to a full or incremental group sync failure.
+
+
+ This fix introduces a retry mechanism for failed group queries to the
+ Cloud Identity Engine. To use this feature, run the following CLI
+ commands.
+
+
+ To enable the retry mechanism:
+ debug user-id dscd retry-enable on.
+
+
+ To set the retry time:
+ debug user-id dscd retry-time set-time <1-10>. The default value is 5 seconds.
+
+
+ To set the number of retry attempts:
+ debug user-id dscd retry attempts set-attempts <3-10>. The default value is 5 attempts.
+
+
+ To disable the retry mechanism:
+ debug user-id dscd retry-enable off.
+
+
+ Additionally, a system log is now generated when a group sync fails,
+ and you are able to monitor the group sync status with the following
+ CLI commands:
+
+
|
+
|
+ PAN-279699
+ |
+
+
+ Fixed an issue on M-600 line cards where the /var/log/messages file
+ flooded with
+ i40e 0000:81:00.1: ARQ: Unknown event 0x0000 ignored
+ messages, causing the root partition to fill up and prevent PAN-OS
+ upgrades.
+
+ |
+
|
+ PAN-278688
+ |
+
+
+ Fixed an issue where DNS Security threat logs were not displayed on
+ the firewall when packet capture was enabled and the domain name
+ length was 62 characters.
+
+ |
+
|
+ PAN-278611
+ |
+
+
+ Fixed an issue on Panorama where software images were not purged from
+ the /opt/pancfg/mgmt/sw-images folder.
+
+ |
+
|
+ PAN-277971
+ |
+
+
+ Fixed an issue where the PA-5220 firewall reports inaccurate NetFlow
+ statistics for DNS flows after upgrading to PAN-OS 10.2.13.
+
+ |
+
|
+ PAN-277178
+ |
+
+
+ Fixed an issue on Panorama where you were unable to delete a shared
+ object due to the rulebase incorrectly referencing the shared object
+ instead of the device group-specific object when the name was used.
+
+
+ To use this fix, delete the original shared object after cloning it to
+ a device group with the same name.
+
+ |
+
|
+ PAN-276525
+ |
+
+
+ Resolved multiple issues affecting IPSec tunnels using NAT Traversal
+ (NAT-T) when a Dynamic NAT policy was configured (including Dynamic
+ NAT or DIPP). During rekey events, tunnels could go down or flap due
+ to incorrect session handling. This issue impacted both cluster and
+ standalone deployments.
+
+ |
+
|
+ PAN-275050
+ |
+
+
+ Fixed an issue where the Japanese translation for the URL filtering
+ option to add a trailing slash to entries and the device license
+ status error was incorrect.
+
+ |
+
|
+ PAN-274484
+ |
+
+
+ Fixed an issue where commits failed when
+ Data Services was in a Service route
+ configuration was configured with the
+ MGMT interface.
+
+ |
+
|
+ PAN-273487
+ |
+
+
+ Fixed an issue where the
+ distributord
+ process restarted on firewalls in multi-vsys environments with User-ID
+ configured and Panorama as a redistribution client. This occurred when
+ a large volume of IP address-to-user mappings were learned.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where an incorrect ASIC configuration caused silent packet drops or
+ application slowness when receiving a mix of jumbo and non-jumbo
+ packets.
+
+ |
+
|
+ PAN-273028
+ |
+
+
+ Fixed an issue where manual SCP exports from firewalls in FIPS mode
+ were successful to SCP servers that were not FIPS-compliant. This
+ occurred because the manual SCP process did not enforce FIPS security
+ checks.
+
+ |
+
|
+ PAN-272432
+ |
+
+
+ Fixed an issue where Panorama and Cortex Data Lake (CDL) logs
+ displayed incorrect interface names without node IDs for cluster
+ firewalls.
+
+ |
+
|
+ PAN-272245
+ |
+
+
+ Fixed an issue where the
+ dnsproxy
+ process stopped responding due to memory corruption caused by a race
+ condition when the allow list downloading was impacted by a
+ configuration change.
+
+ |
+
|
+ PAN-271507
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the DPC on slot 3 intermittently stopped responding due an
+ all_pktproc
+ restart.
+
+ |
+
|
+ PAN-271239
+ |
+
+
+ Fixed an issue where searching for the GlobalProtect client version
+ browser in Panorama logs returned no results.
+
+ |
+
|
+ PAN-268038
+ |
+
+
+ Fixed an issue where the
+ routed process on Orion-ZTNA NGFW
+ Connectors stopped responding when a destination FQDN path monitor
+ configuration was present and the
+ show routing path-monitor CLI
+ command was executed due to the CLI command handler dereferencing a
+ null pointer without proper validation.
+
+ |
+
|
+ PAN-267965
+ |
+
+
+ (Firewalls on Amazon Web Services (AWS) environments only) Fixed an issue where newly bootstrapped firewalls sent an
+ incorrect, non-DHCP-assigned hostname to the SNMP server. This
+ occurred because the SNMP process referred to a configuration file
+ that was not updated due to a missing configuration commit.
+
+ |
+
|
+ PAN-267614
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected due to high CPU utilization on the
+ mongodb
+ process.
+
+ |
+
|
+ PAN-267450
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding with a SIGSEGV at
+ schedule_report_es_response.
+
+ |
+
|
+ PAN-266843
+ |
+
+
+ Fixed an issue on airgapped firewalls where cloud connection errors
+ flooded the system logs.
+
+ |
+
|
+ PAN-265744
+ |
+
+
+ Fixed an issue where the firewall repeatedly generated false critical
+ alerts due to an Intel firmware issue.
+
+ |
+
|
+ PAN-264762
+ |
+
+
+ Fixed an issue where the firewall showed the status of SFP+ interfaces
+ as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
+ connected.
+
+ |
+
|
+ PAN-263691
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a
+ memory leak in the
+ all_task
+ process.
+
+ |
+
|
+ PAN-262353
+ |
+
+
+ Fixed an issue where, when Panorama was upgraded but log collectors
+ were on an earlier version, logs from a log collector group were not
+ viewable on a Panorama.
+
+ |
+
|
+ PAN-259853
+ |
+
+
+ Fixed an issue where, when the DHCP server was enabled for
+ GlobalProtect, the commit error message was not properly displayed
+ when Any was selected as the source
+ interface in the service router configuration (Device > Setup > Service > Service Router
+ Configuration).
+
+ |
+
|
+ PAN-259785
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process restarted and created a core dump because two threads did not
+ terminate correctly.
+
+ |
+
|
+ PAN-255879
+ |
+
+
+ Fixed an issue where the
+ threat name on the firewall report
+ PDF was blank.
+
+ |
+
|
+ PAN-253504
+ |
+
+
+ Fixed an issue where commits did not return an error message when an
+ invalid Log Forwarding Filter was configured.
+
+ |
+
|
+ PAN-250339
+ |
+
+
+ Added an improvement to automatically clean up idle HTTP connection
+ pools to address an issue where idle connection pools accumulated when
+ a circuit breaker limit was reached, which caused client requests to
+ fail with a 503
+ no_healthy_upstream error.
+
+ |
+
|
+ PAN-248913
+ |
+
+
+ Fixed an issue where the Elasticsearch client certificate was not auto
+ renewed, which caused it to enter a Red state, and logs were not
+ displayed in Panorama.
+
+ |
+
|
+ PAN-242952
+ |
+
+
+ Fixed an issue where high SSL traffic depleted flex memory, which
+ prevented the firewall from revalidating SSLVPN client CAs during
+ configuration pushes.
+
+ |
+
|
+ PAN-238208
+ |
+
+
+ Fixed an issue where the firewall API returned inconsistent responses
+ to a failed call using a valid API key. With this fix, the firewall
+ returns the error
+ Session is invalid if the session is
+ not available for the cookie.
+
+ |
+
|
+ PAN-237294
+ |
+
+
+ Fixed an issue where the interface rate counter intermittently went to
+ zero frequently.
+
+ |
+
|
+ PAN-209516
+ |
+
+
+ Fixed an issue where, when creating an interface, an error occurred
+ when you clicked OK without
+ providing a value in the Tag field
+ even though the field was not displayed as mandatory.
+
+ |
+
|
+ PAN-185731
+ |
+
+
+ Fixed an issue where the firewall was unable to parse the URL path and
+ host when the host header was located in a different packet, which
+ resulted in the firewall not logging the URL path in the first packet.
+
+
+ The fix is disabled by default. The following CLI commands can be used
+ to enable/disable the feature:
+
+
|
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-263349
+ |
+
+
+ Fixed an error in the bundling of software components.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-258702
+ |
+
+
+ (WF-500 appliances only) Fixed an issue where
+ the
+ varrcvr
+ process stopped responding when files were being forwarded to the
+ WildFire cloud.
+
+ |
+
|
+ PAN-255773
+ |
+
+
+ Fixed an issue where errors related to applications in
+ Content-preview caused commit
+ failures.
+
+ |
+
|
+ PAN-248508
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where the firewall did not perform MSS clamping when
+ GWLB endpoints were mapped to static subinterfaces.
+
+ |
+
|
+ PAN-247099
+ |
+
+
+ Fixed an issue where the firewall decrypted traffic unexpectedly when
+ the client hello was spread across multiple packets.
+
+ |
+
|
+ PAN-251929
+ |
+
+
+ Fixed an issue where inbound decryption did not work when FIPS self
+ tests were turned on.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ PAN-247230
+ |
+
+
+ Fixed an issue where the syslog forwarding configuration did not
+ include the full path for Security policy rules.
+
+ |
+
|
+ PAN-259997
+ |
+
+
+ (PA-3410, PA-3420, and PA-3430 firewalls only)
+ Fixed an issue where the install failed when upgrading from PAN-OS
+ 10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number
+ of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-273215
+ |
+
+
+ Fixed an issue where a syntax error in the index generation script
+ caused a high management plane CPU load after upgrading.
+
+ |
+
|
+ PAN-271613
+ |
+
+
+ Fixed an issue where configuration pushes from Panorama to the
+ firewall failed due to an OOXML commit error.
+
+ |
+
|
+ PAN-269404
+ |
+
+
+ Fixed an issue where the firewall did not reset the maximum latency
+ timer for hold mode.
+
+ |
+
|
+ PAN-268823
+ |
+
+
+ Fixed an issue where
+ Monitor > Log Display did not
+ display all logs when you applied a filter.
+
+ |
+
|
+ PAN-264549
+ |
+
+
+ Fixed an issue where, after modifying a policy rule on Panorama,
+ pushes to the Cloud NGFW failed with the error
+ saas-user-list unexpected here.
+
+ |
+
|
+ PAN-259078
+ |
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and
+ the following error message was displayed:
+ Error 500: Internal Server Error.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-263387
+ |
+
+
+ Fixed an issue where the firewall web interface was blank after
+ logging in.
+
+ |
+
|
+ PAN-263226
+ |
+
+
+ Fixed an issue where decryption based traffic failed on Explicit Proxy
+ nodes.
+
+ |
+
|
+ PAN-262593
+ |
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome
+ web browser on Secure Web Gateway (SWG) nodes.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred when
+ App-ID stopped responding caused the firewall to restart.
+
+ |
+
|
+ PAN-262013
+ |
+
+
+ Fixed an issue where Prisma Access mobile users did not receive
+ no such name DNS responses from the
+ firewall and were timed out.
+
+ |
+
|
+ PAN-261991
+ |
+
+
+ Fixed an issue where traffic that did not match a decryption policy
+ rule, or matched a no-decrypt policy rule, failed when accumulation
+ proxy was enabled and a Zone Protection profile was configured with
+ syn-cookies enabled.
+
+ |
+
|
+ PAN-261917
+ |
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were
+ decrypted in the traffic log when using a Google Chrome browser with
+ PQC enabled.
+
+ |
+
|
+ PAN-261797
+ |
+
+
+ Fixed an issue where fragmented IP packets were dropped silently.
+
+ |
+
|
+ PAN-261270
+ |
+
+
+ Fixed an issue where the firewall decremented the TTL/Hop limit for
+ BGPv6 packets by 1 after IPSec decryption.
+
+ |
+
|
+ PAN-260059
+ |
+
+
+ Fixed an issue where
+ Device Telemetry Regions did not
+ show up with the latest content due to content files not being parsed
+ for the region list when Telemetry was turned off.
+
+ |
+
|
+ PAN-259964
+ |
+
+
+ Fixed an issue where the firewall was not able to handle a high
+ traffic load, which caused some logs to be lost.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a
+ web browser and displayed the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-259733
+ |
+
+
+ Fixed an issue where a custom report was not deleted on Panorama when
+ expected.
+
+ |
+
|
+ PAN-259480
+ |
+
+
+ Fixed an issue where the
+ varrcvr
+ process stopped responding after running out of memory due to how the
+ process queued and dequeued files for WildFire file forwarding when a
+ WildFire Analysis Security profile was enabled.
+
+ |
+
|
+ PAN-259473
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the chassis shut down when FAN1 was removed.
+
+ |
+
|
+ PAN-259151
+ |
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which
+ caused configuration pushes to fail with the error
+ Number of address groups exceed platform capacity.
+
+ |
+
|
+ PAN-258442
+ |
+
+
+ Fixed an issue where changes made to the split tunnel configuration on
+ the Prisma Access gateway were not reflected on the GlobalProtect
+ client.
+
+ |
+
|
+ PAN-257957
+ |
+
+
+ (Firewalls and Panorama appliances in FIPS-CC mode only) Fixed an issue where the
+ authd
+ process restarted if RADIUS PAP/CHAP authentication was used.
+
+ |
+
|
+ PAN-257925
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the CLI command
+ show system setting ctd state did
+ not work as expected.
+
+ |
+
|
+ PAN-257624
+ |
+
+
+ Fixed an issue where the firewall web interface was blank after
+ logging in.
+
+ |
+
|
+ PAN-257615
+ |
+
+
+ Fixed an issue on Panorama where logs did not display or displayed
+ intermittently on the web interface.
+
+ |
+
|
+ PAN-257563
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ component for SASE and MCW displayed incorrect zones in the traffic
+ flow.
+
+ |
+
|
+ PAN-257515
+ |
+
+
+ Fixed an issue where Possible Domain Fronting Detection for HTTP/2
+ generated false positives. With this change, domain fronting is
+ limited to HTTP/1.
+
+ |
+
|
+ PAN-257462
+ |
+
+
+ Fixed an issue related to the
+ varrcvr
+ process where the management plane CPU was higher than expected.
+
+ |
+
|
+ PAN-257432
+ |
+
+
+ Fixed an issue on Panorama where the
+ reportd
+ process stopped responding, which caused a log query issue.
+
+ |
+
|
+ PAN-257390
+ |
+
+
+ (PA-5250 firewalls only) Fixed an issue where
+ the
+ logrcvr
+ process stopped responding due to a segmentation fault.
+
+ |
+
|
+ PAN-257355
+ |
+
+
+ Fixed an issue where a false positive HTTP/TLS evasion alert was
+ generated when the domain had DNS load balance.
+
+ |
+
|
+ PAN-257197
+ |
+
+
+ Fixed an issue where ifType and
+ ifSpeed were not populated in
+ asynchronous mode of SNMP operations.
+
+ |
+
|
+ PAN-256939
+ |
+
+
+ Fixed an issue on the firewall where disk space was low in
+ /opt/pancfg/, which caused
+ dynamic content installation to fail.
+
+ |
+
|
+ PAN-256765
+ |
+
+
+ Fixed an issue where you were unable to push variables from Panorama
+ in service routes for non-cluster templates.
+
+ |
+
|
+ PAN-256738
+ |
+
+
+ (VM-Series firewalls in HA configurations only)
+ Fixed an issue where BGP routes from the active firewall were lost
+ when the passive firewall was rebooted.
+
+ |
+
|
+ PAN-256666
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when
+ Commit and Push operations were
+ performed on multiple device groups.
+
+ |
+
|
+ PAN-256385
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ communication was broken between the management plane and the
+ dataplane when Anti-Spyware profiles were configured in a Security
+ policy rule.
+
+ |
+
|
+ PAN-256327
+ |
+
+
+ (Panorama virtual appliances on Microsoft Azure environments
+ only) Fixed an issue where the
+ logd
+ process repeatedly restarted due to a buffer overflow when generating
+ a traffic summary from a traffic log.
+
+ |
+
|
+ PAN-256249
+ |
+
+
+ Fixed an issue on the web interface that occurred when changing the
+ pre-shared key to a variable (Network > Network Profiles > IKE Gateways).
+
+ |
+
|
+ PAN-256223
+ |
+
+
+ Fixed an issue where device telemetry log collection filled the root
+ partition.
+
+ |
+
|
+ PAN-256181
+ |
+
+
+ Fixed an issue where the management interface and front panel port
+ interface statistics were not populated in asynchronous mode of SNMP
+ operations.
+
+ |
+
|
+ PAN-255895
+ |
+
+
+ Fixed an issue where Panorama administrators with the
+ Panorama Administrator dynamic
+ administrator type were not able to create or modify BGP timer
+ profiles or BGP dampening profiles.
+
+ |
+
|
+ PAN-255820
+ |
+
+
+ Fixed an issue where the WildFire signature generation check box in
+ Panorama did not register a change in the configuration.
+
+ |
+
|
+ PAN-255711
+ |
+
+
+ Fixed an issue where the firewall displayed a malformed request error
+ when selecting a custom format and clicking
+ OK on the configuration window due
+ to the log type
+ Correlation incorrectly being
+ displayed (Device > Log Setting - Correlation > Syslog Server Profile
+ > Custom Log Format > Correlation).
+
+ |
+
|
+ PAN-255611
+ |
+
+
+ Fixed an issue on the firewall where newly added routes were not
+ automatically sorted based on subnets when added to a redistribution
+ profile.
+
+ |
+
|
+ PAN-255441
+ |
+
+
+ Fixed an issue where BGP-ARE routes were not advertised due to a peer
+ route map filter.
+
+ |
+
|
+ PAN-255396
+ |
+
+
+ Fixed an issue where, when using serial number and IP address
+ authentication, and multiple gateways were configured, the portal
+ returned the last gateway in the list and disregarded the satellite
+ assignment by serial number.
+
+ |
+
|
+ PAN-255391
+ |
+
+
+ Fixed an issue where the firewall was unable to filter logs using the
+ ISO 8601 timestamp format after upgrading to PAN-OS 11.0.4 or a later
+ release.
+
+ |
+
|
+ PAN-255266
+ |
+
+
+ Fixed an issue where you were unable to clone a template stack with
+ the Pre-Shared Key variable.
+
+ |
+
|
+ PAN-255252
+ |
+
+
+ Fixed an issue where Panorama administrators with the type Dynamic
+ were unable to create, modify, or delete BGP Dampening profiles.
+
+ |
+
|
+ PAN-255163
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the system database key that stored the configuration status of the
+ dataplane pod was not updated frequently.
+
+ |
+
|
+ PAN-254826
+ |
+
+
+ Fixed an issue where the firewall stopped responding when processing
+ traffic.
+
+ |
+
|
+ PAN-254629
+ |
+
+
+ Fixed an issue on the Management Processing Card where excessive logs
+ were generated for an error.
+
+ |
+
|
+ PAN-254621
+ |
+
+
+ Fixed an issue where the firewall frequently rebooted due to the
+ brdagent
+ process not responding.
+
+ |
+
|
+ PAN-254577
+ |
+
+
+ Fixed an issue where a core file was created on the Log Forwarding
+ Card (LFC) due to a third-party software issue.
+
+ |
+
|
+ PAN-254425
+ |
+
+
+ Fixed an issue where the firewall did not restrict port 9905 to
+ localhost.
+
+ |
+
|
+ PAN-254423
+ |
+
+
+ Fixed an issue on Panorama where custom role-based admin users with
+ read-only access were able to make changes to configurations.
+
+ |
+
|
+ PAN-254422
+ |
+
+
+ Fixed an issue where the firewall required a restart when an SD-WAN
+ policy rule was pushed from Panorama.
+
+ |
+
|
+ PAN-254411
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding, which caused
+ ERR_CONNECTION_REFUSED error
+ messages to be displayed in admin sessions.
+
+ |
+
|
+ PAN-254373
+ |
+
+
+ Fixed an issue where the firewall did not handle error code 500
+ responses from the WildFire cloud correctly.
+
+ |
+
|
+ PAN-254241
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a high
+ number of SD-WAN probes being sent.
+
+ |
+
|
+ PAN-254181
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ firewall pods and application pods repeatedly restarted.
+
+ |
+
|
+ PAN-253829
+ |
+
+
+ Fixed an issue where the CLI command
+ show running security-policy
+ timed out when the Security policy was large.
+
+ |
+
|
+ PAN-253819
+ |
+
+
+ Fixed an issue where a
+ User Activity Report was not
+ generated by Run Now or not emailed
+ through the Email Schedule when the
+ locale setting was not English.
+
+ |
+
|
+ PAN-253452
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to connect to the
+ GlobalProtect gateway and received the error
+ Gateway does not exist.
+
+ |
+
|
+ PAN-253317
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where you were unable to log in to the firewall
+ after a private data reset.
+
+ |
+
|
+ PAN-252867
+ |
+
+
+ Fixed an issue where an incorrect memory reference in an IoT API
+ caused the wifclient process to
+ stop responding.
+
+ |
+
|
+ PAN-252517
+ |
+
+
+ Fixed an issue where SNMP failed to respond to multiple Object
+ Identifier (OID) queries in a single SNMP GET request.
+
+ |
+
|
+ PAN-252411
+ |
+
+
+ Fixed an issue where, when log files were purged from the rollup
+ summary logs, the summary report still used the rollup summary data,
+ which resulted in the summary report displaying less data.
+
+ |
+
|
+ PAN-251909
+ |
+
+
+ Fixed an issue where a Panorama pushed configuration failed to commit
+ on the firewall due to the address object referenced by the interface
+ not being shared with the firewall.
+
+ |
+
|
+ PAN-251732
+ |
+
+
+ Fixed an issue where Oracle traffic over generic routing encapsulation
+ (GRE) was dropped when the traffic passed through the firewall using
+ ttunnel content inspection (TCI).
+
+ |
+
|
+ PAN-251676
+ |
+
+
+ Fixed an issue on Panorama appliances in large-scale deployments where
+ configd
+ process core files consumed more space in the /opt/panlogs partition
+ than was available.
+
+ |
+
|
+ PAN-251661
+ |
+
+
+ Fixed an issue where a memory overwrite occurred during HTTP/2 header
+ inflation.
+
+ |
+
|
+ PAN-251656
+ |
+
+
+ Fixed an issue where enabling lockless QoS caused traffic disruptions.
+
+ |
+
|
+ PAN-251655
+ |
+
+
+ Fixed an issue where the firewall stopped forwarding files to the
+ WildFire cloud and a restart of the
+ varrcvr
+ process was required.
+
+ |
+
|
+ PAN-251446
+ |
+
+
+ Fixed an issue where a critical system log was generated for a SAML
+ authenticated user whose username length was greater than 32
+ characters.
+
+ |
+
|
+ PAN-251047
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process logs were flooded with an error message related to service
+ profiles.
+
+ |
+
|
+ PAN-250948
+ |
+
+
+ Fixed an issues where GlobalProtect on Microsoft Windows devices did
+ not attempt CNAME resolution for sinkhole.paloaltonetworks.com.
+
+ |
+
|
+ PAN-250909
+ |
+
+
+ Fixed an issue where, when creating a Security policy rule via the
+ CLI, validation was not implemented and the same object was able to be
+ referenced in the policy twice.
+
+ |
+
|
+ PAN-250787
+ |
+
+
+ Fixed an issue where network issues between the firewall and the log
+ collector caused
+ logrcvr
+ process memory exhaustion.
+
+ |
+
|
+ PAN-250597
+ |
+
+
+ Fixed an issue where Global Find for a Panorama pushed shared address
+ object displayed Others in the
+ results.
+
+ |
+
|
+ PAN-250462
+ |
+
+
+ Fixed an issue where the session logout time for the firewall was
+ incorrect when viewing via context switch from Panorama.
+
+ |
+
|
+ PAN-250419
+ |
+
+
+ Fixed an issue where XML API explorer inserted a plus (+) character in
+ the Xpath when a space was used in the object name.
+
+ |
+
|
+ PAN-250405
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue on
+ the firewall where
+ websrvr related messages
+ displayed repeatedly.
+
+ |
+
|
+ PAN-250311
+ |
+
+
+ Fixed an issue where the domain was not mapped when using certificate
+ profile authentication on GlobalProtect.
+
+ |
+
|
+ PAN-250258
+ |
+
+
+ Fixed an issue on the firewall where the Certificate Name character
+ limit was 31 characters instead of 63 characters.
+
+ |
+
|
+ PAN-250127
+ |
+
+
+ Fixed an issue where commits failed with the error message
+ set is not allowed when
+ default originate was enabled with a
+ route map that included a set action.
+
+ |
+
|
+ PAN-250024
+ |
+
+
+ Fixed an issue related to the
+ reportd
+ process where you were unable to log in to Panorama via the web
+ interface and received a 500 error.
+
+ |
+
|
+ PAN-250021
+ |
+
+
+ Fixed an issue where
+ Change Summary and
+ Preview Changes displayed
+ inconsistent information when changing an admin user password.
+
+ |
+
|
+ PAN-250005
+ |
+
+
+ Fixed an issue where the Advanced Routing migration script did not
+ migrate BGP import policy rules correctly when the policy rule was
+ configured with an exact match condition.
+
+ |
+
|
+ PAN-249855
+ |
+
+
+ Fixed an issue where the firewall dropped the active source of the
+ Multicast source via MSDP when they were not received from the MSDP
+ peer firewall.
+
+ |
+
|
+ PAN-249404
+ |
+
+
+ Fixed an issue on the Panorama web interface where the commit lock for
+ a device group and template with the same name was not visible.
+
+ |
+
|
+ PAN-249266
+ |
+
+
+ Fixed an issue where the
+ config
+ process virtual memory was exceeded due to delays in post-commit
+ processing.
+
+ |
+
|
+ PAN-248975
+ |
+
+
+ Fixed an issue on the Panorama web interface where no content was
+ displayed after logging in.
+
+ |
+
|
+ PAN-248841
+ |
+
+
+ Fixed an issue where the SSL response time was not displayed in the
+ GlobalProtect log.
+
+ |
+
|
+ PAN-248542
+ |
+
+
+ Fixed an issue where the NPB policy type was missing from
+ configuration policy updates, which caused error messages to
+ incorrectly display in the system logs.
+
+ |
+
|
+ PAN-248211
+ |
+
+
+ Fixed an issue on Panorama where commits failed when Advanced Routing
+ was enabled.
+
+ |
+
|
+ PAN-248130
+ |
+
+
+ Fixed an issue where the
+ AND operation under a Dynamic
+ Address Group comparison did not work after upgrading the AWS plugin
+ to 3.0.1.
+
+ |
+
|
+ PAN-247857
+ |
+
+
+ (PA-7050 firewalls in HA configurations only)
+ Fixed an issue on the firewall where a dataplane process restarted
+ when updating the routing table.
+
+ |
+
|
+ PAN-247754
+ |
+
+
+ Fixed an issue where successful
+ Commit and Push operations performed
+ by SAML authenticated users were not reflected on the firewall.
+
+ |
+
|
+ PAN-247575
+ |
+
+
+ Fixed an issue where the error message
+ import of <issuecert> failed. Please check the validity of
+ the key pair and try again
+ for unmatched keys for EC certificates.
+
+ |
+
|
+ PAN-247426
+ |
+
+
+ Fixed an issue where a proxy server was used for External Dynamic List
+ communication even when the dataplane interface was configured through
+ service routes.
+
+ |
+
|
+ PAN-247257
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-247230
+ |
+
+
+ Fixed an issue where the syslog forwarding configuration did not
+ include the full path for Security policy rules.
+
+ |
+
|
+ PAN-246772
+ |
+
+
+ Fixed an issue on the firewall where the dataplane went down due to a
+ path monitor failure caused by an out-of-memory (OOM) condition
+ related to the
+ pan_task
+ process.
+
+ |
+
|
+ PAN-246769
+ |
+
+
+ Fixed an issue on Panorama where deny logs were not displayed.
+
+ |
+
|
+ PAN-246220
+ |
+
+
+ Fixed an issue where a dynamic peer connection was rejected when using
+ an FQDN for the peer address.
+
+ |
+
|
+ PAN-246056
+ |
+
+
+ Fixed an issue where single TLS session packets were sent to multiple
+ firewalls when off-loading was enabled and ECMP was disabled.
+
+ |
+
|
+ PAN-245892
+ |
+
+
+ Fixed an issue where Log Filtering (Monitor > Logs) was slower than expected.
+
+ |
+
|
+ PAN-245556
+ |
+
+
+ Fixed an issue where the firewall dropped VxLAN packets via v-wire
+ after upgrading to PAN-OS 10.1.10 or a later release, which impacted
+ SMB traffic and resulted in silent packet drops.
+
+ |
+
|
+ PAN-244746
+ |
+
+
+ Fixed an issue where changes committed on Panorama were not reflected
+ on the firewall after a successful push.
+
+ |
+
|
+ PAN-243957
+ |
+
+
+ Fixed an issue where the firewall TLS/SSL service profile exclusion
+ settings were not correctly applied on the captive portal.
+
+ |
+
|
+ PAN-243387
+ |
+
+
+ Fixed an issue where sessions ended with the message
+ resources-unavailable when traffic
+ hit a Security profile.
+
+ |
+
|
+ PAN-243240
+ |
+
+
+ Fixed an issue where the using QoS caused packet buffer utilization to
+ increase exponentially and the
+ PKI POOL DFLT pool depleted until
+ a reboot was performed.
+
+ |
+
|
+ PAN-243098
+ |
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security
+ profiles were configured.
+
+ |
+
|
+ PAN-243081
+ |
+
+
+ Fixed an issue on the firewall where log filtering with special
+ characters in the username incorrectly returned results.
+
+ |
+
|
+ PAN-242958
+ |
+
+
+ Fixed an issue where the firewall intermittently logged
+ connect-agent-failure messages
+ for service connection instances due to bi-directional host ID
+ redistribution.
+
+ |
+
|
+ PAN-242331
+ |
+
+
+ Fixed an issue where Prisma Access remote network firewalls
+ intermittently created incorrect user-to-IP-address mappings.
+
+ |
+
|
+ PAN-242147
+ |
+
+
+ (PA-1410 firewalls only) Fixed an issue where
+ the firewall did not block STP packets when the ports on the connected
+ routers were in access mode.
+
+ |
+
|
+ PAN-241781
+ |
+
+
+ Fixed an issue where partial
+ commit and
+ commit-all operations took more
+ time than expected to create the job ID.
+
+ |
+
|
+ PAN-241044
+ |
+
+
+ Fixed an issue where traffic was denied by the interzone-default
+ policy rule when a Security policy rule with an FQDN destination was
+ configured.
+
+ |
+
|
+ PAN-239246
+ |
+
+
+ Fixed an issue where the CLI command
+ debug user-id dump hip-based-profile-database-entry
+ returned an incorrect value in the output for the
+ total size of hip reports.
+
+ |
+
|
+ PAN-237582
+ |
+
+
+ Fixed an issue where logs were intermittently missing on the log
+ collector due to missing aliases for some indices.
+
+ |
+
|
+ PAN-236497
+ |
+
+
+ Fixed an issue where the firewall was unable to purge expired GTP-U
+ sessions that remained as allocated sessions even after the TTL was
+ expired.
+
+ |
+
|
+ PAN-235110
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ the web interface did not load after an upgrade.
+
+ |
+
|
+ PAN-234560
+ |
+
+
+ Fixed an issue where the daily summary report displayed IPv6 addresses
+ instead of IPv4 addresses.
+
+ |
+
|
+ PAN-232550
+ |
+
+
+ Fixed an issue where SNMPv3 authentication failed when using SHA-512
+ Auth protocol.
+
+ |
+
|
+ PAN-231642
+ |
+
+
+ Fixed an issue on the Panorama web interface where users that were
+ logged in through multiple sessions were able to see an active lock on
+ only one session.
+
+ |
+
|
+ PAN-230326
+ |
+
+
+ Fixed an issue where the Network Packet Broker (NPB) user interface
+ was incorrectly displayed on unsupported platforms.
+
+ |
+
|
+ PAN-226785
+ |
+
+
+ Fixed an issue where accessing websites with HTTP to HTTPS redirect
+ failed via explicit proxy.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-292503
+ |
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP
+ addresses did not display in traffic & threat logs.
+
+ |
+
|
+ PAN-290996
+ |
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS
+ (Connections Per Second) per vsys on firewalls after upgrading to
+ PAN-OS 11.1.6-h3, even when active connections were present.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ Fixed an issue where a memory leak occurred related to the
+ configd
+ process when pushing configurations from Panorama to a firewall. This
+ occurred when the configurations contained shared policy rules.
+
+ |
+
|
+ PAN-287838
+ |
+
+
+ (Panorama appliances only) Fixed an issue on
+ the web interface where resetting the rule hit counter for multiple
+ policy rules failed with the error message
+ Failed to reset rule-hit job.
+
+ |
+
|
+ PAN-287056
+ |
+
+
+ Fixed an issue where BGP export policy rules with next-hop matching
+ failed to block the advertisement of static routes, and the firewall
+ incorrectly matched the egress interface IP address instead of the
+ original next-hop IP address of the static route, which caused the
+ deny rule to fail.
+
+ |
+
|
+ PAN-287023
+ |
+
+
+ Fixed an issue where a large number of logs caused the
+ logrcvr
+ process to stop responding.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ Fixed an issue where ECMP incorrectly balanced sessions across links
+ based on the configured metric, which led to an imbalance in traffic
+ distribution and resulted in traffic assignment shifting
+ disproportionately to routes with lower metrics.
+
+ |
+
|
+ PAN-286306
+ |
+
+
+ Fixed an issue where, when getting transceiver information from ESCC
+ for SFP 25G modules, the transceiver code was incorrectly updated with
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-284117
+ |
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where the
+ vm_agent
+ process restarted after an upgrade.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ Fixed an issue on the firewall that caused commits to fail and the web
+ interface to become inaccessible.
+
+ |
+
|
+ PAN-284003
+ |
+
+
+ Fixed an issue where clients did not receive a valid response when
+ searching a website due to a compression error.
+
+ |
+
|
+ PAN-282391
+ |
+
+
+ (Panorama appliances and Log Collectors only)
+ Fixed an issue where a VLD memory leak caused increased memory use,
+ which resulted in OOM errors.
+
+ |
+
|
+ PAN-282359
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected.
+
+ |
+
|
+ PAN-281649
+ |
+
+
+ Fixed an issue where the index size limit was incorrectly calculated
+ and indices rolled over earlier than expected, which resulted in high
+ memory and OOM errors.
+
+ |
+
|
+ PAN-281509
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ log exports were slower than expected or failed when filtering logs
+ after an upgrade, which resulted in timeouts or delays in displaying
+ logs on the web interface.
+
+ |
+
|
+ PAN-279500
+ |
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric
+ routing environments if the firewall did not see server-to-client
+ (s2c) packets of the TLS handshake.
+
+
+ To use this fix, run the following CLI command:
+ debug dataplane set ssl-decrypt accumulate-client-hello
+ asym-disable yes.
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Fixed an issue where service routes configured to use a data plane
+ interface incorrectly used the management plane interface for traffic
+ transmission. This issue affected syslog and CRL status traffic when a
+ custom service route was not configured.
+
+ |
+
|
+ PAN-278812
+ |
+
+
+ Fixed an issue where authentication to GlobalProtect failed with the
+ error message
+ User not in allowed list.
+
+ |
+
|
+ PAN-278150
+ |
+
+
+ Fixed an issue where the firewall removed the Authentication Key
+ Identifier (AKID) from the certificate during SSL decryption, which
+ caused Python 3.13 to fail with a certificate verification error.
+
+ |
+
|
+ PAN-277417
+ |
+
+
+ Fixed an memory leak issue related to TLS inbound decryption.
+
+ |
+
|
+ PAN-277147
+ |
+
+
+ Fixed an issue where daily scheduled reports were not generated and
+ emailed.
+
+ |
+
|
+ PAN-276920
+ |
+
+
+ Fixed an issue where web-advertisement traffic was not immediately
+ blocked which resulted in pages loading indefinitely.
+
+ |
+
|
+ PAN-276616
+ |
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet
+ were not visible.
+
+ |
+
|
+ PAN-276276
+ |
+
+
+ (PA-450 firewalls only) Fixed an issue where,
+ after an upgrade, data that was excluded using the query builder in a
+ custom report was still visible in the report, and the logs displayed
+ errors related to invalid threat names being queried.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue
+ where, after an upgrade, the firewall was unable to send logs to the
+ Strata Logging Service (SLS) when using a specific proxy server, and
+ the SSL connection status displayed as failed when attempting to
+ forward logs through the web proxy.
+
+ |
+
|
+ PAN-275032
+ |
+
+
+ (M-600 appliances only) Fixed an issue where
+ the Elasticsearch cluster certificate (CC) status displayed with a
+ past expiration date, which caused all shards to be unassigned.
+
+ |
+
|
+ PAN-274671
+ |
+ + + | +
|
+ PAN-272812
+ |
+
+
+ Fixed an issue where SNMP monitoring of tunnel interfaces displayed
+ zero values for received bytes and packets.
+
+ |
+
|
+ PAN-271810
+ |
+
+
+ Fixed an issue where auto-negotiation advertised and negotiated 10/100
+ half and full duplex.
+
+ |
+
|
+ PAN-271700
+ |
+
+
+ Fixed an issue where User-ID connections were lost after an HA
+ failover.
+
+ |
+
|
+ PAN-271560
+ |
+
+
+ Fixed an issue where DNS requests to malware sites were not blocked as
+ expected, and the
+ dns-security-categories log-level
+ and action displayed default values instead of
+ unavailable.
+
+ |
+
|
+ PAN-270849
+ |
+
+
+ Fixed a memory leak issue related to the
+ configd
+ process that occurred when running consecutive commits for multiple
+ days.
+
+ |
+
|
+ PAN-269899
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected when querying for device tags.
+
+ |
+
|
+ PAN-269731
+ |
+
+
+ Fixed an issue where Panorama did not display logs from firewalls
+ after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
+ getting restarted continuously.
+
+ |
+
|
+ PAN-268787
+ |
+
+
+ Fixed an issue where users were unable to log in to Panorama and the
+ following error message was displayed:
+ Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of
+ devices.
+
+ |
+
|
+ PAN-267535
+ |
+ + + | +
|
+ PAN-267091
+ |
+
+
+ Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
+
+ |
+
|
+ PAN-266639
+ |
+
+
+ Fixed an issue where administrators were unable to edit or add virtual
+ router configurations when a filter was applied to the viewer.
+
+ |
+
|
+ PAN-263369
+ |
+
+
+ Fixed an issue where commits from Panorama to Panorama virtual
+ appliances failed with the error message
+ Internal error during commit processing. Commit/Validate
+ failed
+ after upgrading Panorama.
+
+ |
+
|
+ PAN-261209
+ |
+
+
+ (Firewalls in active/active HA configuration only) Fixed an issue where the firewall displayed the HA2 status as down
+ when the HSCI port was used for both HA2 and HA3.
+
+ |
+
|
+ PAN-260604
+ |
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput
+ utilization stats in NetFlow analyzer tools.
+
+ |
+
|
+ PAN-259881
+ |
+
+
+ Fixed an issue on Panorama where traffic log details were not
+ displayed under detailed log view.
+
+ |
+
|
+ PAN-258757
+ |
+
+
+ Fixed an issue on Panorama where upgrades failed with validation
+ errors.
+
+ |
+
|
+ PAN-255860
+ |
+
+
+ (PA-5200 firewalls only) Fixed an issue where
+ the
+ all_pktproc
+ process stopped responding when the firewall was under a heavy traffic
+ load.
+
+ |
+
|
+ PAN-249384
+ |
+
+
+ Fixed an issue on Panorama where configuration locks were observed
+ during a partial rulebase commit.
+
+ |
+
|
+ PAN-246699
+ |
+
+
+ Fixed an issue on Panorama where
+ Rule Usage and
+ Apps Seen under Security policy
+ rules stopped incrementing.
+
+ |
+
|
+ PAN-245064
+ |
+
+
+ (Multi-vsys firewalls only) Fixed an issue
+ where commits failed on the firewall after selecting
+ Export or push device config bundle
+ on Panorama and a force push was required.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-291499
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where newly deployed firewalls were unable to
+ connect to the Palo Alto Networks Software License Server (SLS) until
+ after a reboot, license fetch, or management server restart.
+
+ |
+
|
+ PAN-290803
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom
+ image, and VM-Series plugin information was not displayed in the
+ system information.
+
+ |
+
|
+ PAN-290241
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process became unresponsive, which caused User ID CLI commands to time
+ out.
+
+ |
+
|
+ PAN-288939
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to an invalid SSL context being used
+ for socket communication, which caused commits to fail.
+
+ |
+
|
+ PAN-287688
+ |
+
+
+ Fixed an issue where the firewall failed to connect to the Palo Alto
+ Networks update server when using a customized service route with the
+ source interface as MGT.
+
+ |
+
|
+ PAN-279901
+ |
+
+
+ An issue was fixed where the firewall dropped fragmented TLS
+ ClientHello packets, which blocked access to certain websites. This
+ occurred because the packets arrived truncated, in varying sizes and
+ orders, and the firewall's heuristics failed to handle them correctly.
+
+
+ To enable this fix, run:
+ debug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
|
+ PAN-268680
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when a configuration merge operation
+ changed.
+
+ |
+
|
+ PAN-268522
+ |
+
+
+ Fixed an issue where the firewall failed to connect to the update
+ server with a customized service route when the source interface was
+ set to MGT and the source address
+ was set as IPv4.
+
+ |
+
|
+ PAN-255914
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-241230
+ |
+
+
+ Fixed an issue where the SNMP get request status value for Panorama
+ connections was incorrect.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-296519
+ |
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an
+ associated error in
+ Wifclient
+ caused the entire pool to close, which resulted in a complete
+ disconnection.
+
+ |
+
|
+ PAN-295560
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors,
+ tunnel logs were not visible in Panorama or Splunk even though traffic
+ and threat logs were received.
+
+ |
+
|
+ PAN-293673
+ |
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM
+ condition caused by a scheduled log export using FTP to an external
+ FTP server.
+
+ |
+
|
+ PAN-292229
+ |
+
+
+ Fixed an issue where Panorama was unable to retrieve
+ userid
+ logs from the firewall for subscribed user-ip-mappings after Panorama
+ was rebooted.
+
+ |
+
|
+ PAN-292202
+ |
+
+
+ Fixed an issue where the system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
+ conditions, leading to device crashes and reboots.
+
+ |
+
|
+ PAN-291631
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall frequently rebooted.
+
+ |
+
|
+ PAN-291288
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a
+ pan_task
+ process restart related to page allocation failures.
+
+ |
+
|
+ PAN-291094
+ |
+
+
+ Fixed an issue the firewall experienced packet descriptor on chip and
+ buffer spikes, which led to dropped traffic due to an unidentified
+ traffic pattern.
+
+ |
+
|
+ PAN-291067
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process periodically exceeded its virtual memory limit and restarted,
+ which led to intermittent outages.
+
+ |
+
|
+ PAN-290542
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding when an additional header logging HTTP
+ header was split across 2 packets.
+
+ |
+
|
+ PAN-290449
+ |
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports
+ were sent in the same email, only the first attached report was
+ displayed.
+
+ |
+
|
+ PAN-287818
+ |
+
+
+ Fixed an issue where sessions timed out sooner than expected due to
+ the
+ pan_proxy_accumulation_restore_timeout
+ not initiating when the accumulation
+ session_init failed.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
+ certain websites weren't accessible when the accumulation proxy was
+ enabled. The proxy did not use the same DF bit state as the original
+ traffic, causing it to be fragmented and dropped elsewhere in the
+ network.
+
+ |
+
|
+ PAN-287782
+ |
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP
+ values from AF11 to CS0 on traffic passing through the firewall, even
+ when QoS policy rules and DSCP rewrite settings were not configured.
+
+ |
+
|
+ PAN-287622
+ |
+
+
+ Fixed an issue where IPv6 traffic was affected after upgrading the
+ firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
+ enabled and a decryption policy configured for the traffic, the
+ firewall dropped packets due to receiving a
+ Packet Too Big ICMP message. This
+ occurred because the PathMTU information update was incorrect for the
+ TCB (pan-server) when the firewall was acting as a server.
+ Additionally, the flow label under the IPv6 header was set to zero
+ while the packet was being transmitted out of the firewall.
+
+ |
+
|
+ PAN-287601
+ |
+
+
+ Fixed an issue on Panorama where commits took longer than expected.
+
+ |
+
|
+ PAN-287423
+ |
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites
+ due to the firewall incorrectly setting the IPv6 header flow label to
+ 0.
+
+ |
+
|
+ PAN-286299
+ |
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 releases where, after
+ being offboarded from Panorama, the firewall XML configuration file
+ retained template information from the previous Panorama
+ configuration. As a result, when the firewall and its configuration
+ were imported to another Panorama appliance, all configurations in the
+ Network and
+ Device tabs became read-only.
+
+ |
+
|
+ PAN-285285
+ |
+
+
+ Fixed an issue where commits remained at 98% completion when static
+ route configuration cleanup was in progress.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to
+ multiple firewalls with different base configurations resulted in
+ configuration corruption, which caused the firewall to go down.
+
+ |
+
|
+ PAN-280698
+ |
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from
+ client hello messages that did not fit in a single packet, which
+ resulted in connection issues.
+
+ |
+
|
+ PAN-279706
+ |
+
+
+ (M-600 appliances only) Fixed an issue where
+ Panorama did not update all
+ panreplay
+ database entries after performing a commit and full push to all
+ devices.
+
+ |
+
|
+ PAN-276484
+ |
+
+
+ Fixed an issue where Panorama did not display license information for
+ Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
+
+ |
+
|
+ PAN-273453
+ |
+
+
+ Fixed an issue where restarting the firewall did not initiate an
+ autocommit job, which caused the firewall to stop responding and the
+ HA interface to go down.
+
+ |
+
|
+ PAN-273300
+ |
+
+
+ Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed
+ with a validation error.
+
+ |
+
|
+ PAN-265044
+ |
+
+
+ Fixed an issue where the default software packet buffer size for the
+ Advanced Header Learning (AHL) feature was excessively large, which
+ led to inefficient use of software packet buffers.
+
+ |
+
|
+ PAN-260015
+ |
+
+
+ Fixed an issue on the firewall where enabling Inline Cloud Analysis
+ features might cause the firewall to unexpectedly reboot, due to an
+ issue related to loopback data handling.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-303559
+ |
+
+
+ Fixed an issue where, after manually creating a device telemetry
+ bundle, the
+ hour_cli_output.txt file within
+ the bundle had a file size of 0 bytes. This occurred when checking the
+ bundle content after enabling device telemetry and setting the device
+ telemetry upload endpoint.
+
+ |
+
|
+ PAN-301456
+ |
+
+
+ Fixed an issue on Panorama where the
+ debug system reset-ztp CLI
+ command was unavailable.
+
+ |
+
|
+ PAN-300216
+ |
+
+
+ Fixed an issue where, when SD-WAN Direct Internet Access was
+ configured and traffic traversed the cellular interface without a NAT
+ policy rule, intermittent cellular modem connectivity issues occurred,
+ which caused the firewall to disconnect and reconnect to the cellular
+ network.
+ To use this fix, run the CLI command set session
+ teardown-upon-fwd-zonechange yes.
+
+ |
+
|
+ PAN-298462
+ |
+
+
+ Fixed an issue where the firewall experienced extended boot times
+ after a reboot due to the
+ configd
+ process needing to rebuild the ACE catalog after detecting
+ discrepancies that were caused by duplicate application checking
+ between the ACE catalog and content.
+
+ |
+
|
+ PAN-297976
+ |
+
+
+ Fixed an issue where the firewall experienced extended boot times
+ after a reboot due to the
+ configd
+ process needing to rebuild the ACE catalog after detecting
+ discrepancies that were caused by duplicate application checking
+ between the ACE catalog and content.
+
+ |
+
|
+ PAN-297972
+ |
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched
+ Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
+ Analysis features were not enabled.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release,
+ the Visible Virtual System field referenced the vsys name instead of
+ the vsys ID, which caused inter-vsys routing to fail. This occurred
+ when a vsys display name matched one of the vsys IDs. If you're using
+ a multivsys environment, you must upgrade your firewalls to a fixed
+ PAN-OS version. The best practice is to upgrade both the firewalls and
+ Panorama to a fixed PAN-OS version.
+
+
+ If you don't upgrade Panorama to a fixed version, you'll encounter
+ PAN-245064, where a commit on a multivsys firewall fails with the
+ message
+ vsys name should end with a number vsys is invalid
+ after you
+ Export or push device config bundle
+ from 11.1.1 Panorama.
+
+
+ After you upgrade Panorama to a fixed version, you'll encounter
+ PAN-214177, which causes an
+ Export or Push device config bundle
+ from Panorama to the firewall to fail. The workaround for PAN-214177
+ is to first push only the template configuration and then push the
+ device group configurations.
+
+ |
+
|
+ PAN-296752
+ |
+
+
+ (PA-1410 Firewalls only) Fixed an issue where
+ the firewall experienced high management CPU usage and repeatedly
+ rebooted when attempting to retrieve SMART data.
+
+ |
+
|
+ PAN-296694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to the
+ useridd
+ process repeatedly restarting during an IP-port data type writes to
+ the redis from multiple sources such as TSA or XML in a scale
+ environment.
+
+ |
+
|
+ PAN-296535
+ |
+
+
+ Fixed an issue on the firewall where BGP peers disconnected due to
+ frr_ns1_bgpd restarting.
+
+ |
+
|
+ PAN-294436
+ |
+
+
+ (PA-410, PA-440, PA-450, and PA-460 firewalls only) Fixed an issue where, after upgrading to PAN-OS 11.1.6-h6 the
+ Eth1/2, Eth1/3, Eth1/8, and HA interfaces failed to display counters
+ and statistics in the CLI and SNMP.
+
+ |
+
|
+ PAN-292447
+ |
+
+
+ Fixed an issue where Panorama did not display data in the
+ Feature Adoption tab in Strata Cloud
+ Manager due to the system creating and deleting a CLI user for each
+ interval instead of reusing a permanent CLI user for telemetry.
+
+ |
+
|
+ PAN-291940
+ |
+
+
+ Fixed an issue where the firewall established multiple TCP connections
+ to a syslog server, which caused logs to be dropped. This occurred
+ because the firewall established a new TCP session for each transfer
+ and the sessions were not closed, which resulted in a continuous
+ increase in connections over time.
+
+ |
+
|
+ PAN-291661
+ |
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after
+ an upgrade, Elasticsearch intermittently entered into a Red state
+ before automatically recovering.
+
+ |
+
|
+ PAN-289249
+ |
+
+
+ Fixed an issue where a memory leak occurred on the
+ reportd
+ process when a WildFire update was initiated while device telemetry
+ data collection was in progress. This resulted in an OOM condition.
+
+ |
+
|
+ PAN-289109
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected during configuration operations and a configuration lock time
+ out occurred during a commit.
+
+ |
+
|
+ PAN-287387
+ |
+
+
+ Fixed an issue on Panorama where API jobs failed with the error
+ message
+ Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a
+ large number of address objects in a single set call.
+
+ |
+
|
+ PAN-284279
+ |
+
+
+ Fixed an issue where the policy destination always defaulted to
+ any, even when specific IP addresses
+ and FQDNs were specified during policy import.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ Fixed a cumulative memory leak in the
+ devsrvr
+ process that occurred whenever the CLI command
+ show running application statistics
+ was issued. This memory leak would gradually consume system memory and
+ produce an OOM condition, causing the firewall to reboot.
+
+ |
+
|
+ PAN-281776
+ |
+
+
+ Fixed an issue on the Panorama web interface where the error message
+ PPPoEv6 Client Interface cannot be enabled with DHCPv6 client
+ was generated when overriding aggregate interfaces even when no DHCPv6
+ or PPPoE was configured.
+
+ |
+
|
+ PAN-279829
+ |
+
+
+ Fixed an issue where NAT pool leaks occurred during a test when RTSP
+ traffic hit NAT rules.
+
+ |
+
|
+ PAN-272746
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where
+ the firewall entered an unstable state after committing changes or
+ onboarding to Panorama.
+
+ |
+
|
+ PAN-272605
+ |
+
+
+ Fixed an issue where the firewall did not display VPC endpoints when
+ there was a large amount of VPC endpoints to interface mappings.
+
+ |
+
|
+ PAN-272245
+ |
+
+
+ Fixed an issue where the
+ dnsproxy
+ process stopped responding due to memory corruption caused by a race
+ condition when the allow list downloading was impacted by a
+ configuration change.
+
+ |
+
|
+ PAN-267450
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding with a SIGSEGV at
+ schedule_report_es_response.
+
+ |
+
|
+ PAN-266312
+ |
+
+
+ Fixed an issue where BFD sessions took longer than expected to
+ establish after an HA failover due to BGP.
+
+ |
+
|
+ PAN-264131
+ |
+
+
+ Fixed an issue where the
+ routed
+ process core failed the automation run.
+
+ |
+
| Issue ID | +Description | +
|---|---|
|
+ —
+ |
+
+
+ A fix was made to address
+ CVE-2026-0227.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-273215
+ |
+
+
+ Fixed an issue where a syntax error in the index generation script
+ caused a high management plane CPU load after upgrading.
+
+ |
+
|
+ PAN-271613
+ |
+
+
+ Fixed an issue where configuration pushes from Panorama to the
+ firewall failed due to an OOXML commit error.
+
+ |
+
|
+ PAN-269404
+ |
+
+
+ Fixed an issue where the firewall did not reset the maximum latency
+ timer for hold mode.
+
+ |
+
|
+ PAN-259078
+ |
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and
+ the following error message was displayed:
+ Error 500: Internal Server Error.
+
+ |
+
| Issue ID | +Description | +
|---|---|
|
+ PAN-276130
+ |
+
+
+ Fixed an issue where, when a new IKEv2 was created on Panorama on a
+ PAN-OS 11.2 release using the default IKE version (IKEv2) and IPSec
+ crypto profiles with no specific changes to the crypto profile
+ parameters, and the configuration was pushed to a firewall on PAN-OS
+ 11.2.0 to PAN-OS 11.2.4, the firewall interpreted the IKEv2 gateway as
+ IKEv1.
+
+ |
+
|
+ PAN-274029
+ |
+
+
+ Fixed an issue where upgrading Panorama and pushing configurations to
+ the firewall caused an IKE version mismatch, which resulted in IPSec
+ tunnel failure with the peer device.
+
+ |
+
|
+ PAN-273994
+ |
+
+
+ A fix was made to address
+ CVE-2025-0111.
+
+ |
+
|
+ PAN-273971
+ |
+
+
+ A fix was made to address
+ CVE-2025-0108.
+
+ |
+
|
+ PAN-273278
+ |
+
+
+ A fix was made to address
+ CVE-2025-0109.
+
+ |
+
|
+ PAN-273197
+ |
+
+
+ Fixed an issue where the endpoint ID was not populated in logs when
+ the least significant word of the Geneve header was 0.
+
+ |
+
|
+ PAN-273165
+ |
+
+
+ Fixed an issue where HTTP/2 sessions failed on the firewall when
+ Dynamic Memory Management was enabled.
+
+ |
+
|
+ PAN-273085
+ |
+
+
+ Fixed an issue on the web interface where you were unable to edit or
+ create policy rules.
+
+ |
+
|
+ PAN-273019
+ |
+
+
+ Fixed an intermittent issue where SSL decryption failed.
+
+ |
+
|
+ PAN-272021
+ |
+
+
+ (M-300 Appliances only) Fixed an issue where a
+ split brain condition was not triggered during an inter-Log Collector
+ disconnect between DLC firewalls in an Elasticsearch cluster, which
+ resulted in missing logs.
+
+ |
+
|
+ PAN-271926
+ |
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
+ error when the firewall was configured to decrypt and inspect TLS
+ traffic.
+
+ |
+
|
+ PAN-271828
+ |
+
+
+ Fixed an issue where, after an accumulation proxy changed to
+ no-decrypt or no proxy, only the Client Hello was sent to Content
+ Threat Detection.
+
+ |
+
|
+ PAN-270549
+ |
+
+
+ Fixed an issue where some TLS connections were not handled correctly,
+ which led to instability in the dataplane.
+
+ |
+
|
+ PAN-270248
+ |
+ + Fixed an issue where the firewall failed to forward logs to a SNMP trap + server if the SNMP manager IP address was unable to be resolved. + | +
|
+ PAN-268815
+ |
+
+
+ Fixed an issue where the firewall entered a non-functional state due
+ to duplicate entries in the shared memory.
+
+ |
+
|
+ PAN-268727
+ |
+ + Fixed an issue where traffic was dropped when the accumulation proxy was + enabled and header insertion modified packets. + | +
|
+ PAN-268229
+ |
+
+
+ Fixed an issue where the firewall stopped responding during session
+ setup for ECMP hit-count updates.
+
+ |
+
|
+ PAN-268215
+ |
+
+
+ (Panorama appliances in HA configurations only)
+ Fixed an issue where, when Elasticsearch was forming a cluster and the
+ port was disabled or disconnected and then reconnected, Elasticsearch
+ did not reform the cluster
+
+ |
+
|
+ PAN-267781
+ |
+
+
+ Fixed an issue where Panorama did not display the Source Dynamic
+ Address Group.
+
+ |
+
|
+ PAN-267671
+ |
+ + + | +
|
+ PAN-265742
+ |
+
+
+ Fixed an issue on the Panorama web interface where the
+ OK button on the GlobalProtect
+ gateway configuration dialog box was not clickable.
+
+ |
+
|
+ PAN-263987
+ |
+
+
+ Fixed an issue on the firewall where, when a NAT transversal IPSec
+ tunnel was terminated, and the NAT rule that was applied to the NAT-T
+ IPSec tunnel was on the same firewall, traffic flowing through the
+ tunnel was not correctly translated.
+
+ |
+
|
+ PAN-252036
+ |
+
+
+ Fixed an issue where, when the GlobalProtect portal was not
+ configured, accessing the GlobalProtect gateway still loaded a portal
+ malformed page.
+
+ |
+
| Issue ID | +Description | +
|---|---|
|
+ PAN-279604
+ |
+
+
+ Fixed an issue where scheduled SaaS application usage reports were
+ generated incorrectly, and the login page was displayed instead of the
+ report content.
+
+ |
+
|
+ PAN-276177
+ |
+
+
+ Fixed an issue where
+ App Acceleration did not work with
+ Oracle databases.
+
+ |
+
|
+ PAN-274791
+ |
+
+
+ Fixed an issue where the firewall rebooted when Shared Pool Type 32
+ was depleted and traffic matched advanced features.
+
+ |
+
|
+ PAN-269499
+ |
+
+
+ Fixed an issue where the firewall stopped responding when receiving a
+ high number of logs.
+
+ |
+
|
+ PAN-252224
+ |
+
+
+ Fixed an issue where Panorama did not forward logs to a syslog server
+ over an SSL connection using CRL as a revocation verification method.
+
+ |
+
|
+ PAN-234082
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where Saas reports were generated with a report period of 0
+ days.
+
+ |
+
|
+ PAN-216054
+ |
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while
+ it was idle.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-284036
+ |
+
+
+ (PA-450R and PA-450R-5G firewalls only) Fixed
+ an issue where the maximum temperature threshold and shutdown
+ threshold were not set correctly.
+
+ |
+
|
+ PAN-282236
+ |
+
+
+ Fixed an issue where large IPv6 packets were reassembled incorrectly
+ on the firewall when the packets arrived fragmented over an IPv4
+ tunnel.
+
+ |
+
|
+ PAN-282206
+ |
+
+
+ Fixed an issue where configuring Secure Web Gateway (SWG) in
+ no-auth mode led to latency when no
+ decryption policy rules or
+ No-decrypt policy rules were
+ present.
+
+ |
+
|
+ PAN-282022
+ |
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700
+ appliances.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ Fixed an issue where navigating
+ Panorama > Monitor > Logs was
+ slower than expected.
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client
+ Hello arrived at the firewall in multiple out-of-order segments and
+ the traffic was not subject to SSL decryption.
+
+ |
+
|
+ PAN-279197
+ |
+
+
+ (PA-450R-5G firewalls only) Fixed an issue
+ where the firewall stopped responding and displayed the error message
+ `Thermal temperature exceeds system threshold! Shutting down NOW` even
+ when the firewall was within the threshold.
+
+ |
+
|
+ PAN-278684
+ |
+
+
+ (PA-445 firewalls only) Fixed an issue where
+ the firewall did not properly power cycle during a reboot.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ Fixed an issue where the system MAC address of the aggregate interface
+ was the same on the active firewall and the passive firewall after an
+ upgrade.
+
+ |
+
|
+ PAN-276546
+ |
+
+
+ Fixed an issue where a session lost the PBF rule mapping after a
+ configuration change or commit.
+
+ |
+
|
+ PAN-275905
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected and Elasticsearch CPU usage was high.
+
+ |
+
|
+ PAN-273949
+ |
+
+
+ Fixed an issue where the firewall generated the following error
+ message in the
+ snmpd
+ logs:
+ pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
+ X2F1dGhfa2V5 import from cryptod failed.
+
+ |
+
|
+ PAN-273026
+ |
+
+
+ Fixed an issue where traffic logs did not display correctly when
+ filters were applied.
+
+ |
+
|
+ PAN-273021
+ |
+
+
+ Fixed an issue where 25G port links did not come up due to a change in
+ the handling of 25G DAC modules.
+
+ |
+
|
+ PAN-272849
+ |
+
+
+ Fixed an issue where log forwarding to a UDP syslog server stopped
+ when an unreachable TCP syslog server was configured and applied.
+
+ |
+
|
+ PAN-272538
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding during a commit-all validation when there
+ were uncommitted changes and
+ share-unused-objects-with-devices
+ was set to off.
+
+ |
+
|
+ PAN-272085
+ |
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is
+ enabled for DNS Security and multiple DoH transactions are sent in a
+ single HTTP/1 connection.
+
+ |
+
|
+ PAN-271912
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when filtering in the configuration audit
+ window after upgrading to PAN-OS 11.1.3.
+
+ |
+
|
+ PAN-271351
+ |
+
+
+ A fix was made to address
+ CVE-2025-0116.
+
+ |
+
|
+ PAN-270224
+ |
+
+
+ Fixed an issue where indices were not opened after a query.
+
+ |
+
|
+ PAN-269956
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused internal path monitor
+ failures.
+
+ |
+
|
+ PAN-269291
+ |
+
+
+ Fixed an issue where the scheduled report generation script did not
+ return debug information.
+
+ |
+
|
+ PAN-269106
+ |
+
+
+ Fixed an issue where the
+ wifclient stopped responding
+ during server certificate verification for MICA gRPC connections and
+ caused the dataplane to restart when using a cloud-based ML detection
+ engine (MICA). On certain platforms, this caused the firewall to
+ reboot periodically.
+
+ |
+
|
+ PAN-269091
+ |
+
+
+ Fixed an issue where the
+ varrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-268501
+ |
+
+
+ Fixed an issue where the firewall was unable to generate a TSF file
+ due to a full root partition.
+
+ |
+
|
+ PAN-267430
+ |
+
+
+ Fixed an issue where Panorama was unable to return logs for queries
+ that were longer than 64,000 characters.
+
+ |
+
|
+ PAN-265179
+ |
+
+
+ Fixed an issue where a kernel race condition caused the firewall to
+ reboot with a kernel panic.
+
+ |
+
|
+ PAN-263208
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an
+ issue where interrupts were generated at a certain packet rate, and
+ dataplane processes missed heartbeats, which caused the dataplane to
+ go down.
+
+ |
+
|
+ PAN-262383
+ |
+
+
+ Fixed an issue where the firewall was unable to decompress the HTTP2
+ header, which caused the session to be classified as unknown-tcp
+ instead of web-browsing.
+
+ |
+
|
+ PAN-261739
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port
+ counters read from MAC.
+
+ |
+
|
+ PAN-261484
+ |
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount
+ of memory as requested for pre-allocation.
+
+ |
+
|
+ PAN-258736
+ |
+
+
+ Fixed an issue where policy rule configurations pushed from Panorama
+ were not reflected on the firewall if the rule had 63 characters.
+
+ |
+
|
+ PAN-258570
+ |
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the
+ varrcvr
+ process progressively using more memory when WildFire file forwarding
+ is handling PE files.
+
+ |
+
|
+ PAN-257619
+ |
+
+
+ Fixed an issue on Panorama where the
+ Task Manager took longer than
+ expected to display managed firewall report tasks.
+
+ |
+
|
+ PAN-257028
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and
+ displayed the error message
+ Dataplane down: path monitor failure during the fail-over.
+
+ |
+
|
+ PAN-255323
+ |
+
+
+ (PA-7050 firewalls only) Fixed an issue where
+ the Network Processing Card (NPC), Data Processing Card (DPC), and Log
+ forwarding Card (LFC) remained in a starting state after an unexpected
+ power cycle.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-286255
+ |
+
+
+ Fixed an issue where, when the firewall received an unexpected
+ termination request for SSL sessions, the dataplane experienced a slow
+ buffer resource leak.
+
+ |
+
|
+ PAN-282968
+ |
+
+
+ Fixed an issue where the firewall did not identify the test threat
+ file when the content was installed via a traditional bootstrap.
+
+ |
+
|
+ PAN-278322
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) Gateway Load
+ Balancer (GWLB) deployments only) Fixed an issue where the firewall did not display the correct
+ source user in traffic logs and session details.
+
+ |
+
|
+ PAN-277629
+ |
+
+
+ Fixed an issue where the firewall did not match the correct policy for
+ SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS
+ 10.2.9-h1 to PAN-OS 11.2.3.
+
+ |
+
|
+ PAN-268474
+ |
+
+
+ Fixed an issue on the firewall where the PAN-DB URL Filtering license
+ displayed as Valid even when the
+ firewall did not have the license, which caused traffic to drop.
+
+ |
+
|
+ PAN-261999
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where enabling flow basic on firewalls caused ARP
+ entries to be removed on both firewalls.
+
+ |
+
|
+ PAN-260290
+ |
+
+
+ Added support for new content size requirements on fixed model
+ licenses.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-267444
+ |
+
+
+ Fixed an issue where large file downloads or uploads failed or
+ remained in an incomplete state when using DLP HTTP2 mirror mode.
+
+ |
+
|
+ PAN-255619
+ |
+
+
+ Fixed an intermittent issue where file downloads from websites failed
+ when decrypting HTTP/2 traffic.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-290239
+ |
+
+
+ (PA-455 firewalls in active/passive high availability (HA)
+ configurations only) Fixed an issue where, after an upgrade, the TCP session for syslog
+ forwarding did not resume after the syslog server service was disabled
+ and then re-enabled, which caused logs to be dropped. This occurred
+ when the syslog server was down for more than 16 minutes.
+
+ |
+
|
+ PAN-289102
+ |
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
+ PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
+ CN-Series firewalls only) Fixed a race condition issue related to predict processing, which
+ resulted in a dataplane restart and traffic loss.
+
+ |
+
|
+ PAN-287002
+ |
+
+
+ A fix was made to address
+ CVE-2025-0133.
+
+ |
+
|
+ PAN-285894
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused the firewall to reboot
+ unexpectedly, and traffic failures occurred.
+
+ |
+
|
+ PAN-285651
+ |
+
+
+ (Panorama appliances in active/passive HA configurations on
+ Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect
+ unexpectedly.
+
+ |
+
|
+ PAN-285590
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
+ only) Fixed an issue where the firewall CPU usage reached 100% after
+ upgrading to PAN-OS 11.1.6-h1.
+
+ |
+
|
+ PAN-284066
+ |
+
+
+ Fixed an issue where, after an upgrade, the SNMP polled values for
+ IF-MIB::ifInErrors displayed a
+ high number of errors that did not match the values in the CLI show
+ interface command.
+
+ |
+
|
+ PAN-283789
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where, after an upgrade, the
+ mac receive error counter in
+ receive incoming errors increased,
+ which resulted in SNMP alerts.
+
+ |
+
|
+ PAN-283467
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall unexpectedly rebooted and entered maintenance mode
+ due to a ctd-agent out-of-memory (OOM) condition. This occurred during
+ advanced services load testing and a high volume of IoT EAL log
+ forwarding.
+
+ |
+
|
+ PAN-283331
+ |
+
+
+ Fixed an issue where selective pushes to managed devices failed when
+ the User ID Master Device was
+ configured.
+
+ |
+
|
+ PAN-282069
+ |
+
+
+ Fixed an issue on Panorama where Security policy rules were removed
+ from device groups when you cloned or edited Security policy rules
+ that used more than 63 characters.
+
+ |
+
|
+ PAN-280532
+ |
+
+
+ Fixed an issue where, after disabling and re-enabling the external
+ syslog server, the TCP session was not resumed, which caused all logs
+ that were forwarded to the syslog server to be dropped.
+
+ |
+
|
+ PAN-279621
+ |
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward
+ traffic was run.
+
+ |
+
|
+ PAN-275077
+ |
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain
+ URLs as Alert instead of taking a Sinkhole action, even when
+ configured to Sinkhole malicious DNS domains.
+
+ |
+
|
+ PAN-274570
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process restarted after a failed commit due to an invalid memory
+ access.
+
+ |
+
|
+ PAN-274314
+ |
+
+
+ (PA-1400 Series, PA-3400 Series, and PA-5400 Series firewalls
+ only) Fixed an issue where, when the
+ pan_task
+ process restarted, control plane packets were dropped, which could
+ impact LACP and pings to host interfaces.
+
+ |
+
|
+ PAN-272006
+ |
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump
+ as a large core when the CPLD (Complex Programmable Logic Device) sent
+ a Non-Maskable Interrupt (NMI) to the CPU.
+
+ |
+
|
+ PAN-271913
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where, when using the
+ Cloud Identity Engine (CIE), the firewall experienced consistent
+ memory leaks on the active firewall, which caused unexpected
+ failovers.
+
+ |
+
|
+ PAN-271273
+ |
+
+
+ Fixed an issue where dynamic update downloads failed when
+ IPv6 firewalling was enabled on the
+ firewall and both IPv4 and IPv6 were configured on the management
+ interface.
+
+ |
+
|
+ PAN-270379
+ |
+
+
+ Fixed an issue where socket files created in the /tmp directory were
+ not cleared.
+
+ |
+
|
+ PAN-269052
+ |
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile
+ even though the Security policy rule did not have a URL filtering
+ profile configured.
+
+ |
+
|
+ PAN-269027
+ |
+
+
+ Fixed an issue related to external dynamic lists that caused commit
+ times on the firewall to be higher than expected.
+
+ |
+
|
+ PAN-268708
+ |
+
+
+ Fixed an issue where PDF summary and email reports displayed IPv6
+ addresses instead of IPv4 addresses.
+
+ |
+
|
+ PAN-268705
+ |
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP
+ traffic after upgrading to PAN-OS 10.1.14.
+
+ |
+
|
+ PAN-268127
+ |
+
+
+ Fixed an issue where tagging devices in Panorama did not work as
+ expected.
+
+ |
+
|
+ PAN-267444
+ |
+
+
+ Fixed an issue where large file downloads or uploads failed or
+ remained in an incomplete state when using DLP HTTP2 mirror mode.
+
+ |
+
|
+ PAN-266900
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ click OK after selecting an install
+ package type and file from the dropdown and selecting a firewall.
+
+ |
+
|
+ PAN-265745
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect MAC receive
+ error counters for VMWare devices hosted in ESXi.
+
+ |
+
|
+ PAN-263973
+ |
+
+
+ Fixed an issue where log collectors had a low incoming log rate.
+
+ |
+
|
+ PAN-261825
+ |
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or
+ Advanced URL Filtering were enabled. This occurred when the payload
+ size was greater than 3.5 KB.
+
+ |
+
|
+ PAN-261673
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled,
+ traffic was dropped because of the
+ flow_parse_ip_hdr counter related
+ to an Nvidia driver issue.
+
+ |
+
|
+ PAN-261429
+ |
+
+
+ Fixed an issue where the
+ show auth radius-require-msg-authentic
+ CLI command displayed no output.
+
+ |
+
|
+ PAN-259706
+ |
+
+
+ Fixed an issue on Panorama where the web interface was slower than
+ expected or unresponsive when monitoring definitions were added in the
+ Kubernetes plugin.
+
+ |
+
|
+ PAN-258680
+ |
+
+
+ Fixed an issue on Panorama where, when you removed Security profile
+ groups from a Security policy rule via the CLI and committed the
+ change, the Security policy rule was deleted.
+
+ |
+
|
+ PAN-257267
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ a warning message was displayed after a commit, and a critical system
+ log was generated when the configuration size exceeded the maximum
+ size.
+
+ |
+
|
+ PAN-255619
+ |
+
+
+ Fixed an intermittent issue where file downloads from websites failed
+ when decrypting HTTP/2 traffic.
+
+ |
+
|
+ PAN-254901
+ |
+
+
+ Fixed an issue where GlobalProtect user-to-IP address mapping was
+ removed even though the tunnel for the specific user was up and
+ traffic was being passed.
+
+ |
+
|
+ PAN-252669
+ |
+
+
+ Fixed an issue where the
+ ikemgr
+ process stopped responding with a SIGSEGV error.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-270802
+ |
+
+
+ Fixed an issue where, after modifying a policy rule on Panorama,
+ pushes to the Cloud NGFW failed with the error
+ saas-user-list unexpected here.
+
+ |
+
|
+ PAN-268823
+ |
+
+
+ Fixed an issue where
+ Monitor > Log Display did not
+ display all logs when you applied a filter.
+
+ |
+
|
+ PAN-267386
+ |
+
+
+ Fixed an issue where VPC IDs and Security keys were not mapped to the
+ correct interfaces for Google IPS.
+
+ |
+
|
+ PAN-266769
+ |
+
+
+ Fixed an issue where the GlobalProtect gateway did not handle IP
+ address changes of the inner gateway when the NGPA new protocol was
+ enabled.
+
+ |
+
|
+ PAN-266581
+ |
+
+
+ Fixed an issue where a failed SSL connection to a syslog server
+ resulted in a
+ /tmp/srvr.crt.xxxxxx file not
+ being removed, which caused index node (inode) exhaustion.
+
+ |
+
|
+ PAN-266114
+ |
+
+
+ Fixed an issue where, when a new set of URL logs came in, the content
+ of the earlier URL and traffic logs were lost.
+
+ |
+
|
+ PAN-265785
+ |
+
+
+ Fixed an issue where the firewall rebooted due to a
+ sysd
+ variable being modified before it was created.
+
+ |
+
|
+ PAN-264249
+ |
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using
+ SNMP.
+
+ |
+
|
+ PAN-264246
+ |
+
+
+ Fixed an issue where the Authentication Portal did not work properly
+ with session cookies when the request to the portal contained the
+ header Sec-Fetch-Site=cross-site.
+
+ |
+
|
+ PAN-263680
+ |
+
+
+ Fixed an issue where Prisma Access gateways consistently stopped
+ responding with process restarts.
+
+ |
+
|
+ PAN-263559
+ |
+
+
+ Fixed an issue where the dataplane stopped responding and the firewall
+ unexpectedly rebooted due to multiple process restarts.
+
+ |
+
|
+ PAN-263287
+ |
+
+
+ The PAN-COMMON-MIB.my file was updated to support new object
+ identifiers (OID) to poll interface use via SNMP with table
+ identifiers.
+
+ |
+
|
+ PAN-262340
+ |
+
+
+ Fixed an issue where FQDN resolution failed for address objects, and
+ all FQDN traffic was denied by the interzone-default policy rule.
+
+ |
+
|
+ PAN-262254
+ |
+
+
+ Fixed an issue where the firewall experienced an OOM condition and the
+ useridd
+ process stopped responding, which caused the firewall to drop
+ interfaces from their respective aggregate groups.
+
+ |
+
|
+ PAN-261489
+ |
+
+
+ Fixed an issue where an out-of-memory (OOM) condition caused a
+ firewall outage.
+
+ |
+
|
+ PAN-260662
+ |
+
+
+ Fixed an issue where large file downloads were slower than expected
+ when private IP address visibility was enabled.
+
+ |
+
|
+ PAN-260512
+ |
+
+
+ Fixed an issue where accessing the IP address of the device address
+ group objects from the user interface caused the
+ configd
+ process to stop responding.
+
+ |
+
|
+ PAN-260316
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding and the firewall rebooted.
+
+ |
+
|
+ PAN-259910
+ |
+
+
+ Fixed an issue where the firewall reported the same value over
+ consecutive SNMP polls when asynchronous mode was enabled.
+
+ |
+
|
+ PAN-259767
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to connect when
+ the option
+ Block sessions if the certificate was not issued to the
+ authenticating device
+ was enabled in the certificate profile.
+
+ |
+
|
+ PAN-259002
+ |
+
+
+ Fixed an issue where frequent external dynamic list updates caused the
+ configd
+ process to restart.
+
+ |
+
|
+ PAN-257736
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ traffic to benign applications was was impacted by holding TCP
+ sequential segments for MLC inspection and not releasing the full
+ chain after a benign verdict was received.
+
+ |
+
|
+ PAN-257601
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ Networking Cards (NC) experienced an internal link fault which caused
+ path monitoring failure on the Dataplane Processing Card (DPC).
+
+ |
+
|
+ PAN-257327
+ |
+
+
+ (PA-5440 firewalls only) Fixed an issue where a
+ failover event occurred unexpectedly on the firewall.
+
+ |
+
|
+ PAN-256077
+ |
+
+
+ Fixed an issue where the GlobalProtect client would disconnect
+ consistently due to keep-alive timeouts when using an SSL-only tunnel.
+
+ |
+
|
+ PAN-254704
+ |
+
+
+ (LSVPN Portal firewalls in active/passive HA configurations only) Fixed an issue where the satellite cookie key did not sync between
+ LSVPN portal HA firewalls, which resulted in re-authentication of
+ satellites with the portal during the event of HA failover.
+
+ |
+
|
+ PAN-251973
+ |
+
+
+ Fixed an issue where the firewall did not detect evasions due to TCP
+ checksum offloading not being enabled.
+
+ |
+
|
+ PAN-250394
+ |
+
+
+ Fixed an issue where a large amount of group data caused serialization
+ errors and prevented synchronization.
+
+ |
+
|
+ PAN-250371
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding, which caused commits to fail with the
+ error message
+ Management server failed to send phase 1 to client logrcvr.
+
+ |
+
|
+ PAN-240990
+ |
+
+
+ Fixed an issue where
+ l3svc.py displayed incorrect
+ logs.
+
+ |
+
|
+ PAN-239952
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where HA sync messages from the active firewall took
+ longer than expected to reach the passive firewall.
+
+ |
+
|
+ PAN-230893
+ |
+
+
+ Added a CLI command to address an issue where system lock files
+ blocked authentication.
+
+ |
+
|
+ PAN-230825
+ |
+
+
+ Fixed an issue where link flaps occurred on Panorama appliances in HA
+ configurations.
+
+ |
+
|
+ PAN-225213
+ |
+
+
+ Fixed an issue where
+ Push All Changes displayed changes
+ that were already committed in the push scope for another device group
+ after performing a selective commit and selective push to the first
+ device group.
+
+ |
+
|
+ PAN-222542
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where Log Forward Cards (LFC) were incorrectly identified as
+ distribution policies, which caused packet loss due to traffic, BFD,
+ and other control packets being forwarded to the LFC.
+
+ |
+
|
+ PAN-214773
+ |
+
+
+ Fixed an issue where RTP packets traversing inter-vsys were dropped on
+ the outgoing vsys.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-282022
+ |
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700
+ appliances.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-275905
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected and Elasticsearch CPU usage was high.
+
+ |
+
|
+ PAN-274029
+ |
+
+
+ Fixed an issue where upgrading Panorama and pushing configurations to
+ the firewall caused an IKE version mismatch, which resulted in IPSec
+ tunnel failure with the peer device.
+
+ |
+
|
+ PAN-273215
+ |
+
+
+ Fixed an issue where a syntax error in the index generation script
+ caused a high management plane CPU load after upgrading.
+
+ |
+
|
+ PAN-273197
+ |
+
+
+ Fixed an issue where the endpoint ID was not populated in logs when
+ the least significant word of the Geneve header was 0.
+
+ |
+
|
+ PAN-272085
+ |
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is
+ enabled for DNS Security and multiple DoH transactions are sent in a
+ single HTTP/1 connection.
+
+ |
+
|
+ PAN-271913
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where, when using the
+ Cloud Identity Engine (CIE), the firewall experienced consistent
+ memory leaks on the active firewall, which caused unexpected
+ failovers.
+
+ |
+
|
+ PAN-271828
+ |
+
+
+ Fixed an issue where, after an accumulation proxy changed to
+ no-decrypt or no proxy, only the Client Hello was sent to Content
+ Threat Detection.
+
+ |
+
|
+ PAN-271613
+ |
+
+
+ Fixed an issue where configuration pushes from Panorama to the
+ firewall failed due to an OOXML commit error.
+
+ |
+
|
+ PAN-270569
+ |
+
+
+ Fixed an issue where the
+ userid
+ process stopped responding due to memory was being reset to NULL when
+ it was freed.
+
+ |
+
|
+ PAN-270549
+ |
+
+
+ Fixed an issue where some TLS connections were not handled correctly,
+ which led to instability in the dataplane.
+
+ |
+
|
+ PAN-270224
+ |
+
+
+ Fixed an issue where indices were not opened after a query.
+
+ |
+
|
+ PAN-269899
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected when querying for device tags.
+
+ |
+
|
+ PAN-269673
+ |
+
+
+ Fixed an issue where ElasticSearch was not set up after an upgrade.
+
+ |
+
|
+ PAN-269539
+ |
+
+
+ Fixed an issue where whitespace was added before the timestamp in
+ syslog logs forwarded from Panorama.
+
+ |
+
|
+ PAN-269499
+ |
+
+
+ Fixed an issue where the firewall stopped responding when receiving a
+ high number of logs.
+
+ |
+
|
+ PAN-269106
+ |
+
+
+ Fixed an issue where the
+ wifclient might crash during
+ server cert verification for MICA gRPC connections and cause the
+ dataplane to restart when using a cloud-based ML detection engine
+ (MICA). On certain platforms, this caused the firewall to reboot
+ periodically.
+
+ |
+
|
+ PAN-269027
+ |
+
+
+ Fixed an issue related to external dynamic lists that caused commit
+ times on the firewall to be higher than expected.
+
+ |
+
|
+ PAN-269000
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL
+ pointer dereference when path monitoring failed.
+
+ |
+
|
+ PAN-268972
+ |
+
+
+ Fixed an issue where Panorama was slower than expected when using a
+ high number of device group tags in a non-shared context.
+
+ |
+
|
+ PAN-268909
+ |
+
+
+ Fixed an issue where IP address tags were removed from firewalls after
+ a management server or userid process restart. This occurred when a
+ Panorama serial-number based configuration was used for User-ID
+ redistribution.
+
+ |
+
|
+ PAN-268815
+ |
+
+
+ Fixed an issue that caused the firewall to reboot due to the
+ wifclient exiting multiple times
+ when using IoT Security.
+
+ |
+
|
+ PAN-268727
+ |
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy
+ was enabled and header insertion modified packets.
+
+ |
+
|
+ PAN-268501
+ |
+
+
+ Fixed an issue where the firewall was unable to generate a TSF file
+ due to a full root partition.
+
+ |
+
|
+ PAN-268474
+ |
+
+
+ Fixed an issue on the firewall where the PAN-DB URL Filtering license
+ displayed as Valid even when the
+ firewall did not have the license, which caused traffic to drop.
+
+ |
+
|
+ PAN-268419
+ |
+
+
+ Fixed an issue where
+ Managed Devices > Summary
+ displayed incorrect subcolumns.
+
+ |
+
|
+ PAN-268229
+ |
+
+
+ Fixed an issue where the firewall stopped responding during session
+ setup for ECMP hit-count updates.
+
+ |
+
|
+ PAN-268228
+ |
+
+
+ Fixed an issue where Panorama administrators were unable to select
+ Edit Selection when pushing changes
+ to devices if they logged in using TACACS authentication.
+
+ |
+
|
+ PAN-268127
+ |
+
+
+ Fixed an issue where tagging devices in Panorama did not work as
+ expected.
+
+ |
+
|
+ PAN-268118
+ |
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where,
+ after a failover, irrelevant routing FIB entries were seen in the
+ routing table on the newly active firewall.
+
+ |
+
|
+ PAN-268002
+ |
+
+
+ Fixed an issue where URL filtering response pages were not displayed
+ for sites that were blocked as a result of SSL/TLS handshake
+ inspection.
+
+ |
+
|
+ PAN-267934
+ |
+
+
+ Fixed an issue where commits remained at 98%, which resulted in the
+ BGP connection flapping.
+
+ |
+
|
+ PAN-267707
+ |
+
+
+ Fixed an issue where BFD sessions did not come up even when BGP
+ peering was established.
+
+ |
+
|
+ PAN-267660
+ |
+
+
+ Fixed an issue where UserID stopped working when the
+ show object registered user CLI
+ command was used with start-point and limit options.
+
+ |
+
|
+ PAN-267535
+ |
+ + + | +
|
+ PAN-267285
+ |
+
+
+ Fixed an issue where a port was able to be connected from outside the
+ network. With this fix, the port is restricted to the local interface.
+
+ |
+
|
+ PAN-267091
+ |
+
+
+ Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
+
+ |
+
|
+ PAN-267001
+ |
+
+
+ Fixed an issue where multicast streams were unstable with ECMP and
+ dropped every 30 seconds.
+
+ |
+
|
+ PAN-266900
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ click OK after selecting an install
+ package type and file from the dropdown and selecting a firewall.
+
+ |
+
|
+ PAN-266704
+ |
+
+
+ Fixed an issue where filtering BGP routes by peer name in Advanced
+ Routing Engine (ARE) did not display the correct routes.
+
+ |
+
|
+ PAN-266695
+ |
+
+
+ Fixed an issue on Panorama where a cyclic nested address group
+ configuration caused the
+ configd
+ process to stop responding after a commit.
+
+ |
+
|
+ PAN-266653
+ |
+
+
+ Fixed an issue where unexpected path monitor failures caused the
+ firewall to stop responding.
+
+ |
+
|
+ PAN-266639
+ |
+
+
+ Fixed an issue where administrators were unable to edit or add virtual
+ router configurations when a filter was applied to the viewer.
+
+ |
+
|
+ PAN-266391
+ |
+
+
+ Fixed an issue where the number of hints values were not updated even
+ when there were no hint files on the system.
+
+ |
+
|
+ PAN-266354
+ |
+
+
+ Fixed an issue where Hybrid-SWG explicit proxy connections failed when
+ the number of destination domains exceeded 1024.
+
+ |
+
|
+ PAN-266328
+ |
+
+
+ Fixed an issue where the firewall was unable to establish a
+ connection.
+
+ |
+
|
+ PAN-266312
+ |
+
+
+ Fixed an issue where BFD sessions took longer than expected to
+ establish after an HA failover due to BGP.
+
+ |
+
|
+ PAN-266167
+ |
+
+
+ Fixed an issue where the
+ restart option for IPSec tunnels was
+ greyed out (Network > IPSec Tunnels > IKE Info).
+
+ |
+
|
+ PAN-266003
+ |
+
+
+ Fixed an issue on the firewall where a configuration policy push
+ caused both active and passive firewalls to go down when a high number
+ of spyware profiles and vulnerability profiles were pushed to the
+ dataplane.
+
+ |
+
|
+ PAN-265973
+ |
+
+
+ Fixed an issue where administrator sessions were logged out with an
+ ERR_CONNECTION_REFUSED error on
+ the browser.
+
+ |
+
|
+ PAN-265963
+ |
+
+
+ Fixed an issue where the
+ escd
+ process caused a memory leak when session resiliency was enabled on
+ the firewall.
+
+ |
+
|
+ PAN-265931
+ |
+
+
+ Added debug functionality in the
+ packet-diag log to address an
+ issue regarding policy rule matching.
+
+ |
+
|
+ PAN-265742
+ |
+
+
+ Fixed an issue on the Panorama web interface where the
+ OK button on the GlobalProtect
+ gateway configuration dialog box was not clickable.
+
+ |
+
|
+ PAN-265621
+ |
+
+
+ Fixed an issue where the
+ restart option for IPSec tunnels was
+ greyed out when you attempted to restart the tunnel from
+ Network > IPSec Tunnels > IKE Info.
+
+ |
+
|
+ PAN-265462
+ |
+
+
+ Fixed an issue where you were unable to download PDFs when connected
+ via a Clientless VPN.
+
+ |
+
|
+ PAN-265434
+ |
+
+
+ Fixed an issue where the flow process restarted with the error message
+ SIGABRT __GI_raise __GI_abort __libc_message malloc_printer.
+
+ |
+
|
+ PAN-265399
+ |
+
+
+ Fixed an issue where DNS queries for uppercase internal domain (SRV
+ record) timed out when DNS Security was enabled.
+
+ |
+
|
+ PAN-265349
+ |
+
+
+ Fixed an issue where multiple segments of HTTP proxy connect messages
+ were not handled correctly by proxy.
+
+ |
+
|
+ PAN-265344
+ |
+
+
+ Fixed an issue where
+ Import GlobalProtect Client Package
+ did not work after clicking OK after
+ selecting a valid package under
+ Device > GlobalProtect Client > Upload).
+
+ |
+
|
+ PAN-265179
+ |
+
+
+ Fixed an issue where a kernel race condition caused the firewall to
+ reboot with a kernel panic.
+
+ |
+
|
+ PAN-265160
+ |
+
+
+ Fixed an issue where the firewall created multiple connections to a
+ syslog server and remained in the FINWAIT1 state, which caused logs to
+ drop while being forwarded to the syslog server.
+
+ |
+
|
+ PAN-264981
+ |
+
+
+ Fixed an issue on the Panorama web interface where it took longer than
+ expected to edit Security policy rules.
+
+ |
+
|
+ PAN-264871
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when viewing IP addresses on dynamic
+ address groups with a large number of IP addresses.
+
+ |
+
|
+ PAN-264806
+ |
+
+
+ (PA-3440 firewalls only) Fixed an issue where
+ the firewall was unable to validate or commit a configuration when it
+ was imported from another firewall model.
+
+ |
+
|
+ PAN-264794
+ |
+
+
+ Fixed an issue where OSPF adjacencies failed to come up when using a
+ subinterface ID with more than 3 digits on Ethernet ports 1/10 and
+ higher.
+
+ |
+
|
+ PAN-264680
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ Device > Setup was not displayed
+ on the web interface.
+
+ |
+
|
+ PAN-264678
+ |
+
+
+ Fixed an issue where
+ Preview Changes did not display
+ configuration changes in
+ Commit and push >
+ Push Scope.
+
+ |
+
|
+ PAN-264662
+ |
+
+
+ Fixed an issue where HTTP POST requests were blocked for URLs that had
+ the block-continue category
+ configured.
+
+ |
+
|
+ PAN-264289
+ |
+
+
+ Fixed an issue where the CLI and XML API values for the show system
+ environment command did not match.
+
+ |
+
|
+ PAN-264169
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where the firewall sent correlated event logs to the syslog server
+ using the management interface instead of the log interface.
+
+ |
+
|
+ PAN-263987
+ |
+
+
+ Fixed an issue on the firewall where, when a NAT transversal IPSec
+ tunnel was terminated, and the NAT rule that was applied to the NAT-T
+ IPSec tunnel was on the same firewall, traffic flowing through the
+ tunnel was not correctly translated.
+
+ |
+
|
+ PAN-263973
+ |
+
+
+ Fixed an issue where log collectors had a low incoming log rate.
+
+ |
+
|
+ PAN-263956
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where a
+ firewall running PAN-OS 11.1.2-h3 only displayed the
+ Auto option for the interface duplex
+ setting.
+
+ |
+
|
+ PAN-263843
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall received no-license packet buffers instead of memory
+ based packet buffer numbers.
+
+ |
+
|
+ PAN-263749
+ |
+
+
+ Fixed an issue where disk space that was used by file descriptors was
+ not freed, which caused the root partition to become full and Panorama
+ to be inaccessible.
+
+ |
+
|
+ PAN-263505
+ |
+
+
+ (PA-850 firewalls only) Fixed an issue where
+ the firewall stopped responding and rebooted after upgrading to PAN-OS
+ 11.1.4.
+
+ |
+
|
+ PAN-263369
+ |
+
+
+ Fixed an issue where commits from Panorama to Panorama virtual
+ appliances failed with the error message
+ Internal error during commit processing. Commit/Validate
+ failed
+ after upgrading Panorama.
+
+ |
+
|
+ PAN-263291
+ |
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when
+ the GlobalProtect clientless VPN was configured.
+
+ |
+
|
+ PAN-263278
+ |
+
+
+ Fixed an issue where the management interface flapped when IPv6 was
+ disabled and DHCPv6 was enabled.
+
+ |
+
|
+ PAN-263208
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an
+ issue where interrupts were generated at a certain packet rate, and
+ dataplane processes missed heartbeats, which caused the dataplane to
+ go down.
+
+ |
+
|
+ PAN-263164
+ |
+
+
+ Fixed an issue where Netflow User ID information was truncated to 31
+ characters.
+
+ |
+
|
+ PAN-263086
+ |
+
+
+ (PA-455 firewalls in HA configurations only)
+ Fixed an issue where the HA LED light on the front panel did not turn
+ on even when HA was enabled.
+
+ |
+
|
+ PAN-263012
+ |
+
+
+ Fixed an issue where commits failed from a Panorama appliance with a
+ default master key to a firewall with a master key configured and a VM
+ Information source configured.
+
+ |
+
|
+ PAN-262973
+ |
+
+
+ Fixed an issue where changes made by a custom role Panorama
+ administrator did not display in the push scope for other custom role
+ administrators when a full commit was performed.
+
+ |
+
|
+ PAN-262902
+ |
+
+
+ Fixed an issue on the web interface where cloning region objects did
+ not work.
+
+ |
+
|
+ PAN-262511
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where OSPF neighbors
+ were not established after an HA failover.
+
+ |
+
|
+ PAN-262415
+ |
+
+
+ Fixed an issue where a partial configuration load failed for
+ configuration files that contained
+ regenerate-hostkeys.
+
+ |
+
|
+ PAN-261997
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect statistics for
+ mac_transmit_err and send_deffered on PA-440 appliances running PAN-OS
+ 10.1.9-h3.
+
+ |
+
|
+ PAN-261909
+ |
+
+
+ Fixed an issue where the GlobalProtect client did not display the
+ dialog box for an MFA verification code.
+
+ |
+
|
+ PAN-261831
+ |
+
+
+ (Firewalls in HA configuration only) Fixed an
+ issue where link-down events did not occur after an HA failover.
+
+ |
+
|
+ PAN-261673
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled,
+ traffic was dropped because of the 'flow_parse_ip_hdr' counter related
+ to an Nvidia driver issue.
+
+ |
+
|
+ PAN-261671
+ |
+
+
+ Fixed an issue where GlobalProtect clients randomly fell back to the
+ SSL tunnel as the gateway dropped the initial three keepalive packets.
+
+ |
+
|
+ PAN-261639
+ |
+
+
+ Fixed an issue where the firewall incorrectly logged the XFF IP in
+ threat logs when a single HTTP header was used.
+
+ |
+
|
+ PAN-261570
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where packet loss occurred when dataport was used
+ for HA3 for asymmetrically routed traffic during commits and a virtual
+ wire was configured .
+
+ |
+
|
+ PAN-261485
+ |
+
+
+ Fixed an issue where the firewall dropped the Real Time Transport
+ Protocol (RTP) session for the second SIP call on Persistent-DIPP
+ connections when the source port of the client device was reset.
+
+ |
+
|
+ PAN-261484
+ |
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount
+ of memory as requested for pre-allocation.
+
+ |
+
|
+ PAN-261371
+ |
+
+
+ (PA-5410 firewalls in active/passive HA configurations only) Fixed an issue where the
+ reportd
+ process restarted, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-261209
+ |
+
+
+ (Firewalls in active/active HA configuration only) Fixed an issue where the firewall displayed the HA2 status as down
+ when the HSCI port was used for both HA2 and HA3.
+
+ |
+
|
+ PAN-261174
+ |
+
+
+ Fixed an issue on Panorama where importing a certificate for a
+ template stack configuration incorrectly prompted for a passphrase as
+ a required field.
+
+ |
+
|
+ PAN-261028
+ |
+
+
+ Fixed an issue where the firewall did not autocommit after a reboot
+ when the cellular interface was configured as a local interface for
+ the IPSec Satellite and the IP address was allocated dynamically.
+
+ |
+
|
+ PAN-261001
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to switch
+ gateways after upgrading to GlobalProtect version 6.2.3.
+
+ |
+
|
+ PAN-260842
+ |
+
+
+ A CLI command was introduced to address an issue where TCP packets
+ were out of order.
+
+ |
+
|
+ PAN-260796
+ |
+
+
+ Fixed an issue where servers were not accessible through an active SSL
+ GlobalProtect VPN tunnel until a new connection was established or the
+ session was cleared on the firewall.
+
+ |
+
|
+ PAN-260738
+ |
+
+
+ Fixed an issue on the Panorama web interface where the progress bar
+ did not complete when importing a vulnerability profile configuration
+ through an XML file.
+
+ |
+
|
+ PAN-260633
+ |
+
+
+ Fixed an issue where the firewall did not send a client certificate
+ after a TLS Certificate Request when establishing a secure syslog
+ connection.
+
+ |
+
|
+ PAN-260604
+ |
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput
+ utilization stats in NetFlow analyzer tools.
+
+ |
+
|
+ PAN-260564
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where a network loop
+ was detected by switches after suspending HA on the active firewall.
+
+ |
+
|
+ PAN-260549
+ |
+
+
+ Fixed an issue where the management plane CPU usage was not calculated
+ correctly on firewalls with integrated an dataplane and management
+ plane.
+
+ |
+
|
+ PAN-260546
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where
+ the system clock reset to the epoch date and time after 8 to 12 weeks
+ of shelf life or no power.
+
+ |
+
|
+ PAN-260417
+ |
+
+
+ Fixed an issue on Panorama where
+ UpdateLicDB was triggered every
+ few minutes when firewalls with PAYG licenses were onboarded.
+
+ |
+
|
+ PAN-260358
+ |
+
+
+ Fixed an issue where the firewall did not include the NAS-ID and
+ NAS-IP attributes in the RADIUS Access-Request message when using
+ PEAP-MSCHAPv2 authentication.
+
+ |
+
|
+ PAN-260290
+ |
+
+
+ Fixed an issue for fixed model licenses to support new content size
+ requirements by reducing the total sessions supported to be equivalent
+ to their flex memory counterpart
+
+ |
+
|
+ PAN-260279
+ |
+
+
+ Fixed an issue where selective push operations failed with the error
+ message:
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+
|
+ PAN-260218
+ |
+
+
+ Fixed an issue where BGP Aggregate Advertise filters did not work as
+ expected when the summary option was enabled, and only summarized
+ routes were advertised.
+
+ |
+
|
+ PAN-260193
+ |
+
+
+ Fixed an issue where GlobalProtect on macOS clients did not connect
+ when using a client certificate and the X.509 policy was set to
+ Use System Default.
+
+ |
+
|
+ PAN-260149
+ |
+
+
+ Fixed an issue where the management plane DNS cache size was lower
+ than expected.
+
+ |
+
|
+ PAN-260132
+ |
+
+
+ Fixed an issue where secondary IP addresses with a /32 prefix
+ configured on Layer 3 interfaces were not reachable in FRR mode.
+
+ |
+
|
+ PAN-260131
+ |
+
+
+ Fixed an issue where the firewall consumed a large amount of memory
+ when forwarding raw logs.
+
+ |
+
|
+ PAN-260114
+ |
+
+
+ Fixed an issue where the firewall generated a
+ devsrvr
+ core file when processes were restarted.
+
+ |
+
|
+ PAN-259883
+ |
+
+
+ Fixed an issue where the firewalls behind an Amazon Web Services (AWS)
+ Gateway Load Balancer (GWLB) stopped responding when processing GENEVE
+ packets with the reserved bit set.
+
+ |
+
|
+ PAN-259881
+ |
+
+
+ Fixed an issue on Panorama where traffic log details were not
+ displayed under detailed log view.
+
+ |
+
|
+ PAN-259870
+ |
+
+
+ (PA-7000b firewalls only) Fixed an issue where
+ Luna Network Hardware Security Modules (HSM) did not work after an
+ upgrade or downgrade.
+
+ |
+
|
+ PAN-259802
+ |
+
+
+ (Panorama appliances in HA clusters only) Fixed
+ an issue where, after replacing a secondary Panorama appliance in a
+ Panorama HA cluster, the ElasticSearch cluster was unable to establish
+ SSL tunnels due to SSLHandshakeException errors.
+
+ |
+
|
+ PAN-259706
+ |
+
+
+ Fixed an issue on Panorama where the web interface was slower than
+ expected or unresponsive when monitoring definitions were added in the
+ Kubernetes plugin.
+
+ |
+
|
+ PAN-259200
+ |
+
+
+ Fixed an issue where the firewall displayed truncated zone names in
+ the Block IP List log when a zone
+ name contained more than 14 characters.
+
+ |
+
|
+ PAN-259078
+ |
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and
+ the following error message was displayed:
+ Error 500: Internal Server Error.
+
+ |
+
|
+ PAN-258996
+ |
+
+
+ Fixed an issue where the firewall displayed the SFP ports as
+ PowerDown when the SFP
+ transceiver was removed and reinserted or the port was shut down and
+ brought back up on the peer device.
+
+ |
+
|
+ PAN-258757
+ |
+
+
+ Fixed an issue on Panorama where upgrades failed with validation
+ errors.
+
+ |
+
|
+ PAN-258736
+ |
+
+
+ Fixed an issue where policy rule configurations pushed from Panorama
+ were not reflected on the firewall if the rule had 63 characters.
+
+ |
+
|
+ PAN-258734
+ |
+
+
+ Fixed an issue where virtual wire ports did not go down when moving
+ from an active state to a suspended state.
+
+ |
+
|
+ PAN-258680
+ |
+
+
+ Fixed an issue on Panorama where, when you removed Security profile
+ groups from a Security policy rule via the CLI and committed the
+ change, the Security policy rule was deleted.
+
+ |
+
|
+ PAN-258576
+ |
+
+
+ Fixed an issue on the Panorama web interface where products in HIP
+ objects were not displayed correctly.
+
+ |
+
|
+ PAN-258570
+ |
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the
+ varrcvr
+ process progressively using more memory when WildFire file forwarding
+ is handling PE files.
+
+ |
+
|
+ PAN-258240
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where HA path monitoring did not work as expected when using
+ vwire.
+
+ |
+
|
+ PAN-258225
+ |
+
+
+ Fixed an issue on the Panorama web interface where Security policy
+ rules loaded more slowly than expected.
+
+ |
+
|
+ PAN-258188
+ |
+
+
+ Fixed an issue on Panorama Template where the virtual wire
+ subinterface page did not display all fields and the
+ OK button did not work.
+
+ |
+
|
+ PAN-258149
+ |
+
+
+ Fixed an issue where the firewall dropped the SYN-ACK when using the
+ TCP Fast Open option.
+
+ |
+
|
+ PAN-257961
+ |
+
+
+ Fixed an issue on Panorama where
+ Test Security Policy Match failed
+ when the From or
+ To zone fields were populated.
+
+ |
+
|
+ PAN-257912
+ |
+
+
+ Fixed an issue where the firewall stopped responding when it received
+ RADIUS traffic and user equipment (UE) traffic at the same time on a
+ Network Processing Card (NPC)
+
+ |
+
|
+ PAN-257660
+ |
+
+
+ Fixed an issue where show commands were hidden for superusers in
+ read-only roles.
+
+ |
+
|
+ PAN-257600
+ |
+
+
+ Fixed an issue where the firewall returned a 404 error for all sites
+ accessed through the clientless VPN portal.
+
+ |
+
|
+ PAN-257267
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ observed warning message during commit completion & critical
+ system log when configuration size exceeded the maximum recommended
+ configuration size.
+
+ |
+
|
+ PAN-257117
+ |
+
+
+ Fixed an issue where CSV or PDF exports of zones did not contain all
+ zones.
+
+ |
+
|
+ PAN-257028
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and
+ displayed the error message
+ Dataplane down: path monitor failure during the fail-over.
+
+ |
+
|
+ PAN-257021
+ |
+
+
+ "Fixed an issue on the web interface where
+ Match Evidence log details for
+ Monitor > Correlated events did
+ not populate."
+
+ |
+
|
+ PAN-256960
+ |
+
+
+ Fixed an issue where a custom portal login page was not displayed
+ correctly in the GlobalProtect portal when using a customized portal
+ landing page.
+
+ |
+
|
+ PAN-256725
+ |
+
+
+ Fixed an issue on the Panorama interface where
+ Traffic and
+ Unified event details loaded more
+ slowly than expected.
+
+ |
+
|
+ PAN-256669
+ |
+
+
+ Fixed an issue where the memory usage reported by SNMP did not match
+ the memory usage reported by the top command.
+
+ |
+
|
+ PAN-256518
+ |
+
+
+ Fixed an issue where Panorama was unable to push firmware updates to a
+ VM-Series firewall with a PAYG license.
+
+ |
+
|
+ PAN-256449
+ |
+
+
+ Fixed an issue where DHCPv6 relay was not working in Advanced Routing
+ mode when the firewall was configured as a DHCP relay agent.
+
+ |
+
|
+ PAN-256350
+ |
+
+
+ Fixed an issue where, when you cloned an admin role or an LDAP server
+ profile and then changed the name of the clone, the configuration
+ change was not reflected on the managed firewall after pushing the
+ configuration from Panorama.
+
+ |
+
|
+ PAN-256320
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where GTP sessions remained as allocated sessions on
+ the passive firewall even when there were no active sessions.
+
+ |
+
|
+ PAN-256115
+ |
+
+
+ Fixed an issue where, after replacing a Panorama appliance or log
+ collector, the secondary Panorama appliance or log collector displayed
+ a disconnected status for the
+ inter-log collector connection.
+
+ |
+
|
+ PAN-255930
+ |
+
+
+ Fixed an issue where persistent DIPP NAT entries were deleted even
+ when being used during an active session.
+
+ |
+
|
+ PAN-255915
+ |
+
+
+ Fixed an issue where a memory leak in the
+ sslmgr
+ process caused the firewall to restart.
+
+ |
+
|
+ PAN-255747
+ |
+
+
+ Fixed an issue on the firewall where CLI commands returned
+ Server error: op command for client dagger timed out as client is
+ not available.
+
+ |
+
|
+ PAN-255360
+ |
+
+
+ Fixed an issue where the firewall booted into maintenance mode when
+ there was no connectivity to the specified hardware security module
+ (HSM).
+
+ |
+
|
+ PAN-254901
+ |
+
+
+ Fixed an issue where GlobalProtect user-to-IP address mapping was
+ removed even though the tunnel for the specific user was up and
+ traffic was being passed.
+
+ |
+
|
+ PAN-254797
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where you were unable to use SNMP polling o monitor the status of
+ power supply units.
+
+ |
+
|
+ PAN-254794
+ |
+
+
+ Fixed an issue where the Panorama management server stopped
+ responding.
+
+ |
+
|
+ PAN-254671
+ |
+
+
+ Fixed an issue where excessive
+ Timed out while getting config lock
+ error messages were generated when making bulk changes via XML API.
+
+ |
+
|
+ PAN-254301
+ |
+
+
+ Fixed an issue where GlobalProtect logs showed the public IPv4 address
+ in the private IPv4 address field for logs generated during
+ portal/gateway negotiation.
+
+ |
+
|
+ PAN-254124
+ |
+
+
+ (PA-7050 firewalls with DPC and 100G NPCs only)
+ Fixed an issue on the firewall where you were unable to change the
+ flow key type from tag to tuple.
+
+ |
+
|
+ PAN-253626
+ |
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the
+ firewall, which caused the push operations to intermittently fail.
+
+ |
+
|
+ PAN-253584
+ |
+
+
+ Fixed an issue where ikemgr process unexpectedly stopped due to a
+ memory mapping in an incorrect location.
+
+ |
+
|
+ PAN-253485
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration
+ failed on the active firewall with the error
+ op command for client dagger timed out as client is not
+ available.
+
+ |
+
|
+ PAN-252816
+ |
+
+
+ Fixed an issue where multiple SSHD process restarts triggered a
+ firewall reboot when the login banner and SSH host keys were updated
+ at the same time.
+
+ |
+
|
+ PAN-252801
+ |
+
+
+ Fixed an issue where the LSVPN tunnel monitoring status displayed as
+ No data available after re-key
+ events.
+
+ |
+
|
+ PAN-252604
+ |
+
+
+ Fixed an issue where the clientless VPN did not carry authentication
+ to other tabs.
+
+ |
+
|
+ PAN-252370
+ |
+
+
+ Fixed an issue where services with the reserved keyword
+ application-default were allowed.
+
+ |
+
|
+ PAN-252300
+ |
+
+
+ Fixed an issue where you were unable to select device groups in the
+ push scope for user accounts.
+
+ |
+
|
+ PAN-252270
+ |
+
+
+ Fixed an issue on the firewall where changes were incorrectly applied
+ after a reboot or a restart of the
+ configd
+ process.
+
+ |
+
|
+ PAN-252224
+ |
+
+
+ Fixed an issue where Panorama did not forward logs to a syslog server
+ over an SSL connection using CRL as a revocation verification method.
+
+ |
+
|
+ PAN-252036
+ |
+
+
+ Fixed an issue where, when the GlobalProtect portal was not
+ configured, accessing the GlobalProtect gateway still loaded a portal
+ malformed page.
+
+ |
+
|
+ PAN-252029
+ |
+
+
+ Fixed an issue where the firewall stopped responding when processing
+ authentication requests.
+
+ |
+
|
+ PAN-251484
+ |
+
+
+ Fixed an issue where the firewall web interface displayed incorrect
+ PPPoE configuration options under the subinterface of an Aggregate
+ Ethernet interface.
+
+ |
+
|
+ PAN-250928
+ |
+
+
+ (PA-5450 firewalls in active/active HA configurations only) Fixed an issue where firewall traffic was silently dropped when
+ sent to the peer owner.
+
+ |
+
|
+ PAN-250703
+ |
+
+
+ Fixed an issue where the task manager failed with a 504 error when a
+ large number of previous jobs or tasks were present.
+
+ |
+
|
+ PAN-250443
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ multiple processes exited due to an OOM condition and caused a network
+ outage.
+
+ |
+
|
+ PAN-249581
+ |
+
+
+ Fixed an issue where stale BGP routes were advertised to peers even
+ when they were not present in the local RIB table.
+
+ |
+
|
+ PAN-249533
+ |
+
+
+ Fixed an issue where an internal error message was displayed when you
+ selected
+ Exclude video traffic from the tunnel (Windows and macOS
+ only).
+
+ |
+
|
+ PAN-249384
+ |
+
+
+ Fixed an issue on Panorama where configuration locks were observed
+ during a partial rulebase commit.
+
+ |
+
|
+ PAN-249072
+ |
+
+
+ Fixed an issue where content upgrade installation failed with the
+ error
+ Error: can't find cert <cert> when using cloud
+ interfaces.
+
+ |
+
|
+ PAN-247052
+ |
+
+
+ Fixed an intermittent issue where the OSPF ABR option was disabled
+ when a static route was added.
+
+ |
+
|
+ PAN-246567
+ |
+
+
+ Fixed an issue where a firewall with a copper SFP transceiver
+ (PAN-SFP-CG) flapped during a commit.
+
+ |
+
|
+ PAN-246304
+ |
+
+
+ Fixed an issue on Panorama where commits failed due to a timeout in
+ the
+ sysd
+ process during decryption.
+
+ |
+
|
+ PAN-245545
+ |
+
+
+ Fixed an issue where, when you were connected to the VPN and enabled
+ the client accelerator, you were disconnected from the VPN.
+
+ |
+
|
+ PAN-245058
+ |
+
+
+ Fixed an issue on the Panorama web interface where tagging a new user
+ failed the error message
+ Tags addition failed.
+
+ |
+
|
+ PAN-244743
+ |
+
+
+ Fixed an issue where intermittent 500 errors occurred when making API
+ calls to the firewall.
+
+ |
+
|
+ PAN-244708
+ |
+
+
+ Fixed an issue where the GlobalProtect VPN connection inactivity TTL
+ value became negative, which caused the VPN to disconnect when the
+ system time was changed back to the past time.
+
+ |
+
|
+ PAN-244039
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the firewall dropped packets when attempting to reuse a TCP session.
+
+ |
+
|
+ PAN-243786
+ |
+
+
+ Fixed an issue on Panorama where custom GlobalProtect reports
+ displayed inaccurate values.
+
+ |
+
|
+ PAN-242991
+ |
+
+
+ Fixed an issue where the web interface stopped responding when you
+ searched for members in an address group that contained more than 500
+ members.
+
+ |
+
|
+ PAN-242957
+ |
+
+
+ Fixed an issue where the
+ Rule usage columns of overridden
+ default policy rules on the Security policy page stopped responding.
+
+ |
+
|
+ PAN-242602
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced slow SMB-V3
+ download throughput when passing through a Prisma IPSec tunnel and the
+ firewall and the SMB-V3 session owner dataplane was the same as the
+ IPSec-ESP tunnel on the multi-dataplane firewall.
+
+ |
+
|
+ PAN-238793
+ |
+
+
+ (Panorama virtual appliances in Microsoft Azure environments
+ only) Fixed an issue where a bootstrapped Panorama appliance did not
+ automatically retrieve the CDL license, which resulted in the firewall
+ not automatically sending logs to CDL.
+
+ |
+
|
+ PAN-238741
+ |
+
+
+ Fixed an issue where, after a selective push of the configuration, a
+ parent device group object with multiple child device groups was not
+ shown in the device group's push scope.
+
+ |
+
|
+ PAN-221096
+ |
+
+
+ Fixed an issue where IPSec transport mode failed when the firewall was
+ the initiator.
+
+ |
+
|
+ PAN-216054
+ |
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while
+ it was idle.
+
+ |
+
|
+ PAN-214430
+ |
+
+
+ Fixed an issue where some commands did not have executable
+ permissions.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ Fixed an issue on Panorama where different threat names were used when
+ querying a threat under
+ Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after
+ clicking a threat name in
+ Threat Monitor and filtering it in
+ the global filters.
+
+ |
+
|
+ PAN-199141
+ |
+
+
+ Fixed an issue where renaming a device group and then performing a
+ partial commit led to the device group hierarchy being incorrectly
+ changed.
+
+ |
+
|
+ PAN-192176
+ |
+
+
+ Fixed an issue where the management server access log file did not
+ rotate, which caused the root partition to become full and led to
+ system instability.
+
+ |
+
|
+ PAN-76904
+ |
+
+
+ (PA-5410 firewalls only) Fixed an issue where
+ the management interface went down and an error message displayed in
+ the show interface management CLI
+ command output.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-287812
+ |
+
+
+ Fixed an intermittent issue where the dataplane stopped responding
+ when advanced DNS was enabled.
+
+ |
+
|
+ PAN-286255
+ |
+
+
+ Fixed an issue where, when the firewall received an unexpected
+ termination request for SSL sessions, the dataplane experienced a slow
+ buffer resource leak.
+
+ |
+
|
+ PAN-284908
+ |
+
+
+ Fixed an issue where retrieving filenames from OneDrive resulted in a
+ cache miss.
+
+ |
+
|
+ PAN-284116
+ |
+
+
+ Fixed an issue where mTLS decryption bypass did not work when the
+ decryption profile was configured with the maximum TLS version as TLS
+ 1.3.
+
+ |
+
|
+ PAN-284036
+ |
+
+
+ (PA-450R and PA-450R-5G firewalls only) Fixed
+ an issue where the maximum temperature threshold and shutdown
+ threshold were not set correctly.
+
+ |
+
|
+ PAN-283467
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall unexpectedly rebooted and entered maintenance mode
+ due to a ctd-agent out-of-memory (OOM) condition. This occurred during
+ advanced services load testing and a high volume of IoT EAL log
+ forwarding.
+
+ |
+
|
+ PAN-282968
+ |
+
+
+ Fixed an issue where the firewall did not identify the test threat
+ file when the content was installed via a traditional bootstrap.
+
+ |
+
|
+ PAN-282236
+ |
+
+
+ Fixed an issue where large IPv6 packets were reassembled incorrectly
+ on the firewall when the packets arrived fragmented over an IPv4
+ tunnel.
+
+ |
+
|
+ PAN-282206
+ |
+
+
+ Fixed an issue where configuring Secure Web Gateway (SWG) in
+ no-auth mode led to latency when no
+ decryption policy rules or
+ No-decrypt policy rules were
+ present.
+
+ |
+
|
+ PAN-282069
+ |
+
+
+ Fixed an issue on Panorama where Security policy rules were removed
+ from device groups when you cloned or edited Security policy rules
+ that used more than 63 characters.
+
+ |
+
|
+ PAN-282022
+ |
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700
+ appliances.
+
+ |
+
|
+ PAN-280700
+ |
+
+
+ Fixed an Issue where commits failed with the error
+ invalid IPv6 x:x - must be global/link-local unicast
+ when the management IPv6 address had a specific value.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ Fixed an issue where navigating
+ Panorama > Monitor > Logs was
+ slower than expected.
+
+ |
+
|
+ PAN-279983
+ |
+
+
+ (PA-1400 Series firewalls only) Fixed an issue
+ on the web interface where
+ Enable Bonjour Reflector was not
+ displayed (Network > Interfaces > Ethernet Interface).
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client
+ Hello arrived at the firewall in multiple out-of-order segments and
+ the traffic was not subject to SSL decryption.
+
+ |
+
|
+ PAN-279621
+ |
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward
+ traffic was run.
+
+ |
+
|
+ PAN-279197
+ |
+
+
+ (PA-450R-5G firewalls only) Fixed an issue
+ where the firewall stopped responding and displayed the error message
+ Thermal temperature exceeds system threshold! Shutting down
+ NOW
+ even when the firewall was within the threshold.
+
+ |
+
|
+ PAN-279191
+ |
+
+
+ Fixed an issue where a GlobalProtect gateway stopped responding when
+ handling HTTP/1.1 traffic with web inspection enabled.
+
+ |
+
|
+ PAN-278684
+ |
+
+
+ (PA-445 firewalls only) Fixed an issue where
+ the firewall did not properly power cycle during a reboot.
+
+ |
+
|
+ PAN-278322
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) Gateway Load
+ Balancer (GWLB) deployments only) Fixed an issue where the firewall did not display the correct
+ source user in traffic logs and session details.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ Fixed an issue where the system MAC address of the aggregate interface
+ was the same on the active firewall and the passive firewall after an
+ upgrade.
+
+ |
+
|
+ PAN-277762
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
+
+ |
+
|
+ PAN-277751
+ |
+
+
+ Fixed an issue where a policy-based forwarding (PBF) rule with an
+ action of no-pbf and a service of
+ TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a
+ result, traffic was matched by a lower rule with a service of
+ any and an action of
+ forward.
+
+ |
+
|
+ PAN-277629
+ |
+
+
+ Fixed an issue where the firewall did not match the correct policy for
+ SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS
+ 10.2.9-h1 to PAN-OS 11.2.3.
+
+ |
+
|
+ PAN-277417
+ |
+
+
+ Fixed an memory leak issue related to TLS inbound decryption.
+
+ |
+
|
+ PAN-277135
+ |
+
+
+ Fixed an issue where the firewall stopped responding when a DNS client
+ closed or reset a TCP connection while the firewall was sending a
+ response.
+
+ |
+
|
+ PAN-276822
+ |
+
+
+ Fixed an issue where the packet buffer size increased significantly
+ when WildFire File Forwarding was continued after a threat detection
+ and then canceled.
+
+ |
+
|
+ PAN-276607
+ |
+
+
+ Fixed an issue where GlobalProtect users experienced DNS resolution
+ timeouts when using Prisma Access.
+
+ |
+
|
+ PAN-276546
+ |
+
+
+ Fixed an issue where a session lost the PBF rule mapping after a
+ configuration change or commit.
+
+ |
+
|
+ PAN-276177
+ |
+
+
+ Fixed an issue where
+ App Acceleration did not work with
+ Oracle databases.
+
+ |
+
|
+ PAN-276090
+ |
+
+
+ Fixed an issue where the DLP feature did not work as expected and
+ performance issues occurred when uploading files. This was caused by
+ incomplete error handling when writing CTD WIF messages to shared
+ memory and incomplete checking of parameters when freeing entries in
+ the shared memory.
+
+ |
+
|
+ PAN-276016
+ |
+
+
+ Fixed an issue where Prisma Access cap700 instances did not insert
+ HTTP headers when accessing certain Google domains if the 32 byte pool
+ size was low.
+
+ |
+
|
+ PAN-275032
+ |
+
+
+ (M-600 appliances only) Fixed an issue where
+ the Elasticsearch cluster certificate (CC) status displayed with a
+ past expiration date, which caused all shards to be unassigned.
+
+ |
+
|
+ PAN-274592
+ |
+
+
+ (Firewalls in high availability (HA) configurations only) Fixed an issue where the firewall did not fail over when the active
+ firewall experienced data plane issues.
+
+ |
+
|
+ PAN-274314
+ |
+
+
+ (PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400
+ Series firewalls only) Fixed an issue where, when the
+ pan_task
+ process restarted, control plane packets were dropped, which could
+ impact LACP and pings to host interfaces.
+
+ |
+
|
+ PAN-273949
+ |
+
+
+ Fixed an issue where the firewall generated the following error
+ message in the
+ snmpd
+ logs:
+ pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
+ X2F1dGhfa2V5 import from cryptod failed.
+
+ |
+
|
+ PAN-273727
+ |
+
+
+ Fixed an issue where the firewall skipped the DNS policy rule of a
+ domain external dynamic list (EDL) during an EDL refresh.
+
+
+ To use this fix, run the following CLI command and commit:
+ set deviceconfig setting ctd custom-edl-domains-continuous-reload
+ yes/no
+
+ |
+
|
+ PAN-273195
+ |
+
+
+ Fixed an issue where the firewall did not log the correct NAT IP
+ address and source zone for HTTP2 traffic with SSL decryption enabled
+ on RNHP nodes.
+
+ |
+
|
+ PAN-273129
+ |
+
+
+ Fixed an issue on the web interface where the
+ negate option was visible when you
+ clicked on the rule name, but not when you viewed the target options
+ from the rulebase attribute.
+
+ |
+
|
+ PAN-273026
+ |
+
+
+ Fixed an issue where traffic logs did not display correctly when
+ filters were applied.
+
+ |
+
|
+ PAN-273021
+ |
+
+
+ Fixed an issue where 25G port links did not come up due to a change in
+ the handling of 25G DAC modules.
+
+ |
+
|
+ PAN-272959
+ |
+
+
+ Fixed an issue where the firewall generated BGP update packets larger
+ than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames
+ were enabled globally.
+
+ |
+
|
+ PAN-272849
+ |
+
+
+ Fixed an issue where log forwarding to a UDP syslog server stopped
+ when an unreachable TCP syslog server was configured and applied.
+
+ |
+
|
+ PAN-272538
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding during a commit-all validation when there
+ were uncommitted changes and
+ share-unused-objects-with-devices
+ was set to off.
+
+ |
+
|
+ PAN-272171
+ |
+
+
+ Fixed an issue where the firewall dropped the AAAA DNS server response
+ and caused delays in traffic from Ubuntu or Linux clients when DNS
+ Security was enabled.
+
+ |
+
|
+ PAN-272085
+ |
+
+
+ Fixed an issue where the firewall unexpectedly stopped responding and
+ rebooted when DoH was enabled for DNS Security and multiple DoH
+ transactions were sent in a single HTTP/1 connection.
+
+ |
+
|
+ PAN-271912
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when filtering in the configuration audit
+ window after upgrading to PAN-OS 11.1.3.
+
+ |
+
|
+ PAN-271701
+ |
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
+ Enhanced Application Log stopped working due to incorrect memory usage
+ accounting, which caused memory usage to remain at 99% after an
+ extended period of time.
+
+ |
+
|
+ PAN-271314
+ |
+
+
+ Fixed an issue where pushing changes to a prefix list used for BGP
+ from Panorama affected OSPF routes.
+
+ |
+
|
+ PAN-271273
+ |
+
+
+ Fixed an issue where dynamic update downloads failed when
+ IPv6 firewalling was enabled on the
+ firewall and both IPv4 and IPv6 were configured on the management
+ interface.
+
+ |
+
|
+ PAN-271181
+ |
+
+
+ Fixed an issue where committing changes to Advanced Routing and
+ redistribution profiles failed while pushing the configuration from
+ SCM.
+
+ |
+
|
+ PAN-271152
+ |
+
+
+ (7000-Series firewalls in HA configurations only) Fixed an issue where the firewall failed over into a non-functional
+ state, and the LFC LED was blinking on the passive firewall.
+
+ |
+
|
+ PAN-270607
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where OSPF failed to establish after a failover from
+ the active firewall to the passive firewall.
+
+ |
+
|
+ PAN-270471
+ |
+
+
+ Firewalls in active/active configurations only)
+ Fixed an issue where the firewall did not detect configuration changes
+ when only the interface of an IKE gateway was changed, which caused
+ IPSec tunnels to not come up after migrating the IKE gateway IP
+ address from a subinterface to a physical interface.
+
+ |
+
|
+ PAN-269956
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused internal path monitor
+ failures.
+
+ |
+
|
+ PAN-269731
+ |
+
+
+ Fixed an issue where Panorama did not display logs from firewalls
+ after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
+ getting restarted continuously.
+
+ |
+
|
+ PAN-269291
+ |
+
+
+ Fixed an issue where the scheduled report generation script did not
+ return debug information.
+
+ |
+
|
+ PAN-269052
+ |
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile
+ even though the Security policy rule did not have a URL filtering
+ profile configured.
+
+ |
+
|
+ PAN-268705
+ |
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP
+ traffic after upgrading to PAN-OS 10.1.14.
+
+ |
+
|
+ PAN-268168
+ |
+
+
+ Fixed an issue where uploading files that were 5GB or larger to Google
+ Drive or YouTube failed when a decryption policy rule for http2 was
+ enabled.
+
+ |
+
|
+ PAN-267662
+ |
+
+
+ Fixed an issue where the firewall experienced a memory out-of-bounds
+ access when the firewall was configured with SD-WAN and the SD-WAN
+ plugin was loading, which caused the firewall to stop responding and
+ drop VPN tunnels.
+
+ |
+
|
+ PAN-267580
+ |
+
+
+ Fixed an issue where an External Dynamic List (EDL) IP address in an
+ unsupported format was recognized as valid on the firewall.
+
+ |
+
|
+ PAN-267489
+ |
+
+
+ Fixed an issue where firewalls on PAN-OS 11.2 releases were not able
+ to successfully onboard to SCM with ZTP due to a commit failure in the
+ bootstrap process.
+
+ |
+
|
+ PAN-267444
+ |
+
+
+ Fixed an issue where large file downloads or uploads failed or
+ remained in an incomplete state when using DLP HTTP2 mirror mode.
+
+ |
+
|
+ PAN-265219
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ GRE traffic did not work properly.
+
+ |
+
|
+ PAN-265021
+ |
+
+
+ Fixed an issue where the firewall did not inspect NXDomain responses
+ and follow the regular traffic inspection flow.
+
+ |
+
|
+ PAN-261998
+ |
+
+
+ Fixed an issue where the firewall configuration process restarted
+ during an External Dynamic List refresh or a commit and push
+ operation.
+
+ |
+
|
+ PAN-261825
+ |
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or
+ Advanced URL Filtering were enabled. This occurred when the payload
+ size was greater than 3.5 KB.
+
+ |
+
|
+ PAN-261429
+ |
+
+
+ Fixed an issue where the
+ show auth radius-require-msg-authentic
+ command CLI displayed no output.
+
+ |
+
|
+ PAN-260300
+ |
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the
+ all_pktproc
+ process where DPC slot 3 stopped responding.
+
+ |
+
|
+ PAN-260235
+ |
+
+
+ Fixed an issue where the firewall sent Threat logs and URL logs to an
+ external syslog server without Security profile settings when Enhanced
+ Application Logging was enabled.
+
+ |
+
|
+ PAN-260090
+ |
+
+
+ Fixed an issue where commit all operations failed when the application
+ openair-psa was used as a keyword
+ on a remote network instance that was upgraded to PAN-OS 10.2.4-h20.
+
+ |
+
|
+ PAN-260015
+ |
+
+
+ Fixed an issue on the firewall where enabling Inline Cloud Analysis
+ features might cause the firewall to unexpectedly reboot, due to an
+ issue related to loopback data handling.
+
+ |
+
|
+ PAN-259076
+ |
+
+
+ Fixed an issue where the firewall displayed an OCSP/CRL check failure
+ when accessing websites.
+
+ |
+
|
+ PAN-257619
+ |
+
+
+ Fixed an issue on Panorama where the
+ Task Manager took longer than
+ expected to display managed firewall report tasks.
+
+ |
+
|
+ PAN-255914
+ |
+
+
+ (VM-Series firewalls on AWS environments only)
+ Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-255619
+ |
+
+
+ Fixed an intermittent issue where file downloads from websites failed
+ when decrypting HTTP/2 traffic.
+
+ |
+
|
+ PAN-252381
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected when opening interfaces, virtual routers, and zones in a
+ template or template stack.
+
+ |
+
|
+ PAN-245064
+ |
+
+
+ (Multi-vsys firewalls only) Fixed an issue
+ where commits failed on the firewall after selecting
+ Export or push device config bundle
+ on Panorama and a force push was required.
+
+ |
+
|
+ PAN-233647
+ |
+
+
+ Fixed an issue where Panorama management servers generated duplicate
+ configuration logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-294436
+ |
+ + Fixed an issue where polling failed for ethernet interfaces due to the + physical port counters read from the MAC being 0. + | +
|
+ PAN-293842
+ |
+
+
+ Fixed an issue where the hybrid-SWG service proxy stopped working
+ after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to
+ establish the listening interface.
+
+ |
+
|
+ PAN-293673
+ |
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM
+ condition caused by a scheduled log export using FTP to an external
+ FTP server.
+
+ |
+
|
+ PAN-292503
+ |
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP
+ addresses did not display in traffic and threat logs.
+
+ |
+
|
+ PAN-291060
+ |
+
+
+ Fixed an issue where commits failed due to the configured connected
+ gateway IPv6 address in the NAT64 policy exceeding the 31 character
+ limit.
+
+ |
+
|
+ PAN-290996
+ |
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS
+ (Connections Per Second) per vsys on firewalls after upgrading to
+ PAN-OS 11.1.6-h3, even when active connections were present.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ Fixed an issue where a memory leak occurred related to the
+ configd
+ process when pushing configurations from Panorama to a firewall. This
+ occurred when the configurations contained shared policy rules.
+
+ |
+
|
+ PAN-289714
+ |
+
+
+ (Prisma Access only) Fixed an issue where
+ persistent commit failures occurred due to a missing transformation
+ script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0.
+
+ |
+
|
+ PAN-289268
+ |
+ + Fixed an issue where internet access through Secure Web Gateway (SWG) + proxy nodes did not work when the default internet access policy rule + source user was not known-user. + | +
|
+ PAN-288939
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to an invalid SSL context being used
+ for socket communication, which caused commits to fail.
+
+ |
+
|
+ PAN-284878
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where commits failed due the
+ useridd
+ process restarting.
+
+ |
+
|
+ PAN-284003
+ |
+
+
+ Fixed an issue where clients did not receive a valid response when
+ when searching a website due to a compression error.
+
+ |
+
|
+ PAN-280409
+ |
+
+
+ Fixed an issue where the popup window did not appear as expected for
+ Clientless VPN users.
+
+ |
+
|
+ PAN-279901
+ |
+
+
+ An issue was fixed where the firewall dropped fragmented TLS
+ ClientHello packets, which blocked access to certain websites. This
+ occurred because the packets arrived truncated, in varying sizes and
+ orders, and the firewall's heuristics failed to handle them correctly.
+
+
+ To enable this fix, run:
+ debug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
|
+ PAN-279690
+ |
+
+
+ Fixed an issue where the the
+ all_pktproc
+ process stopped responding, which caused the firewall to unexpectedly
+ restart.
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Fixed an issue where service routes configured to use a data plane
+ interface incorrectly used the management plane interface for traffic
+ transmission. This issue affected syslog and CRL status traffic when a
+ custom service route was not configured.
+
+ |
+
|
+ PAN-276616
+ |
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet
+ were not visible.
+
+ |
+
|
+ PAN-271810
+ |
+
+
+ Fixed an issue where auto-negotiation advertised and negotiated 10/100
+ half and full duplex.
+
+ |
+
|
+ PAN-268787
+ |
+
+
+ Fixed an issue where users were unable to log in to Panorama and the
+ following error message was displayed:
+ Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of
+ devices.
+
+ |
+
|
+ PAN-255860
+ |
+
+
+ (PA-5200 firewalls only) Fixed an issue where
+ the
+ all_pktproc
+
+ process stopped responding when the firewall was under a heavy traffic
+ load.
+
+ |
+
|
+ PAN-252706
+ |
+
+
+ Fixed an issue where the URL filtering response page for
+ Continue and
+ Override did not work with IPv6
+ Router Advertisement (RA) or Multicast Listener Query (MLQ) for
+ IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-310868
+ |
+
+
+ Fixed an issue where PA Explicit proxy blocked ICMP packets from
+ flowing towards Envoy for Geneve due to the router not camping MSS
+ when the MTU was lower in the path.
+
+ |
+
|
+ PAN-307901
+ |
+
+
+ Fixed an issue where a leak in decryption counters caused resource
+ exhaustion, which led to a GlobalProtect service outage.
+
+ |
+
|
+ PAN-306502
+ |
+
+
+ Fixed two issues that impacted TLSv1.2 or earlier sessions when the
+ traffic matched a decryption policy rule with the no-decrypt action:
+
+
|
+
|
+ PAN-306103
+ |
+
+
+ (PA-3400 and PA-5400 Series firewalls only)
+ Fixed an issue where the firewall dataplane frequently restarted when
+ lockless QoS was enabled
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Fixed an issue where traffic was incorrectly identified as
+ unknown-tcp/unknown-udp due to App-ID resource leak and eventually
+ dropped.
+
+ |
+
|
+ PAN-302767
+ |
+
+
+ Fixed an issue where IPv6 IPsec WAN support was not available in
+ Prisma Access.
+
+ |
+
|
+ PAN-301222
+ |
+
+
+ Fixed an issue where DNS Security logs incorrectly displayed a
+ sinkhole action for benign DNS categories due to the firewall saving
+ the drop or sinkhole action in session flags without discarding the
+ session.
+
+ |
+
|
+ PAN-300638
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall stopped responding due to an out-of-bounds read when
+ parsing TLS 1.3 clientHello messages with large TLS clientHello
+ extensions where the
+ supported_versions extension fell
+ outside the first TCP segment.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high
+ packet rates on the synthetic path in DPDK mode.
+
+ |
+
|
+ PAN-295803
+ |
+
+
+ Addressed a memory leak issue under sc3 and automatic commit recovery
+ (ACR) code path.
+
+ |
+
|
+ PAN-294488
+ |
+
+
+ Fixed an issue where certificate data was missing in decryption logs
+ for No decrypt policy rules and
+ TLS1.2 traffic after upgrading, and the
+ Subject Common Name,
+ Issuer Common Name,
+ Certificate Start Date,
+ Certificate End Date, Certificate Serial Number, and
+ Certificate Fingerprint fields were
+ blank in the decryption logs.
+
+ |
+
|
+ PAN-283563
+ |
+
+
+ Fixed an issue where the GlobalProtect gateway firewall intermittently
+ failed to assign an IP address to GlobalProtect clients from the DHCP
+ server, even after successfully receiving a DHCP offer. This occurred
+ when the DHCP retry and timeout settings were overwritten due to
+ parsing results being stored in the same variable, which caused the
+ last gateway configuration to take effect.
+
+ |
+
|
+ PAN-271438
+ |
+
+
+ Fixed an issue where the firewall calculated available memory
+ incorrectly on CENTOS devices, which caused the firewall to display
+ high memory usage alerts even when sufficient memory was available.
+
+ |
+
|
+ PAN-267328
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused the firewall to stop
+ processing traffic.
+
+ |
+
|
+ PAN-259853
+ |
+
+
+ Fixed an issue where, when the DHCP server was enabled for
+ GlobalProtect, the commit error message was not properly displayed
+ when Any was selected as the source
+ interface in the service router configuration ().
+
+ |
+
|
+ PAN-258039
+ |
+
+
+ Fixed an issue where the firewall displayed the incorrect rule name
+ when a threat log was generated for Inline Cloud Analyzed CMD
+ Injection Traffic Detection.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308902
+ |
+
+
+ Fixed an issue where, after upgrading to an affected release, the
+ firewall did not add mTLS websites that required client certificate
+ authentication via DN list to the ssl-decrypt exclude-cache list.
+
+ |
+
|
+ PAN-308654
+ |
+
+
+ Fixed an issue where the Elasticsearch Close Indices process closed
+ more indices than expected and dropped the number of open shards below
+ the minimum of 800 per Elasticsearch instance. This occurred because
+ the process did not correctly account for the number of Elasticsearch
+ instances when calculating the maximum number of allowed open shards.
+
+ |
+
|
+ PAN-304718
+ |
+
+
+ Fixed an issue where OSPF and BGP outages occurred due to an
+ all_task
+ process restart during clientless VPN content rewrite processing.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Fixed an issue where the firewall entered a non-functional state due
+ to segmentation fault within the
+ all_pktproc
+ process that was caused by a session that involved http2 cleartext
+ traffic
+
+ |
+
|
+ PAN-304496
+ |
+
+
+ Fixed an issue where, after unregistering an IP tag and registering a
+ different IP tag for the same IP address via XML API, the dynamic
+ address group membership was not updated on the dataplane, which
+ resulted in Security policy rules being enforced incorrectly.
+
+ |
+
|
+ PAN-303722
+ |
+
+
+ Fixed an issue on the firewall where configuring spyware and
+ vulnerability profiles in Security policy rules caused a memory leak
+ in the
+ devsrvr
+ process with each configuration commit.
+
+ |
+
|
+ PAN-288001
+ |
+
+
+ Fixed an issue where devices with 5G cellular modems did not support
+ the ATT FirstNet auto Access Point Name (APN).
+
+ |
+
|
+ PAN-285181
+ |
+
+
+ Fixed an issue where the wifclient ran out of memory when Enhanced
+ Application Logging was enabled and a sudden traffic increase caused a
+ surge in EAL messages sent through WIF.
+
+
+ To use this fix, run the CLI command
+ debug iot eal memory-gc native
+
+ |
+
|
+ PAN-278688
+ |
+
+
+ Fixed an issue where DNS Security threat logs were not displayed on
+ the firewall when packet capture was enabled and the domain name
+ length was 62 characters.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where an incorrect ASIC configuration caused silent packet drops or
+ application slowness when receiving a mix of jumbo and non-jumbo
+ packets.
+
+ |
+
|
+ PAN-269228
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused a split brain condition.
+
+ |
+
|
+ PAN-267614
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected due to high CPU utilization on the
+ mongodb
+ process.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
| + | + |
|
+ PAN-316911
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-315912
+ |
+
+
+ Fixed an issue where the Maximum Segment Size (MSS) rewrite
+ functionality for packets ingressing through SD-WAN interfaces on
+ firewalls was not optimized.
+
+ |
+
|
+ PAN-314147
+ |
+
+
+ Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces
+ with member having different MTU.
+
+ |
+
|
+ PAN-313623
+ |
+
+
+ Fixed an issue where the
+ /opt/pancfg/mgmt/ssl/private/
+ directory on Palo Alto Networks devices with TPM support became 100%
+ utilized due to an accumulation of undeleted
+ .pub_pem files. This occurred
+ because executing the
+ show device-certificate status
+ CLI command initiated a process that generated these files but failed
+ to remove them, which prevented the fetching of new device
+ certificates.
+
+ |
+
|
+ PAN-313216
+ |
+
+
+ Fixed an issue where firewalls with Prisma Access incorrectly
+ displayed some traffic as unsanctioned in traffic logs for cloud
+ applications that were tagged as
+ sanctioned.
+
+ |
+
|
+ PAN-312706
+ |
+
+
+ Fixed an issue where the firewalls restarted due to a function lacking
+ a NULL-pointer sanity check.
+
+ |
+
|
+ PAN-311512
+ |
+
+
+ Fixed an issue where HIP (Host Information Profile) reports were
+ blocked on GlobalProtect when
+ Authentication Cookie Usage Restrictions
+ was enabled and the Prisma Access Agent protocol was in use. This
+ occurred because the system failed to correctly process HIP messages
+ that were relayed via IPSec tunnels with a Virtual IP as the source,
+ leading to their rejection.
+
+ |
+
|
+ PAN-309300
+ |
+
+
+ Fixed an issue where management plane system resources configuration
+ size exceeded 28 MB for over 4 hours, and the following error message
+ was displayed:
+ Configuration size reaching device capacity limit.
+
+ |
+
|
+ PAN-308786
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ traffic log queries using the
+ device_name filter returned no
+ results, and complex log queries that included negation operators
+ produced incorrect outputs.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Fixed an issue where packets were dropped on SD-WAN interfaces when a
+ proxy was enabled due to an MTU inconsistency where the firewall
+ failed to rewrite the maximum segment size in SYN/ACK packets based on
+ the SD-WAN virtual interface MTU.
+
+
+ Note: This fix does not apply when the traffic
+ egress interface is SD-WAN Direct Internet Access (DIA) interface
+ and proxy is enabled.
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ (Panorama managed firewalls only) Fixed an
+ issue where the firewall intermittently failed to maintain active log
+ forwarding streams to Strata Logging Service (SLS) even when duplicate
+ logging and enhanced application logging were enabled.
+
+ |
+
|
+ PAN-308418
+ |
+
+
+ Fixed an issue where, when Advanced DNS Security was enabled and
+ experienced unusually high loads, DNS resolution failures occurred
+ with the error
+ resources-unavailable.
+
+ |
+
|
+ PAN-306555
+ |
+
+
+ Fixed an issue where the firewall stopped responding, which led to
+ service outages.
+
+ |
+
|
+ PAN-304019
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall did not send traffic to SCM or SLS via a configured
+ explicit proxy IP address when the proxy username was not configured.
+
+ |
+
|
+ PAN-303745
+ |
+
+
+ Fixed an issue where inter-dataplane forwarding did not work for
+ sessions ingressing on Slot 2, which resulted in intermittent ping
+ failures to interfaces on Network Card 2 when traffic was forwarded to
+ Slot 3.
+
+
+ Note: With this fix, after a slot restart, the
+ global counter will still show dot1q errors for a short period.
+
+ |
+
|
+ PAN-302983
+ |
+
+
+ Fixed an issue where, after committing changes on Panorama, a shared
+ post-rule moved to the end of the
+ post shared rulebase on the
+ managed device instead of remaining at the top.
+
+ |
+
|
+ PAN-302564
+ |
+
+
+ Fixed an issue on the firewall where a path monitoring failure
+ occurred and caused the dataplane to restart.
+
+ |
+
|
+ PAN-301653
+ |
+
+
+ Fixed an issue where DNS traffic sessions prematurely terminated with
+ the message
+ resources-unavailable. This occurred due to IPv4 fragmented DNS responses causing the
+ Advanced DNS Security module to incorrectly pack the DNS payload
+ multiple times when forwarding to the cloud for inspection.
+
+ |
+
|
+ PAN-300837
+ |
+
+
+ Fixed an issue where firewalls experienced multiple reboots due to the
+ pan_task
+ process restarting with a SIGSEGV signal. This occurred because the
+ client-to-firewall side assumed TLS 1.3 for the firewall-server side.
+
+ |
+
|
+ PAN-300671
+ |
+
+
+ Fixed an issue where traffic reports that were generated with
+ destination/source and destination/source hostnames were not displayed
+ in IPv4 format.
+
+ |
+
|
+ PAN-300423
+ |
+
+
+ Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
+ and 6 remained stuck in a starting state with the error
+ Signal detected for port xeS5-DP0 but Link Down
+ alerts, which resulted in device instability.
+
+ |
+
|
+ PAN-299242
+ |
+
+
+ Fixed an issue where the firewall's SSL proxy sent an empty HTTP2
+ SETTINGS message to the client before confirming server support, which
+ caused some clients to incorrectly assume HTTP/2 support and not fall
+ back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad
+ Request frames from the server, which prevented the client from
+ correctly detecting the lack of HTTP/2 support.
+
+ |
+
|
+ PAN-298617
+ |
+
+
+ Optimized the commit workflow to reduce the size of the effective
+ configuration, resulting in lower memory consumption.
+
+ |
+
|
+ PAN-297708
+ |
+
+
+ Fixed an issue where a long-lived session with many Machine Learning
+ (ML) model triggers caused a memory leak of feature states associated
+ with the ML model runs. This resulted in Spyware_State failure
+ increases, allocation max outs, and impaired policy matching.
+
+ |
+
|
+ PAN-295802
+ |
+
+
+ Fixed an issue where a memory leak related to the
+ configd
+ process occurred.
+
+ |
+
|
+ PAN-295309
+ |
+
+
+ Fixed an issue where OSPF session using MD5 authentication experienced
+ intermittent flapping due to out-of-order packet processing.
+
+ |
+
|
+ PAN-293644
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the
+ configd
+ process stopped responding during an External Dynamic List (EDL)
+ refresh.
+
+ |
+
|
+ PAN-290938
+ |
+
+
+ Fixed an issue where multiple memory leaks occurred related to the
+ configd
+ process.
+
+ |
+
|
+ PAN-264762
+ |
+
+
+ Fixed an issue where the firewall showed the status of SFP+ interfaces
+ as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
+ connected.
+
+ |
+
|
+ PAN-263691
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a
+ memory leak in the
+ all_task
+ process.
+
+ |
+
|
+ PAN-248913
+ |
+
+
+ Fixed an issue where the Elasticsearch client certificate was not auto
+ renewed, which caused it to enter a Red state, and logs were not
+ displayed in Panorama.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-291499
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where newly deployed firewalls were unable to
+ connect to the Palo Alto Networks Software License Server (SLS) until
+ after a reboot, license fetch, or management server restart.
+
+ |
+
|
+ PAN-290241
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process became unresponsive, which caused User ID CLI commands to time
+ out.
+
+ |
+
|
+ PAN-287688
+ |
+
+
+ Fixed an issue where the firewall failed to connect to the Palo Alto
+ Networks update server when using a customized service route with the
+ source interface as MGT.
+
+ |
+
|
+ PAN-268680
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when a configuration merge operation
+ changed.
+
+ |
+
|
+ PAN-268522
+ |
+
+
+ Fixed an issue where the firewall failed to connect to the update
+ server with a customized service route when the source interface was
+ set to MGT and the source address
+ was set as IPv4.
+
+ |
+
|
+ PAN-241230
+ |
+
+
+ Fixed an issue where the SNMP get request status value for Panorama
+ connections was incorrect.
+
+ |
+
|
+ PAN-216770
+ |
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud
+ Manager and configured to use a proxy server for external connections,
+ the management server did not use the configured settings to connect
+ to the Cloud Management service.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-297458
+ |
+
+
+ Fixed an issue where the
+ all_task_1
+ process crashed on the firewall when the wif service wasn't available
+ because the wif detection ID was not in the current service table.
+
+ |
+
|
+ PAN-297261
+ |
+
+
+ Fixed an issue where the proxy-protocol debug level was set to
+ verbose on Prisma Access
+ instances, even when it was not explicitly configured, which caused
+ excessive logging by the
+ pan_task
+ process.
+
+ |
+
|
+ PAN-296519
+ |
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an
+ associated error in
+ Wifclient
+ caused the entire pool to close, which resulted in a complete
+ disconnection.
+
+ |
+
|
+ PAN-296478
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
+ GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
+ JavaScript links, resulting in an authorization error. This occurred
+ because the firewall was incorrectly injecting text into URLs when
+ JavaScript buttons or dropdown menus were clicked within the
+ Clientless VPN portal.
+
+ |
+
|
+ PAN-295812
+ |
+
+
+ Fixed an issue where the throughput data on the Switch Card Module
+ (SCM) was not accurately reported. This issue affected Standard SC
+ USABN and USABN-2 when using Direct-IO deployment.
+
+ |
+
|
+ PAN-294179
+ |
+
+
+ Fixed an issue on Panorama where commit versions did not display
+ correct data in the config audit page even after a refresh.
+
+ |
+
|
+ PAN-292202
+ |
+
+
+ Fixed an issue where the system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over.
+
+ |
+
|
+ PAN-291631
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall frequently rebooted.
+
+ |
+
|
+ PAN-291288
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a
+ pan_task
+ process restart related to page allocation failures.
+
+ |
+
|
+ PAN-290449
+ |
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports
+ were sent in the same email, only the first attached report was
+ displayed.
+
+ |
+
|
+ PAN-288726
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding due to a Security policy rule ID being set
+ to 0, which caused the last configuration retrieval to fail.
+
+ |
+
|
+ PAN-287423
+ |
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites
+ due to the firewall incorrectly setting the IPv6 header flow label to
+ 0.
+
+ |
+
|
+ PAN-286299
+ |
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 releases where, after
+ being offboarded from Panorama, the firewall XML configuration file
+ retained template information from the previous Panorama
+ configuration. As a result, when the firewall and its configuration
+ were imported to another Panorama appliance, all configurations in the
+ Network and
+ Device tabs became read-only.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to
+ multiple firewalls with different base configurations resulted in
+ configuration corruption, which caused the firewall to go down.
+
+ |
+
|
+ PAN-285285
+ |
+
+
+ Fixed an issue where commits remained at 98% completion when static
+ route configuration cleanup was in progress.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ Fixed an issue on the firewall that caused commits to fail and the web
+ interface to become inaccessible.
+
+ |
+
|
+ PAN-279706
+ |
+
+
+ (M-600 appliances only) Fixed an issue where
+ Panorama did not update all
+ panreplay database entries after
+ performing a commit and full push to all devices.
+
+ |
+
|
+ PAN-277034
+ |
+
+
+ Fixed an issue where WildFire reports were not fully displayed and
+ were not downloadable due to static resources not being found.
+
+ |
+
|
+ PAN-276484
+ |
+
+
+ Fixed an issue where Panorama did not display license information for
+ Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
+
+ |
+
|
+ PAN-259741
+ |
+
+
+ Fixed an issue where the firewall dropped GRE keepalive packets that
+ were encapsulated under another GRE tunnel.
+
+ |
+
|
+ PAN-251442
+ |
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode if
+ the authentication process restarted repeatedly.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-304088
+ |
+
+
+ Fixed an issue where TCP traffic stopped working from Prisma Access
+ clients to TCP services behind the Service Connection (SC) after a
+ dataplane upgrade to an affected release.
+
+ |
+
|
+ PAN-303559
+ |
+
+
+ Fixed an issue where, after manually creating a device telemetry
+ bundle, the hour_cli_output.txt file within the bundle had a file size
+ of 0 bytes. This occurred when checking the bundle content after
+ enabling device telemetry and setting the device telemetry upload
+ endpoint.
+
+ |
+
|
+ PAN-301828
+ |
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud
+ Manager and configured to use a proxy server for external connections,
+ the management server did not use the configured settings to connect
+ to the Cloud Management service.
+
+ |
+
|
+ PAN-300906
+ |
+
+
+ Fixed an issue where XML API commands failed with a
+ Method not found (policy_xml)
+ error in dagger.log. The issue was due to missing XML-related
+ functions for inline-cloud-proxy.
+
+ |
+
|
+ PAN-298505
+ |
+
+
+ Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
+ the vsys ID changed in sequence, causing autocommit failures with
+ validation errors. This occurred when the multi-vsys firewall had
+ virtual systems created and pushed from Panorama, and the vsys ID was
+ not in a correct sequence because the unused vsys was deleted from
+ Panorama and pushed to devices.
+
+ |
+
|
+ PAN-298387
+ |
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP
+ addresses did not display in traffic and threat logs.
+
+ |
+
|
+ PAN-297972
+ |
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched
+ Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
+ Analysis features were not enabled.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ Fixed an issue where, after upgrading, the
+ Visible Virtual Systems field
+ started to reference the vsys name instead of the vsys ID, which
+ caused inter-vsys routing to fail. This occurred when a vsys display
+ name matched one of the vsys IDs.
+
+ |
+
|
+ PAN-297240
+ |
+
+
+ Fixed an issue where attempting to generate reports in a WildFire FIPS
+ Private Cloud or WF-500 deployment returned 401 errors.
+
+ |
+
|
+ PAN-295560
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors,
+ tunnel logs were not visible in Panorama or Splunk even though traffic
+ and threat logs were received.
+
+ |
+
|
+ PAN-295385
+ |
+
+
+ Fixed an issue where syslog forwarding dropped due to FQDN resolution
+ failures.
+
+ |
+
|
+ PAN-295257
+ |
+
+
+ Fixed an issue where, after onboarding a firewall to Panorama, IPsec
+ tunnels displayed IKEv2 in Panorama, even though the tunnels were
+ configured with IKEv1 locally on the firewall.
+
+ |
+
|
+ PAN-295221
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors,
+ Traffic and Threat logs were not forwarded to a Splunk server over
+ UDP.
+
+ |
+
|
+ PAN-294893
+ |
+
+
+ Fixed an issue where firewalls with the
+ Send handshake messages to CTD for inspection
+ setting enabled caused incorrect security policy rules to be matched.
+ Specifically, traffic not identified as openai-base or openai-chatgpt
+ applications was incorrectly matched by the
+ ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
+ response page for blocked URLs was not displayed.
+
+ |
+
|
+ PAN-294524
+ |
+
+
+ Fixed an issue where firewalls and Panorama management servers were
+ unable to view or download WildFire reports from a WF-500 appliance,
+ resulting in a 401 error in the report tab.
+
+ |
+
|
+ PAN-294320
+ |
+
+
+ Fixed an issue where the
+ mprelay
+ process repeatedly restarted.
+
+ |
+
|
+ PAN-294161
+ |
+ + + | +
|
+ PAN-292447
+ |
+
+
+ Fixed an issue where Panorama did not display data in the
+ Feature Adoption tab in Strata Cloud
+ Manager due to the system creating and deleting a CLI user for each
+ interval instead of reusing a permanent CLI user for telemetry.
+
+ |
+
|
+ PAN-291940
+ |
+
+
+ Fixed an issue where the firewall established multiple TCP connections
+ to a syslog server, which caused logs to be dropped. This occurred
+ because the firewall established a new TCP session for each transfer
+ and the sessions were not closed, which resulted in a continuous
+ increase in connections over time.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ Fixed an issue where during a commit, the firewall experienced an
+ out-of-memory (OOM) condition due to a memory leak and displayed an
+ error message. This issue caused the device to crash and reboot
+ unexpectedly.
+
+ |
+
|
+ PAN-291653
+ |
+
+
+ Fixed an issue where the GlobalProtect host ID field was
+ intermittently blank in traffic logs on Prisma Access, even when the
+ user was connected and had the correct host ID information. This
+ occurred when the IP address to host ID entry expired and the entry
+ was re-insterted without the dataplane flag being set.
+
+ |
+
|
+ PAN-291635
+ |
+
+
+ Fixed an issue where cookie surrogate cache entries remained
+ unresolved after an
+ idmgr
+ process reset due to the request not being retransmitted. This
+ occurred because the timestamp in the cache entry was refreshed even
+ when the UID was 0, which prevented the retransmission of the request
+ if the initial response was not received.
+
+ |
+
|
+ PAN-291283
+ |
+ + + | +
|
+ PAN-291067
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process periodically exceeded its virtual memory limit and restarted,
+ which led to intermittent outages.
+
+ |
+
|
+ PAN-289859
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where Panorama failed to mount logging disks larger than 2TB due
+ to a partitioning error.
+
+ |
+
|
+ PAN-289405
+ |
+
+
+ (VM-Series firewalls only) Added the CLI
+ command
+ no-refresh-discard-session to
+ address an issue where the discarded session time to live (TTL) did
+ not refresh at the default value.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ Fixed an issue where the MPLS interface eth1/6 went down and remained
+ down, even after replacing the SFP with a supported one and adjusting
+ duplex and speed settings.
+
+ |
+
|
+ PAN-289249
+ |
+
+
+ Fixed an issue where a memory leak occurred on the
+ reportd
+ process when a WildFire update was initiated while device telemetry
+ data collection was in progress. This resulted in an OOM condition.
+
+ |
+
|
+ PAN-289109
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected during configuration operations and a configuration lock time
+ out occurred during a commit.
+
+ |
+
|
+ PAN-288097
+ |
+
+
+ Fixed an issue where on the firewall where the
+ routed
+ process stopped responding after changing the MTU or any link state
+ parameters when OSPF and PIM were enabled on the same interface.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Fixed an issue where, after upgrading, certain websites weren't
+ accessible when the accumulation proxy was enabled. The proxy did not
+ use the same DF bit state as the original traffic, causing it to be
+ fragmented and dropped elsewhere in the network.
+
+ |
+
|
+ PAN-287782
+ |
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP
+ values from AF11 to CS0 on traffic passing through the firewall, even
+ when QoS policy rules and DSCP rewrite settings were not configured.
+
+ |
+
|
+ PAN-287622
+ |
+
+
+ Fixed an issue where IPv6 traffic was affected after upgrading the
+ firewall. With SSL decryption enabled and a decryption policy
+ configured for the traffic, the firewall dropped packets due to
+ receiving a Packet Too Big ICMP
+ message. This occurred because the PathMTU information update was
+ incorrect for the TCB (pan-server) when the firewall was acting as a
+ server. Additionally, the flow label under the IPv6 header was set to
+ zero while the packet was being transmitted out of the firewall.
+
+ |
+
|
+ PAN-287601
+ |
+
+
+ Fixed an issue on Panorama where commits took longer than expected.
+
+ |
+
|
+ PAN-287387
+ |
+
+
+ Fixed an issue on Panorama where API jobs failed with the error
+ message
+ Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a
+ large number of address objects in a single set call.
+
+ |
+
|
+ PAN-283053
+ |
+
+
+ Fixed an issue where the firewall experienced high disk space
+ utilization, which caused the firewall to become non-functional.
+
+ |
+
|
+ PAN-282277
+ |
+
+
+ Fixed an issue where an OOM condition on the
+ logrcvr
+ process caused interface flapping, and the interface unexpectedly went
+ down and then recovered without intervention.
+
+ |
+
|
+ PAN-281776
+ |
+
+
+ Fixed an issue on the Panorama web interface where the error message
+ PPPoEv6 Client Interface cannot be enabled with DHCPv6 client
+ was generated when overriding aggregate interfaces even when no DHCPv6
+ or PPPoE was configured.
+
+ |
+
|
+ PAN-278836
+ |
+
+
+ Fixed an issue where, after an upgrade, GlobalProtect attempted to use
+ the embedded browser instead of the default browser for gateway
+ authentication even when it was configured to use the default browser.
+
+ |
+
|
+ PAN-272245
+ |
+
+
+ Fixed an issue where the
+ dnsproxy
+ process stopped responding due to memory corruption caused by a race
+ condition when the allow list downloading was impacted by a
+ configuration change.
+
+ |
+
|
+ PAN-267450
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding with a SIGSEGV at
+ schedule_report_es_response.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-306534
+ |
+
+
+ Fixed an issue were the
+ all_task
+ process repeatedly restarted due to memory pool corruption when
+ processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred
+ due to incorrect buffer length calculations during memory deallocation
+ when the query name field spanned multiple packets.
+
+ |
+
|
+ PAN-305480
+ |
+
+
+ Fixed an issue where the
+ pan_task
+ process stopped responding while processing DoH JSON format traffic
+ with DoH Security enabled, which caused missing cross-packet bytes in
+ the decoded DNS query type field, and the dataplane went down.
+
+ |
+
|
+ PAN-305301
+ |
+
+
+ Fixed an issue where GlobalProtect notifications in tunnels caused
+ processes to stop responding and the dataplane to restart due to the
+ session lookup returning an incorrect session, which resulted in the
+ data being sent through the wrong tunnel.
+
+ |
+
|
+ PAN-292344
+ |
+
+
+ Fixed an issue where the firewall rebooted multiple times after an
+ upgrade if the config contained an EDL (External Dynamic List) that
+ didn't have an associated certificate profile.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308727
+ |
+
+
+ Fixed an issue where traffic logs for
+ Remote Networks displayed the source
+ zone as trust instead of the remote
+ network name.
+
+ |
+
|
+ PAN-308468
+ |
+
+
+ Fixed an issue where the firewall rebooted due to the
+ all_task
+ process restarting.
+
+ |
+
|
+ PAN-303051
+ |
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the
+ reportd
+ process due to retaining memory that was temporarily used for report
+ generation instead of releasing the memory for reuse, which resulted
+ in continuous accumulation and memory exhaustion.
+
+ |
+
|
+ PAN-302927
+ |
+
+
+ Fixed an issue where, after upgrading Panorama, the
+ Push to Devices option did not
+ display selected devices, and the
+ OK and
+ Cancel
+ buttons did not function as expected. Selecting
+ OK did not close the window, and
+ selecting Cancel returned to the
+ main push screen with the push selected devices displaying as empty.
+ Despite this, selecting Push or
+ Validate Device Group Push still
+ pushed to the previously canceled, non-displayed devices.
+
+ |
+
|
+ PAN-301801
+ |
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process
+ fluctuated intermittently between green and red states, which led to
+ interruptions in log collection. This issue occurred when the number
+ of shards exceeded the cluster's maximum supported threshold of
+ greater than 1000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-301691
+ |
+
+
+ Fixed an issue where BGP stopped responding with the error message
+ Too many open files when pushing
+ 1000 eBGP (External BGP) neighbor configurations. With this fix, the
+ number of file descriptors for the BGP process is increased from 1024
+ to 8192.
+
+ |
+
|
+ PAN-301456
+ |
+
+
+ Fixed an issue on Panorama where the
+ debug system reset-ztp CLI
+ command was unavailable.
+
+ |
+
|
+ PAN-300216
+ |
+
+
+ Fixed an issue where, when SD-WAN Direct Internet Access was
+ configured and traffic traversed the cellular interface without a NAT
+ policy rule, intermittent cellular modem connectivity issues occurred,
+ which caused the firewall to disconnect and reconnect to the cellular
+ network.
+
+
+ To use this fix, run the CLI command
+ set session teardown-upon-fwd-zonechange yes.
+
+ |
+
|
+ PAN-300138
+ |
+
+
+ Fixed an issue where DNS queries stalled or repeatedly time out due to
+ multiple DNS responses with different CNAME values causing evasion
+ false positive alerts.
+
+ |
+
|
+ PAN-299772
+ |
+
+
+ (VM-Series firewalls in active/passive configurations only) Fixed an issue where, after an HA failover event, the newly active
+ firewall DHCP client interfaces failed to obtain IP addresses
+ automatically. This occurred because the DHCP client processes did not
+ initiate the necessary DHCP discover or renew requests
+
+ |
+
|
+ PAN-297976
+ |
+
+
+ Fixed an issue where the firewall experienced extended boot times
+ after a reboot due to the
+ configd
+ process needing to rebuild the ACE catalog after detecting
+ discrepancies that were caused by duplicate application checking
+ between the ACE catalog and content.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade
+ due to the
+ fsck
+ command scanning drive partitions in parallel with the root partition,
+ which caused the process to take an extended amount of time.
+
+ |
+
|
+ PAN-297005
+ |
+
+
+ Fixed an issue where exporting custom reports resulted in empty CSV
+ files.
+
+ |
+
|
+ PAN-296977
+ |
+
+
+ Fixed an issue where the web interface became unresponsive when
+ attempting to view
+ Ethernet interface details after
+ applying a filter in
+
+
+ |
+
|
+ PAN-296752
+ |
+
+
+ (PA-1410 Firewalls only) Fixed an issue where
+ the firewall experienced high management CPU usage and repeatedly
+ rebooted when attempting to retrieve SMART data.
+
+ |
+
|
+ PAN-296694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to the
+ useridd
+ process repeatedly restarting during an IP-port data type writes to
+ the redis from multiple sources such as TSA or XML in a scale
+ environment.
+
+ |
+
|
+ PAN-296535
+ |
+
+
+ Fixed an issue on the firewall where BGP peers disconnected when more
+ than 500 BGP neighbors were configured in a single Logical Router
+
+ |
+
|
+ PAN-295899
+ |
+
+
+ Fixed an issue where DNS resolution failed on Linux machines running
+ GlobalProtect client version 6.2.6 when connected with DNS Security
+ enabled. This occurred because the firewall incorrectly discarded DNS
+ packets when processing multiple DNS requests or responses over the
+ same session, even when no malicious verdict was received.
+
+ |
+
|
+ PAN-295342
+ |
+
+
+ Fixed an issue where the
+ pan_comm
+ process stopped responding due to insufficient time allocated to read
+ file descriptors when processing long messages.
+
+ |
+
|
+ PAN-295049
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to memory allocation errors during
+ Redis communication.
+
+ |
+
|
+ PAN-293985
+ |
+
+
+ Fixed an issue with the Panorama web interface where admin users were
+ unable to log in and received the error message
+ 504: Gateway Timeout.
+
+ |
+
|
+ PAN-292770
+ |
+
+
+ Fixed an issue where, after reinstalling the device certificate,
+ delayed telemetry data was displayed in AIOPS.
+
+ |
+
|
+ PAN-291661
+ |
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after
+ an upgrade, Elasticsearch intermittently entered into a Red state
+ before automatically recovering.
+
+ |
+
|
+ PAN-288388
+ |
+
+
+ Fixed an issue where, after an EDL certificate update or repository
+ migration, authentication failures caused the firewall to not fall
+ back to the last successfully cached EDL entries, which led to policy
+ rules that referenced the EDL to not be enforced.
+
+ |
+
|
+ PAN-287842
+ |
+
+
+ Fixed an issue where the
+ comm
+ process stopped responding due to missing heartbeats, which resulted
+ in a system alert and HA communication loss on slot1.
+
+ |
+
|
+ PAN-285169
+ |
+
+
+ Fixed an issue on Panorama where Kerberos superusers were unable to
+ edit policy rules because the target device tab was grayed out.
+
+ |
+
|
+ PAN-281797
+ |
+
+
+ Fixed an issue where firewalls became unstable and stopped responding,
+ which resulted in an OOM condition.
+
+ |
+
|
+ PAN-280917
+ |
+
+
+ Fixed an issue on Panorama where the WildFire cloud URL contained an
+ extra period character, which prevented the retrieval of WildFire
+ analysis reports.
+
+ |
+
|
+ PAN-279829
+ |
+
+
+ Fixed an issue where NAT pool leaks occurred during a test when RTSP
+ traffic hit NAT rules.
+
+ |
+
|
+ PAN-270554
+ |
+
+
+ Fixed an issue where the GlobalProtect client (UWP) or metered hotspot
+ connections triggered TLS resumption fo GlobalProtect portal
+ authentication, which caused the portal authentication to fail with a
+ valid cert required error.
+
+ |
+
|
+ PAN-264131
+ |
+
+
+ Fixed an issue where the
+ routed
+ process core failed the automation run.
+
+ |
+
|
+ PAN-209516
+ |
+
+
+ Fixed an issue where, when creating an interface, an error occurred
+ when you clicked OK without
+ providing a value in the Tag field
+ even though the field was not displayed as mandatory.
+
+ |
+
|
+ PAN-185731
+ |
+
+
+ Fixed an issue where the firewall was unable to parse the URL path and
+ host when the host header was located in a different packet, which
+ resulted in the firewall not logging the URL path in the first packet.
+
+
+ The fix is disabled by default. The following CLI commands can be used
+ to enable/disable the feature: set system setting ctd
+ url-crosspkt-host-path-caching enable set system setting ctd
+ url-crosspkt-host-path-caching disable set system setting ctd
+ url-crosspkt-host-path-caching default
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-290803
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom
+ image, and VM-Series plugin information was not displayed in the
+ system information.
+
+ |
+
|
+ PAN-290542
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding when an additional header logging HTTP
+ header was split across 2 packets.
+
+ |
+
|
+ PAN-290239
+ |
+
+
+ (PA-455 firewalls in active/passive high availability (HA)
+ configurations only) Fixed an issue where, after an upgrade, the TCP session for syslog
+ forwarding did not resume after the syslog server service was disabled
+ and then re-enabled, which caused logs to be dropped. This occurred
+ when the syslog server was down for more than 16 minutes.
+
+ |
+
|
+ PAN-289102
+ |
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
+ PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
+ CN-Series firewalls only) Fixed a race condition issue related to predict processing, which
+ resulted in a dataplane restart and traffic loss.
+
+ |
+
|
+ PAN-288930
+ |
+
+
+ Fixed an issue where traffic from cloud applications intermittently
+ matched an incorrect
+ cloud-apps policy rule when ACE
+ (App-ID Cloud Engine) was enabled.
+
+ |
+
|
+ PAN-287818
+ |
+
+
+ Fixed an issue where sessions timed out sooner than expected due to
+ the
+ pan_proxy_accumulation_restore_timeout
+ not initiating when the accumulation
+ session_init failed.
+
+ |
+
|
+ PAN-286897
+ |
+
+
+ Fixed an issue where the
+ pan_task
+ process stopped responding when the firewall attempted to forward
+ files to the WildFire public cloud, which caused the dataplane to
+ experience heartbeat failures.
+
+ |
+
|
+ PAN-286857
+ |
+
+
+ Fixed an issue where only failed Kerberos authentication events were
+ logged in auth.log, and
+ successful authentication events were not logged.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ Fixed an issue where ECMP incorrectly balanced sessions across links
+ based on the configured metric, which led to an imbalance in traffic
+ distribution and resulted in traffic assignment shifting
+ disproportionately to routes with lower metrics.
+
+ |
+
|
+ PAN-286825
+ |
+
+
+ Fixed an issue where GlobalProtect User-ID mappings were lost after 5
+ minutes, which caused users to not match User-ID source-based policy
+ rules. This occurred due to a mismatch between the GlobalProtect
+ gateway connection settings and the device behavior and when the
+ inactivity-logout setting was
+ deleted and set to a different value.
+
+ |
+
|
+ PAN-285894
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused the firewall to reboot
+ unexpectedly, and traffic failures occurred.
+
+ |
+
|
+ PAN-285651
+ |
+
+
+ (Panorama appliances in active/passive HA configurations on
+ Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect
+ unexpectedly.
+
+ |
+
|
+ PAN-285597
+ |
+
+
+ Fixed an issue where a
+ routed
+ process memory leak occurred when advanced routing was enabled.
+
+ |
+
|
+ PAN-285590
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
+ only) Fixed an issue where the firewall CPU usage reached 100% after
+ upgrading to PAN-OS 11.1.6-h1.
+
+ |
+
|
+ PAN-284117
+ |
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where the
+ vm_agent
+ process restarted after an upgrade.
+
+ |
+
|
+ PAN-284066
+ |
+
+
+ Fixed an issue where, after an upgrade, the SNMP polled values for
+ IF-MIB::ifInErrors displayed a
+ high number of errors that did not match the values in the CLI show
+ interface command.
+
+ |
+
|
+ PAN-283813
+ |
+
+
+ Fixed an issue on Panorama where the web interface performance was
+ slower than usual when retrieving read-only configurations from
+ Panorama.
+
+ |
+
|
+ PAN-283789
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where, after an upgrade, the
+ mac receive error counter in
+ receive incoming errors increased,
+ which resulted in SNMP alerts.
+
+ |
+
|
+ PAN-283644
+ |
+
+
+ (Prisma Access only) Fixed an issue where URL
+ log ingestion decreased after an upgrade, and secondary connections
+ were lost.
+
+ |
+
|
+ PAN-283331
+ |
+
+
+ Fixed an issue where selective pushes to managed devices failed when
+ the User ID Master Device was
+ configured.
+
+ |
+
|
+ PAN-282697
+ |
+
+
+ Fixed an issue where traffic was delayed significantly when it used
+ No Authentication Explicit Proxy and
+ matched a decryption policy rule.
+
+ |
+
|
+ PAN-282640
+ |
+
+
+ Fixed an issue where custom reports showed incomplete data when
+ exported in CSV format from Panorama.
+
+ |
+
|
+ PAN-282394
+ |
+
+
+ Fixed an issue where a firewall was only able to display a maximum of
+ 14 permitted IP addresses from a Panorama Template Variable.
+
+ |
+
|
+ PAN-282391
+ |
+
+
+ (Panorama appliances and Log Collectors only)
+ Fixed an issue where a VLD memory leak caused increased memory use,
+ which resulted in OOM errors.
+
+ |
+
|
+ PAN-282359
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected.
+
+ |
+
|
+ PAN-282240
+ |
+
+
+ Fixed an issue where, when attempting to modify an Anti-Spyware
+ profile via the web interface under a shared location, clicking the
+ OK button displayed a console
+ exception error.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ Fixed an issue where, when exporting and importing CSV files, the hash
+ values of pre-shared key variables set at template and template stack
+ levels changed inconsistently, which resulted in both variables
+ displaying the same hash value.
+
+ |
+
|
+ PAN-281882
+ |
+
+
+ Fixed an issue where OSPF redistributed connected routes beyond the
+ intended loopback IP address.
+
+ |
+
|
+ PAN-281649
+ |
+
+
+ Fixed an issue where the index size limit was incorrectly calculated
+ and indices rolled over earlier than expected, which resulted in high
+ memory and OOM errors.
+
+ |
+
|
+ PAN-281540
+ |
+
+
+ Fixed an issue where the
+ logd
+ process repeatedly restarted when the SD-WAN site name was over 31
+ characters and contained certain XML escape characters.
+
+ |
+
|
+ PAN-281509
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ log exports were slower than expected or failed when filtering logs
+ after an upgrade, which resulted in timeouts or delays in displaying
+ logs on the web interface.
+
+ |
+
|
+ PAN-281269
+ |
+
+
+ (PA-5420 firewalls) Fixed an issue where the
+ firewall management server memory usage continuously increased.
+
+ |
+
|
+ PAN-281264
+ |
+
+
+ Fixed an issue where the
+ routed
+ process memory usage continuously increased when Advanced Routing was
+ enabled.
+
+ |
+
|
+ PAN-280942
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-280698
+ |
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from
+ client hello messages that did not fit in a single packet, which
+ resulted in connection issues.
+
+ |
+
|
+ PAN-280532
+ |
+
+
+ Fixed an issue where, after disabling and re-enabling the external
+ syslog server, the TCP session was not resumed, which caused all logs
+ that were forwarded to the syslog server to be dropped.
+
+ |
+
|
+ PAN-280505
+ |
+
+
+ Fixed an issue where the web interface did not display a message to
+ commit prior changes before attempting a partial configuration load.
+
+ |
+
|
+ PAN-280477
+ |
+
+
+ Fixed an issue on the web interface were you were unable to scroll up
+ or down to view source zones in a NAT policy rule.
+
+ |
+
|
+ PAN-280335
+ |
+
+
+ Fixed an issue with an SNMPv3 EngineBoots value discrepancy that
+ prevented to SNMP server from logging.
+
+ |
+
|
+ PAN-280243
+ |
+
+
+ Fixed an issue where the firewall lost the pre-shared key
+ configuration assigned from a PSK variable when an unrelated device
+ group configuration was loaded.
+
+ |
+
|
+ PAN-279691
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs
+ (security associations) to the passive firewall if the tunnel was not
+ initially established by the active firewall.
+
+ |
+
|
+ PAN-279500
+ |
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric
+ routing environments if the firewall did not see server-to-client
+ (s2c) packets of the TLS handshake.
+
+
+ To use this fix, run the following CLI command:
+ debug dataplane set ssl-decrypt accumulate-client-hello
+ asym-disable yes.
+
+ |
+
|
+ PAN-279495
+ |
+
+
+ Fixed an issue where accessing a URL from the browser returned the
+ error message
+ ERR_RESPONSE_HEADERS_TRUNCATED
+ when the firewall was configured with TLS 1.3.
+
+ |
+
|
+ PAN-279400
+ |
+
+
+ Fixed an issue where, when
+ Restrict Certificate Extensions was
+ enabled on decryption profiles, the basic constraints extension was
+ overwritten incorrectly.
+
+ |
+
|
+ PAN-279336
+ |
+
+
+ Fixed an issue where the CLI did not display a message to commit prior
+ changes before loading a partial configuration.
+
+ |
+
|
+ PAN-279176
+ |
+
+
+ Fixed an issue where the configuration audit displayed inaccurate
+ information after partially loading the configuration via the CLI,
+ which caused the audit to flag the configuration as deleted or
+ changed.
+
+ |
+
|
+ PAN-279065
+ |
+
+
+ Fixed an issue where the firewall sent logs with
+ connection succeeded to the syslog
+ server every time a connection was established, which resulted in
+ excessive logs.
+
+ |
+
|
+ PAN-278981
+ |
+
+
+ Fixed an issue where DNS domain resolutions experienced intermittent
+ delays due to the firewall not connecting to the DNS Security cloud.
+
+
+ To use this fix, enable DNS monitoring on the dataplane via the CLI
+ command
+ debug dnsproxyd enable-rtsig-health-monitor yes.
+
+
+ To show the current setting, run the CLI command
+ debug dnsproxyd enable-rtsig-health-monitor show. If the
+ cfg.general.dns-rtsig-monitor-interval
+ shows a non-zero value, DNS monitoring is enabled.
+
+ |
+
|
+ PAN-278812
+ |
+
+
+ Fixed an issue where authentication to GlobalProtect failed with the
+ error message
+ User not in allowed list.
+
+ |
+
|
+ PAN-278461
+ |
+
+
+ (Firewalls deployed in Amazon Web Services (AWS) environments
+ only) Fixed an issue where DNS Security retransmit packets were not
+ re-encapsulated into Geneve, which caused DNS requests that were
+ initiated from the firewall to be returned to AWS GWLB.
+
+ |
+
|
+ PAN-278190
+ |
+
+
+ Fixed an issue on Panorama where a scheduled report with SLS data had
+ an invalid translated-query.
+
+ |
+
|
+ PAN-278150
+ |
+
+
+ Fixed an issue where the firewall removed the Authentication Key
+ Identifier (AKID) from the certificate during SSL decryption, which
+ caused Python 3.13 to fail with a certificate verification error.
+
+ |
+
|
+ PAN-277808
+ |
+
+
+ Fixed an issue where the
+ eproxy. process stopped responding when running a long duration test using
+ IXload with hybrid SWG SAML authentication bypass for HTTPS payloads,
+ which caused the proxy to become unreachable.
+
+ |
+
|
+ PAN-277631
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process discarded logs due to a full queue.
+
+ |
+
|
+ PAN-277464
+ |
+
+
+ Fixed an issue with intermittent access and slower than expected
+ loading times when accessing websites. This occurred when Anti-Spyware
+ inline cloud analysis was enabled and the
+ SSL Command and Control action was
+ not either allow or
+ alert and server hello packets were
+ out of order.
+
+ |
+
|
+ PAN-277234
+ |
+
+
+ Fixed an issue where a device group import resulted in a Security
+ policy rule being created with
+ Application set to
+ none.
+
+ |
+
|
+ PAN-277147
+ |
+
+
+ Fixed an issue where daily scheduled reports were not generated and
+ emailed.
+
+ |
+
|
+ PAN-276920
+ |
+
+
+ Fixed an issue where web-advertisement traffic was not immediately
+ blocked which resulted in pages loading indefinitely.
+
+ |
+
|
+ PAN-276678
+ |
+
+
+ Fixed an issue where Panorama became unresponsive while performing a
+ dynamic address update without a lock.
+
+ |
+
|
+ PAN-276276
+ |
+
+
+ (PA-450 firewalls only) Fixed an issue where,
+ after an upgrade, data that was excluded using the query builder in a
+ custom report was still visible in the report, and the logs displayed
+ errors related to invalid threat names being queried.
+
+ |
+
|
+ PAN-276062
+ |
+
+
+ Fixed an issue where importing a firewall with a large number of
+ address objects into Panorama did not work and remained at 99%
+ completion.
+
+ |
+
|
+ PAN-275754
+ |
+
+
+ Added support for bootstrapping Panorama virtual appliances on ESXi.
+
+ |
+
|
+ PAN-275718
+ |
+
+
+ Fixed an issue where Panorama stopped forwarding logs to a syslog
+ server after upgrading to PAN-OS 11.1.5-h1.
+
+ |
+
|
+ PAN-275713
+ |
+
+
+ Fixed an issue where the
+ dscd
+ process stopped responding when
+ Endpoint Serial Number was enabled,
+ which resulted in the **Active Directory* returning a list of serial
+ numbers for a specific firewall from the Cloud Identity Engine.
+
+ |
+
|
+ PAN-275133
+ |
+
+
+ Fixed an issue where HTTP 503 server errors occurred while browsing
+ websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
+
+ |
+
|
+ PAN-275077
+ |
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain
+ URLs as Alert instead of taking a Sinkhole action, even when
+ configured to Sinkhole malicious DNS domains.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue
+ where, after an upgrade, the firewall was unable to send logs to the
+ Strata Logging Service (SLS) when using a specific proxy server, and
+ the SSL connection status displayed as failed when attempting to
+ forward logs through the web proxy.
+
+ |
+
|
+ PAN-274806
+ |
+
+
+ (PA-5250 firewalls only) Fixed an issue where
+ IPv6 pings experienced a high number of dropped packets when forwarded
+ to another dataplane, which resulted in ping failures. This occurred
+ when initiating a ping to the link local address of the firewall and
+ the packet drop percentage depended on the number of dataplanes.
+
+ |
+
|
+ PAN-274797
+ |
+
+
+ Fixed an issue where a DPC on slot 3 failed intermittently due to the
+ pktlog_forwarding process
+ restarting, which resulted in an unexpected HA failover.
+
+ |
+
|
+ PAN-274750
+ |
+
+
+ Fixed an issue where the detailed log view in Panorama did not display
+ all packet details for traffic logs received from the cloud.
+
+ |
+
|
+ PAN-274726
+ |
+
+
+ Fixed an issue where Wildfire signature generation was enabled on all
+ nodes in a cluster instead of only the active node.
+
+ |
+
|
+ PAN-274697
+ |
+
+
+ Fixed an issue where push operations from Panorama failed on passive
+ firewalls when an application was removed from a Security policy rule
+ and the policy rule was referenced in a device group.
+
+ |
+
|
+ PAN-274671
+ |
+
+
+ Fixed an issue where empty traffic
+ logdb folders were generated for
+ each day even when trafcfic logs were not received by the
+ logrcvr
+ process.
+
+ |
+
|
+ PAN-274569
+ |
+
+
+ Fixed an issue where the QSPF transceiver interface displayed an
+ incorrect range figure on the temperature alarm.
+
+ |
+
|
+ PAN-274496
+ |
+
+
+ Fixed an issue where the root partition reached 100% which caused the
+ system to become non-functional and failover even when aggressive
+ cleaning was enabled.
+
+ |
+
|
+ PAN-274146
+ |
+
+
+ Fixed an issue where the firewall rebooted continuously after
+ upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in
+ a Gateway Load Balancing (GWLB) scenario and no data packet was
+ associated with the packet.
+
+ |
+
|
+ PAN-273964
+ |
+
+
+ Fixed an issue where SNMP scans to a firewall timed out after
+ upgrading to a PAN-OS 10.2 release.
+
+ |
+
|
+ PAN-273694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to an out-of-bounds
+ memory access that occurred as a result of the SIP content length
+ value being split across packets.
+
+ |
+
|
+ PAN-273614
+ |
+
+
+ Fixed an issue where packets were dropped initially when a SYN cookie
+ with activation threshold 0 was enabled.
+
+ |
+
|
+ PAN-273597
+ |
+
+
+ Fixed an issue where logs in the cloud database displayed in the
+ Not-Resolved category but not in the
+ local database.
+
+ |
+
|
+ PAN-273453
+ |
+
+
+ Fixed an issue where restarting the firewall did not initiate an
+ autocommit job, which caused the firewall to stop responding and the
+ HA interface to go down.
+
+ |
+
|
+ PAN-273277
+ |
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices were
+ prompted to enter their username and password for Kerberos SSO
+ authentication.
+
+ |
+
|
+ PAN-273153
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected due to excessive polling of the
+ MonitorDirect.getTasks API by the
+ Task Manager.
+
+ |
+
|
+ PAN-273141
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file
+ transfer download throughput when passing through an IPSec tunnel.
+
+ |
+
|
+ PAN-272812
+ |
+
+
+ Fixed an issue where SNMP monitoring of tunnel interfaces displayed
+ zero values for received bytes and packets.
+
+ |
+
|
+ PAN-272746
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where
+ the firewall entered an unstable state after committing changes or
+ onboarding to Panorama.
+
+ |
+
|
+ PAN-272605
+ |
+
+
+ Fixed an issue where the firewall did not display VPC endpoints when
+ there was a large amount of VPC endpoints to interface mappings.
+
+ |
+
|
+ PAN-272539
+ |
+
+
+ (Panorama appliances on Microsoft Azure environments only) Fixed an issue where user to IP address mapping was missing for
+ some users connected to specific Prisma Access gateways, which caused
+ the collection layer Azure firewall to not form the mapping.
+
+ |
+
|
+ PAN-272395
+ |
+
+
+ Fixed an issue where informational logs caused the
+ distributord
+ process log file to be frequently overwritten.
+
+ |
+
|
+ PAN-272175
+ |
+
+
+ Fixed an issue where session rematch caused ACE cloud application
+ traffic to match the wrong policy.
+
+ |
+
|
+ PAN-271700
+ |
+
+
+ Fixed an issue where User-ID connections were lost after an HA
+ failover.
+
+ |
+
|
+ PAN-271560
+ |
+
+
+ Fixed an issue where DNS requests to malware sites were not blocked as
+ expected, and the
+ dns-security-categories log-level
+ and action displayed default values instead of
+ unavailable.
+
+ |
+
|
+ PAN-271498
+ |
+
+
+ (PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls
+ in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and
+ frequent reboots were required.
+
+ |
+
|
+ PAN-271425
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue with SSL inbound decryption on firewalls on a vwire
+ setup with asymmetric routing.
+
+
+ To use this fix, enter the CLI command
+ set system setting ssl-decrypt ha-vwire-mac-learn global yes
+ on both firewalls in an HA pair.
+
+ |
+
|
+ PAN-271184
+ |
+
+
+ Fixed an issue where Device Telemetry failed due to an issue with the
+ encoding of characters in the log file path.
+
+ |
+
|
+ PAN-271175
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding with a SIGABRT.
+
+ |
+
|
+ PAN-271151
+ |
+
+
+ Fixed an issue where the GlobalProtect client did not automatically
+ initiate a Kerberos SSO connection after logging in to Windows.
+
+ |
+
|
+ PAN-270849
+ |
+
+
+ Fixed a memory leak issue related to the
+ configd
+ process that occurred when running consecutive commits for multiple
+ days.
+
+ |
+
|
+ PAN-270744
+ |
+
+
+ Fixed an issue where API calls to Panorama failed with the error
+ Server error : Timed out while getting config lock. Please try
+ again.
+
+ |
+
|
+ PAN-270379
+ |
+
+
+ Fixed an issue where socket files created in the /tmp directory were
+ not cleared.
+
+ |
+
|
+ PAN-270193
+ |
+
+
+ Fixed an issue where the Panorama management server changed its
+ certificate authority (CA) unexpectedly, which caused managed
+ firewalls to disconnect.
+
+ |
+
|
+ PAN-270192
+ |
+
+
+ Fixed an issue where Panorama did not display the management IP
+ address of devices onboarded via ZTP.
+
+ |
+
|
+ PAN-269700
+ |
+
+
+ Fixed an issue where commits to service connection firewalls from
+ Panorama failed.
+
+ |
+
|
+ PAN-269677
+ |
+
+
+ Fixed an issue where Panorama did not check for a NULL pointer when
+ querying logs, which caused logs to not display on the web interface.
+
+ |
+
|
+ PAN-269624
+ |
+
+
+ Fixed an issue where GlobalProtect clients failed to connect with the
+ error message
+ The device or feature requires a GlobalProtect subscription
+ license.
+
+ |
+
|
+ PAN-269193
+ |
+
+
+ Fixed an issue where the firewall redirected the user to the first
+ application instead of the portal page with a list of applications
+ when multiple applications were configured for GlobalProtect
+ clientless VPN along with any user match.
+
+ |
+
|
+ PAN-269139
+ |
+
+
+ (Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
+ environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
+ mac receive error counter increased
+ without an error even though traffic was not impacted.
+
+ |
+
|
+ PAN-268708
+ |
+
+
+ Fixed an issue where PDF summary and email reports displayed IPv6
+ addresses instead of IPv4 addresses.
+
+ |
+
|
+ PAN-268614
+ |
+
+
+ Fixed an issue on the web interface where, when all rules were
+ highlighted when a read-only admin user clicked the
+ Highlight Unused Rules checkbox.
+
+ |
+
|
+ PAN-268489
+ |
+
+ Fixed a Threat log PCAP ID overwrapping issue.
+ |
+
|
+ PAN-268465
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where the total user count in the registered users was different
+ between the active and passive firewall.
+
+ |
+
|
+ PAN-268279
+ |
+
+
+ Fixed an issue where autocommits failed if the management IPv6 gateway
+ was the same as the dataplane interface IP address.
+
+ |
+
|
+ PAN-267759
+ |
+
+
+ Fixed an issue where Prisma Access gateway downloads were slower than
+ expected.
+
+ |
+
|
+ PAN-267518
+ |
+
+
+ Fixed an issue where WildFire submission logs incorrectly reported
+ allowed malicious samples even when they were blocked by threat
+ prevention profiles.
+
+ |
+
|
+ PAN-266427
+ |
+
+
+ Fixed an issue on the firewall where, when a high number of SD-WAN
+ branch sites or interfaces were not connected, SD-WAN processes and
+ tund
+ processes stopped responding due to a high probing rate.
+
+ |
+
|
+ PAN-266116
+ |
+
+
+ Fixed an issue where URLs did not work due to certificate revocation
+ list (CRL) requests failing.
+
+ |
+
|
+ PAN-265900
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a
+ tund
+ process or SD-WAN process restart.
+
+ |
+
|
+ PAN-265791
+ |
+
+
+ Fixed an issue where the
+ all_task process stopped
+ responding, which caused the dataplane to go down.
+
+ |
+
|
+ PAN-264982
+ |
+
+
+ (VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the firewall entered maintenance mode after an
+ auto-commit when sending an ARP packet through the loopback interface
+ using an IPv6 address.
+
+ |
+
|
+ PAN-264708
+ |
+
+
+ Fixed an issue where a selective push was blocked when a configuration
+ load was done.
+
+ |
+
|
+ PAN-262729
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ the
+ configd
+ process experienced continuous high CPU utilization and repeatedly
+ restarted.
+
+ |
+
|
+ PAN-262373
+ |
+
+
+ Fixed an issue where the error message
+ Failed to reload config files
+ displayed in the system logs even when device telemetry was not
+ enabled.
+
+ |
+
|
+ PAN-262372
+ |
+
+
+ Fixed an issue where the firewall generated the error message
+ Successfully generating a new set of config files
+ in the system logs even when device telemetry was not enabled.
+
+ |
+
|
+ PAN-262063
+ |
+
+
+ Fixed an issue where the firewall did not display the converted
+ configurations before a commit and reboot, and the commit failed when
+ attempting to migrate from MS to FRR mode.
+
+ |
+
|
+ PAN-261597
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused the firewall to become
+ unavailable.
+
+ |
+
|
+ PAN-261312
+ |
+
+
+ Fixed an issue where a commit for a policy and configuration dump
+ overlapped, which resulted in a null pointer exception.
+
+ |
+
|
+ PAN-261074
+ |
+
+
+ Fixed an issue where the firewall delayed video file transfers over
+ SMB when Exclude Video Traffic from
+ the Tunnel feature was enabled and no applications were added to the
+ list.
+
+ |
+
|
+ PAN-260229
+ |
+
+
+ Fixed an issue where HA path monitoring using VWire did not work as
+ expected after a reboot.
+
+ |
+
|
+ PAN-259727
+ |
+
+
+ (Panorama appliances in HA configurations only)
+ Fixed an issue where Panorama became unresponsive and displayed a 504
+ gateway timeout error when accessing the web interface or the CLI.
+
+ |
+
|
+ PAN-259610
+ |
+
+
+ Fixed an issue where Wildfire content installation failed for WF-500B
+ clusters when deployed from Panorama using the deployment schedule.
+
+ |
+
|
+ PAN-258743
+ |
+
+
+ Fixed an issue where, when you attempted to select a redistribution
+ profile when creating a BGP Redistribute policy rule, the firewall
+ displayed an empty dropdown.
+
+ |
+
|
+ PAN-258166
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ the root partition frequently reached 100%.
+
+ |
+
|
+ PAN-258162
+ |
+
+
+ (Panorama appliances on AWS environments only
+ Fixed an issue where IP addresses were not retrieved in Dynamic
+ Address Groups when multiple AND operators were configured.
+
+ |
+
|
+ PAN-257183
+ |
+
+
+ Fixed an issue where the firewall dropped DNS traffic when using DNS
+ Security.
+
+ |
+
|
+ PAN-256904
+ |
+
+
+ Fixed an issue where the firewall inconsistently blocked URLs due to
+ intermittent URL category misidentification.
+
+ |
+
|
+ PAN-256867
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding while processing session logs for
+ forwarding to the LFC.
+
+ |
+
|
+ PAN-255759
+ |
+
+
+ Fixed an issue where the firewall was unable to match HIP data with
+ the correct anti-malware object for Windows Defender.
+
+ |
+
|
+ PAN-254904
+ |
+
+
+ Fixed an issue on Panorama where a core file was generated by
+ /usr/local/bin/logd during a restart.
+
+ |
+
|
+ PAN-254524
+ |
+
+
+ Fixed an issue on Panorama where, when the
+ Commit and Push button was clicked
+ during a selective
+ Commit and Push operation, the
+ window stopped responding, which caused the operation to be delayed.
+
+ |
+
|
+ PAN-253127
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the
+ hardware pool DFLT became highly utilized, and the packet buffer
+ gradually increased.
+
+ |
+
|
+ PAN-251715
+ |
+
+
+ Fixed an issue where the firewall closed the SSL connection to the
+ user ID agent.
+
+ |
+
|
+ PAN-243235
+ |
+
+
+ Fixed an issue where Panorama stopped responding and rebooted
+ repeatedly after an upgrade.
+
+ |
+
|
+ PAN-193285
+ |
+
+
+ Fixed an issue where the policy optimizer feature did not add entries
+ back to the mongodb database
+ after removing them during an upgrade or downgrade.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+ ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
+ PAN-297240
+ |
+
+
+ Fixed an issue where attempting to generate reports in a WildFire FIPS
+ Private Cloud or WF-500 deployment returned 401 errors.
+
+ |
+ ||||||||||||
|
+ PAN-296592
+ |
+
+
+ Fixed an issue where a 404 error occurred when attempting to download
+ a sample file.
+
+ |
+ ||||||||||||
|
+ PAN-295049
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to memory allocation errors during
+ Redis communication.
+
+ |
+ ||||||||||||
|
+ PAN-294488
+ |
+
+
+ Fixed an issue where certificate data was missing in decryption logs
+ for No decrypt policy rules and
+ TLS1.2 traffic after upgrading, and the
+ Subject Common Name,
+ Issuer Common Name,
+ Certificate Start Date,
+ Certificate End Date,
+ Certificate Serial Number, and
+ Certificate Fingerprint fields were
+ blank in the decryption logs.
+
+ |
+ ||||||||||||
|
+ PAN-294436
+ |
+
+
+ Fixed an issue where polling failed for ethernet interfaces due to the
+ physical port counters read from the MAC being 0.
+
+ |
+ ||||||||||||
|
+ PAN-294320
+ |
+
+
+ Fixed an issue where the
+ mprelay
+ process repeatedly restarted.
+
+ |
+ ||||||||||||
|
+ PAN-293842
+ |
+
+
+ Fixed an issue where the hybrid-SWG service proxy stopped working
+ after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to
+ establish the listening interface.
+
+ |
+ ||||||||||||
|
+ PAN-293673
+ |
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM
+ condition caused by a scheduled log export using FTP to an external
+ FTP server.
+
+ |
+ ||||||||||||
|
+ PAN-293484
+ |
+
+
+ Fixed an issue where, after upgrading the firewall having an IKE
+ gateway that uses an aggregate ethernet interface in DHCP client mode,
+ the IPSec tunnels went down with the error
+ failed to find a socket for retransmission.
+
+ |
+ ||||||||||||
|
+ PAN-293287
+ |
+
+
+ (Panorama virtual appliances in FIPS mode only)
+ Fixed an issue where plugin installs failed with the error
+ invalid image after manually
+ uploading the plugin package from the Customer Support Portal (CSP).
+
+ |
+ ||||||||||||
|
+ PAN-292503
+ |
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP
+ addresses did not display in traffic and threat logs.
+
+ |
+ ||||||||||||
|
+ PAN-292344
+ |
+
+
+ Fixed an issue where the firewall rebooted multiple times after an
+ upgrade if the config contained an EDL (External Dynamic List) that
+ didn't have an associated certificate profile.
+
+ |
+ ||||||||||||
|
+ PAN-292202
+ |
+
+
+ Fixed an issue where the system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over.
+
+ |
+ ||||||||||||
|
+ PAN-291973
+ |
+
+
+ Fixed an issue where the Advanced Routing Engine stopped responding
+ when a route-map was configured to match on a metric with a value of
+ 0.
+
+ |
+ ||||||||||||
|
+ PAN-291631
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) only) Fixed an issue where the firewall frequently rebooted.
+
+ |
+ ||||||||||||
|
+ PAN-291593
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where, when the passive firewall was down and the
+ idmr
+ process was reset, the firewall generated the system log
+ User-ID manager was reset. Commit is not required to reinitialize
+ User-ID, even though the
+ idmr
+ process restart was not successful.
+
+ |
+ ||||||||||||
|
+ PAN-291499
+ |
+
+
+ (
+ VM-Series firewalls on Amazon Web Services (AWS) envirobments
+ only) Fixed an issue where newly deployed firewalls were unable to
+ connect to the Palo Alto Networks Software License Server (SLS) until
+ after a reboot, license fetch, or management server restart.
+
+ |
+ ||||||||||||
|
+ PAN-291456
+ |
+
+
+ Fixed an issue where the custom completer for device groups and
+ templates received the device group name and template name from the
+ running configuration instead of the candidate configuration.
+
+ |
+ ||||||||||||
|
+ PAN-291306
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ override the primary or secondary DNS server address in the template
+ stack.
+
+ |
+ ||||||||||||
|
+ PAN-291288
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a
+ pan_task
+ process restart related to page allocation failures.
+
+ |
+ ||||||||||||
|
+ PAN-291283
+ |
+ + + | +||||||||||||
|
+ PAN-291273
+ |
+
+
+ Fixed an issue where a PA-VM-Flex firewall in an air-gapped
+ environment failed to install the license when bootstrapping after a
+ factory reset when the ISO image contained a PAN-OS image.
+
+ |
+ ||||||||||||
|
+ PAN-291124
+ |
+
+
+ (Firewalls with multi-vsys enabled only) Fixed
+ an issue where an XML API call to get the running Security policy
+ rules returned only the first Security policy rules.
+
+ |
+ ||||||||||||
|
+ PAN-291094
+ |
+
+
+ Fixed an issue the firewall experienced packet descriptor on chip and
+ buffer spikes, which led to dropped traffic due to an unidentified
+ traffic pattern.
+
+ |
+ ||||||||||||
|
+ PAN-291060
+ |
+
+
+ Fixed an issue where commits failed due to the configured connected
+ gateway IPv6 address in the NAT64 policy exceeding the 31 character
+ limit.
+
+ |
+ ||||||||||||
|
+ PAN-290998
+ |
+
+
+ (Firewalls on Microsoft Azure environments only) Fixed an issue where management plane CPU usage was unexpectedly
+ high for netsec firewall.
+
+ |
+ ||||||||||||
|
+ PAN-290996
+ |
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS
+ (Connections Per Second) per vsys on firewalls after upgrading to
+ PAN-OS 11.1.6-h3, even when active connections were present.
+
+ |
+ ||||||||||||
|
+ PAN-290923
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue on the web interface where you were unable to export the
+ Threat Map.
+
+ |
+ ||||||||||||
|
+ PAN-290900
+ |
+
+
+ Fixed an issue where Panorama in FIPS-CC mode failed to push IKEv2
+ Post-Quantum Pre-Shared Key (PQ PPK) configurations to firewalls that
+ were not in FIPS-CC mode.
+
+ |
+ ||||||||||||
|
+ PAN-290702
+ |
+
+
+ Fixed an issue where
+ Log Quotas incorrectly displayed a
+ value that was higher than possible.
+
+ |
+ ||||||||||||
|
+ PAN-290694
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ push shared objects to devices if an
+ HA failover occurred during a configuration push.
+
+ |
+ ||||||||||||
|
+ PAN-290691
+ |
+
+
+ Added the CLI command
+ set system setting ctd h323_rtp_predict timeout
+ to increase the maximum timeout limit from 3600 seconds to 65535
+ seconds.
+
+ |
+ ||||||||||||
|
+ PAN-290449
+ |
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports
+ were were sent in the same email, only the first attached report was
+ displayed.
+
+ |
+ ||||||||||||
|
+ PAN-290241
+ |
+
+
+ Fixed an issue where the
+ useridd process became unresponsive,
+ which caused User ID CLI commands to time out.
+
+ |
+ ||||||||||||
|
+ PAN-290191
+ |
+
+
+ Fixed an issue where BGP learned routes were not advertised when
+ Legacy Routing was used and an
+ export policy rule was configured to match the next hop of the learned
+ route.
+
+ |
+ ||||||||||||
|
+ PAN-290157
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when filtering in the
+ Config Audit window, which caused
+ Panorama to restart unexpectedly.
+
+ |
+ ||||||||||||
|
+ PAN-290088
+ |
+
+
+ Fixed an issue where a memory leak occurred related to the
+ configd
+ process when pushing configurations from Panorama to a firewall. This
+ occurred when the configurations contained shared policy rules.
+
+ |
+ ||||||||||||
|
+ PAN-290074
+ |
+
+
+ Fixed an issue where IPv6 URLs were incorrectly categorized as
+ private-ip-addresses even if the
+ URL had a valid category. This occurred because the firewall did not
+ check for IPv6 addresses when determining if an IP address was
+ private.
+
+ |
+ ||||||||||||
|
+ PAN-289895
+ |
+
+
+ Fixed an issue where, when SSL decryption was enabled, traffic
+ matching a deny rule was incorrectly allowed until the SSL handshake
+ was complete.
+
+ |
+ ||||||||||||
|
+ PAN-289859
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where Panorama failed to mount logging disks larger than 2TB due
+ to a partitioning error.
+
+ |
+ ||||||||||||
|
+ PAN-289826
+ |
+
+
+ Fixed an issue on Panorama where a selective push of policy rule
+ changes to a firewall caused the firewall to lose its Security policy
+ rules.
+
+ |
+ ||||||||||||
|
+ PAN-289803
+ |
+
+
+ Fixed an issue on the firewall where AIPOs and ADEM licenses failed
+ when SD-WAN or GlobalProtect licenses were not present.
+
+ |
+ ||||||||||||
|
+ PAN-289763
+ |
+
+
+ (PA-5400f firewalls only) Fixed an issue where
+ SD-WAN SaaS monitoring did not work with URL monitoring.
+
+ |
+ ||||||||||||
|
+ PAN-289714
+ |
+
+
+ (Prisma Access only) Fixed an issue where
+ persistent commit failures occurred due to a missing transformation
+ script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0.
+
+ |
+ ||||||||||||
|
+ PAN-289652
+ |
+
+
+ Fixed an issue related to external URL lists where pushing
+ configuration changes from Panorama failed.
+
+ |
+ ||||||||||||
|
+ PAN-289573
+ |
+
+
+ Fixed an issue on Panorama where the web interface became unresponsive
+ when attempting to edit the
+ Allow traffic to specified FQDN when Enforce GlobalProtect
+ Connection for Network Access
+ setting in a GlobalProtect portal configuration after adding 40 or
+ more FQDN entries.
+
+ |
+ ||||||||||||
|
+ PAN-289532
+ |
+
+
+ Fixed an issue where, when the Advanced Routing Engine was enabled,
+ PIM (Protocol Independent Multicast) neighborship was not established
+ concurrently on multiple interfaces.
+
+ |
+ ||||||||||||
|
+ PAN-289406
+ |
+
+
+ Fixed an issue where, when redistributing User-ID information between
+ firewalls, the receiving firewall incorrectly received and stored
+ duplicate Host Information Profile (HIP) profiles. This occurred when
+ a GlobalProtect gateway redistributed User-ID and HIP information
+ through an intermediate firewall.
+
+ |
+ ||||||||||||
|
+ PAN-289405
+ |
+
+
+ (VM-Series firewalls only) Added the CLI
+ command
+ no-refresh-discard-session to
+ address an issue where the discarded session time to live (TTL) did
+ not refresh at the default value.
+
+ |
+ ||||||||||||
|
+ PAN-289383
+ |
+
+
+ Fixed an issue where the MPLS interface eth1/6 went down and remained
+ down, even after replacing the SFP with a supported one and adjusting
+ duplex and speed settings.
+
+ |
+ ||||||||||||
|
+ PAN-289320
+ |
+
+
+ Fixed an issue where External Dynamic List (EDL) entries for
+ predefined lists were not visible in Panorama when logged in with a
+ SuperUser Read-Only role.
+
+ |
+ ||||||||||||
|
+ PAN-289304
+ |
+
+
+ (PA-7500 firewalls only) Fixed an issue where
+ SNMP polling failed due to the
+ snmpd
+ process becoming unresponsive to incoming requests, which resulted in
+ high CPU usage.
+
+ |
+ ||||||||||||
|
+ PAN-289301
+ |
+
+
+ Fixed an issue on the Panorama web interface where a template name or
+ device group name displayed invalid text.
+
+ |
+ ||||||||||||
|
+ PAN-289268
+ |
+
+
+ Fixed an issue where internet access through Secure Web Gateway (SWG)
+ proxy nodes did not work when the default internet access policy rule
+ source user was not known-user.
+
+ |
+ ||||||||||||
|
+ PAN-289239
+ |
+
+
+ Fixed an issue on Panorama where a new virtual system (vsys) was
+ automatically created with the name of a device group.
+
+ |
+ ||||||||||||
|
+ PAN-289226
+ |
+
+
+ (Firewalls in HA active/passive configurations only) Fixed an issue where the firewalls experienced high dataplane CPU
+ use when NAT64 was enabled. This occurred due to NAT64 traffic not
+ being offloaded and unnecessary HA session updates being sent for
+ every NAT64 packet.
+
+ |
+ ||||||||||||
|
+ PAN-289109
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected during configuration operations and a configuration lock time
+ out occurred during a commit.
+
+ |
+ ||||||||||||
|
+ PAN-288988
+ |
+
+
+ Fixed an issue on Panorama where, after logging in to the web
+ interface as the ZTP installer administrator, the web interface was
+ blank.
+
+ |
+ ||||||||||||
|
+ PAN-288939
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to an invalid SSL context being used
+ for socket communication, which caused commits to fail.
+
+ |
+ ||||||||||||
|
+ PAN-288893
+ |
+
+
+ (Firewalls in multi-vsys configurations only)
+ Fixed an issue where HTTP/2 traffic failed due when one virtual system
+ (vsys) had a decryption policy rule enabled and another vsys had a
+ no-decrypt policy rule for the same session.
+
+ |
+ ||||||||||||
|
+ PAN-288731
+ |
+
+
+ Fixed an issue where the firewall incorrectly allowed traffic for
+ certain applications when no decryption policy rule was configured.
+
+ |
+ ||||||||||||
|
+ PAN-288726
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding due to a Security policy rule ID being set
+ to 0, which caused the last configuration retrieval to fail.
+
+ |
+ ||||||||||||
|
+ PAN-288693
+ |
+
+
+ Fixed an issue where importing a device configuration into Panorama
+ failed with a validation error if the configuration included a shared
+ gateway with shared address objects.
+
+ |
+ ||||||||||||
|
+ PAN-288617
+ |
+
+
+ Fixed an issue where the firewall attempted to connect to
+ wildfire.paloaltonetworks.com when a user downloaded a WildFire PDF
+ report from the CSP/WF portal even if the user was not behind the
+ firewall.
+
+ |
+ ||||||||||||
|
+ PAN-288529
+ |
+
+
+ Fixed an issue where the firewall failed to forward critical system
+ logs to Strata Logging Service due to a reboot.
+
+ |
+ ||||||||||||
|
+ PAN-288432
+ |
+
+
+ Fixed an issue where, when Advanced Routing Engine was enabled
+ firewalls configured with multiple logical routers, static routes were
+ preferred over eBGP routes even though the static routes had a higher
+ administrative distance.
+
+ |
+ ||||||||||||
|
+ PAN-288427
+ |
+
+
+ Fixed an issue on Panorama where commit jobs were not queued and the
+ system reported that the
+ useridd
+ was not connected.
+
+ |
+ ||||||||||||
|
+ PAN-288426
+ |
+ + + | +||||||||||||
|
+ PAN-288158
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall became inaccessible via the web interface and SSH and
+ remained in an initializing state.
+
+ |
+ ||||||||||||
|
+ PAN-288140
+ |
+
+
+ Fixed an issue where the
+ debug dataplane sync ippool CLI
+ command output incorrectly included reserved ports.
+
+ |
+ ||||||||||||
|
+ PAN-288097
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where on the firewall where the
+ routed
+ process stopped responding after changing the MTU or any link state
+ parameters when OSPF and PIM were enabled on the same interface.
+
+ |
+ ||||||||||||
|
+ PAN-287978
+ |
+
+
+ Fixed an issue where a directly connected interface or aggregate
+ interface did not appear in the routing table, which caused ping
+ failures to the directly connected interface.
+
+ |
+ ||||||||||||
|
+ PAN-287921
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the maximum registered IP address for was incorrectly set to 100,000
+ instead of the expected 500,000.
+
+ |
+ ||||||||||||
|
+ PAN-287842
+ |
+
+
+ Fixed an issue where the
+ comm process stopped responding due
+ to missing heartbeats, which resulted in a system alert and HA
+ communication loss on slot1.
+
+ |
+ ||||||||||||
|
+ PAN-287838
+ |
+
+
+ (Panorama appliances only) Fixed an issue on
+ the web interface where resetting the rule hit counter for multiple
+ policy rules failed with the error message
+ Failed to reset rule-hit job.
+
+ |
+ ||||||||||||
|
+ PAN-287765
+ |
+
+
+ Fixed an issue where SAML authentication failed, which caused the
+ GlobalProtect client to repeatedly attempted to reconnect.
+
+ |
+ ||||||||||||
|
+ PAN-287734
+ |
+
+
+ Fixed an issue where the error message
+ Scan ERR: Internal Err 1002 was
+ generated unexpectedly when WIF shared memory use was high.
+
+ |
+ ||||||||||||
|
+ PAN-287688
+ |
+
+
+ Fixed an issue where the firewall failed to connect to the Palo Alto
+ Networks update server when using a customized service route with the
+ source interface as MGT.
+
+ |
+ ||||||||||||
|
+ PAN-287621
+ |
+
+
+ Added debug logs for an issue where a slow IP address pool NAT leak
+ occurred when persistent NAT was enabled, which led to NAT IP pool
+ exhaustion.
+
+ |
+ ||||||||||||
|
+ PAN-287611
+ |
+
+
+ Fixed an issue where, after upgrading, the firewall incorrectly
+ calculated the UDP checksum for RTP traffic after NAT and Security
+ policy application, which led to dropped packets and silent calls in
+ applications.
+
+ |
+ ||||||||||||
|
+ PAN-287601
+ |
+
+
+ Fixed an issue on Panorama where commits took longer than expected.
+
+ |
+ ||||||||||||
|
+ PAN-287584
+ |
+
+
+ Fixed an issue on the web interface where the address object pop up
+ window only displayed a maximum of four address objects in the policy
+ rule even after expanding the window.
+
+ |
+ ||||||||||||
|
+ PAN-287558
+ |
+
+
+ Fixed an issue on the firewall where the QSFP-40G-SR-BD transceiver
+ was incorrectly flagged as an unsupported SFP.
+
+ |
+ ||||||||||||
|
+ PAN-287548
+ |
+
+
+ Fixed an issue where Security policy rules that had the same
+ parameters were not detected as shadow rules on commit.
+
+ |
+ ||||||||||||
|
+ PAN-287423
+ |
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites
+ due to the firewall incorrectly setting the IPv6 header flow label to
+ 0.
+
+ |
+ ||||||||||||
|
+ PAN-287394
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the firewall generated critical system log alerts every 3 minutes.
+
+ |
+ ||||||||||||
|
+ PAN-287314
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where an OOM condition occurred and caused a failover due to a memory
+ leak associated with the
+ logrcvr
+ process.
+
+ |
+ ||||||||||||
|
+ PAN-287272
+ |
+
+
+ Fixed an issue on the firewall were fan alarms were incorrectly
+ generated constantly.
+
+ |
+ ||||||||||||
|
+ PAN-287154
+ |
+
+
+ Fixed an issue on the firewall where the
+ show advanced-routing bgp loc-rib-detail
+ CLI command incorrectly displayed
+ no BGP route when multiple BGP
+ peers were enabled. With this fix, the CLI command requires a peer
+ name to be specified to display local RIB details.
+
+ |
+ ||||||||||||
|
+ PAN-287133
+ |
+
+
+ Fixed an issue on the Panorama web interface where assigning a policy
+ rule to a group at the top or bottom of the list changed the order of
+ other policy rules.
+
+ |
+ ||||||||||||
|
+ PAN-287056
+ |
+
+
+ Fixed an issue where BGP export policy rules with next-hop matching
+ failed to block the advertisement of static routes, and the firewall
+ incorrectly matched the egress interface IP address instead of the
+ original next-hop IP address of the static route, which caused the
+ deny rule to fail.
+
+ |
+ ||||||||||||
|
+ PAN-287035
+ |
+
+
+ Fixed an issue where, when an application stopped responding, a large
+ file was created in the /opt/panlogs directory, which caused the
+ partition to fill up.
+
+ |
+ ||||||||||||
|
+ PAN-287023
+ |
+
+
+ Fixed an issue where a large number of logs caused the
+ logrcvr
+ process to stop responding.
+
+ |
+ ||||||||||||
|
+ PAN-286931
+ |
+
+
+ Fixed an issue where syslog forwarding in PAN-OS 11.1 and later
+ releases did not support service routes when performing certificate
+ validation over TLS.
+
+ |
+ ||||||||||||
|
+ PAN-286922
+ |
+
+
+ Fixed an issue where user-to-IP address mappings were not available on
+ the dataplane for User-ID, which prevented the enforcement of
+ user-based Security policy rules. This was due to the firewall not
+ validating the timestamp of mappings received from certain User
+ Identification Agent (UIA) agents before adding them to the dataplane.
+
+ |
+ ||||||||||||
|
+ PAN-286899
+ |
+
+
+ Fixed an issue where the
+ device-group-tags CLI command
+ used an unnecessary configuration read lock.
+
+ |
+ ||||||||||||
|
+ PAN-286832
+ |
+
+
+ (VM-Series firewalls only AWS environments only) Fixed an issue where the firewall did not send
+ ICMP unreachable - Fragmentation Needed
+ message when it received packets larger than the MTU.
+
+ |
+ ||||||||||||
|
+ PAN-286818
+ |
+
+
+ Fixed an issue where closing an SSH session to a Panorama using Ctrl+D
+ did not generate a log message in the system logs, and the session
+ remained in an idle state for 60 minutes before being automatically
+ terminated.
+
+ |
+ ||||||||||||
|
+ PAN-286789
+ |
+
+
+ (Panorama virtual appliances in HA configurations on Microsoft Azure
+ environments only) Fixed an issue where plugin versions displayed when hovering over
+ the Green Match icon were
+ inconsistent even though the web interface reported the versions as
+ matching.
+
+ |
+ ||||||||||||
|
+ PAN-286734
+ |
+
+
+ (PA-5450 firewalls only) Added uplink counters
+ to enhance debug capability for traffic drops.
+
+ |
+ ||||||||||||
|
+ PAN-286673
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ the
+ Require SSL/TLS secured connection
+ in the LDAP profile within the template stack did not take effect
+ after overriding the configuration. This occurred even when the
+ setting was enabled multiple times.
+
+ |
+ ||||||||||||
|
+ PAN-286669
+ |
+
+
+ (PA-5410 and PA-5430 firewalls only) Fixed an
+ issue where SFP28 25G ports using S28-25G-LR transceivers did not come
+ up after an upgrade when Forward Error Connection (FEC) was disabled
+ on the ports.
+
+ |
+ ||||||||||||
|
+ PAN-286576
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process restarted, which caused heartbeat failures to occur and a slot
+ to go down due to path monitor failure.
+
+ |
+ ||||||||||||
|
+ PAN-286534
+ |
+
+
+ Fixed an issue where a multi-vsys firewall was unable to retrieve
+ address groups and address objects pushed from Panorama as shared
+ objects when using the REST API.
+
+ |
+ ||||||||||||
|
+ PAN-286492
+ |
+
+
+ Fixed an issue on Panorama where logs were not forwarded to syslog
+ servers due to missing CLI options to configure the syslog queue size
+ and threads.
+
+ |
+ ||||||||||||
|
+ PAN-286475
+ |
+
+
+ Fixed an issue where the option to sort sequence numbers was missing
+ from Filters prefix list in the
+ advanced routing filters.
+
+ |
+ ||||||||||||
|
+ PAN-286443
+ |
+
+
+ Fixed an issue where, after an upgrade, the firewall was unable to be
+ managed via HTTPS or SSH.
+
+ |
+ ||||||||||||
|
+ PAN-286306
+ |
+
+
+ Fixed an issue where, when getting transceiver information from ESCC
+ for SFP 25G modules, the transceiver code was incorrectly updated with
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+ ||||||||||||
|
+ PAN-286299
+ |
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 releases where, after
+ being offboarded from Panorama, the firewall XML configuration file
+ retained template information from the previous Panorama
+ configuration. As a result, when the firewall and its configuration
+ were imported to another Panorama appliance, all configurations in the
+ Network and
+ Device tab became read-only.
+
+ |
+ ||||||||||||
|
+ PAN-286231
+ |
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to
+ multiple firewalls with different base configurations resulted in
+ configuration corruption, which caused the firewall to go down.
+
+ |
+ ||||||||||||
|
+ PAN-286180
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where, after a failover, an SSH decryption caused a mismatch in
+ the host key, which resulted in a warning message. This issue occurred
+ because the SSH tunnel keys were not synchronized between the active
+ and passive firewalls.
+
+ |
+ ||||||||||||
|
+ PAN-286037
+ |
+
+
+ Fixed an issue where the firewall stopped processing traffic.
+
+ |
+ ||||||||||||
|
+ PAN-286034
+ |
+
+
+ Fixed an issue where the XML API returned an error when attempting to
+ view debug log receiver statistics.
+
+ |
+ ||||||||||||
|
+ PAN-285834
+ |
+
+
+ Fixed an issue on Panorama where
+ Policy recommendation displayed
+ Unable to read data for certain
+ profiles due to a large response size.
+
+ |
+ ||||||||||||
|
+ PAN-285818
+ |
+
+
+ Fixed an issue where a tool was needed to display leaked NAT port
+ numbers without requiring a forced synchronization.
+
+ |
+ ||||||||||||
|
+ PAN-285759
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding during a selective push after a move and
+ rename operation when the configuration was performed via the CLI.
+
+ |
+ ||||||||||||
|
+ PAN-285680
+ |
+
+
+ Fixed an issue where firewalls entered a boot loop after receiving a
+ HSM configuration template push from Panorama.
+
+ |
+ ||||||||||||
|
+ PAN-285623
+ |
+
+
+ Fixed an issue where the
+ configd
+ process restarted and generated a core file during an HA sync commit
+ job. This occurred when the firewall was in the HA passive state.
+
+ |
+ ||||||||||||
|
+ PAN-285615
+ |
+
+
+ Fixed an issue where, when the firewall acted as an IKEv2 responder
+ with fragmentation enabled, the firewall did not send the Notify
+ message type 16430 “IKEV2_FRAGMENTATION_SUPPORTED” in the IKE_SA_INIT
+ exchange. This prevented the remote peer from fragmenting subsequent
+ IKEv2 messages.
+
+ |
+ ||||||||||||
|
+ PAN-285591
+ |
+
+
+ Fixed an issue where the Panorama web interface did not display a
+ warning message when a collector group was configured with a 2 node
+ cluster.
+
+ |
+ ||||||||||||
|
+ PAN-285436
+ |
+
+
+ Fixed an issue where a selective push from Panorama caused the
+ firewall Security policy rules to be removed on firewalls associated
+ with the device group. This occurred when the base configuration
+ version chosen for the selective push preceded the device config
+ import operation, which caused the imported configuration to not be
+ included in the pushed configuration.
+
+ |
+ ||||||||||||
|
+ PAN-285325
+ |
+
+
+ Fixed an issue on Panorama where tags were not automatically populated
+ in the Security policy rule when searching by name in the tag field.
+
+ |
+ ||||||||||||
|
+ PAN-285298
+ |
+
+
+ Fixed an issue where the firewall became unresponsive when the
+ show user user-ids user all CLI
+ command was executed repeatedly on large scale LDAP group mappings,
+ and you were unable to connect to the gateways with the error message
+ The network connection is unreachable or the gateway is
+ unresponsive. Check the network connection and reconnect.
+
+ |
+ ||||||||||||
|
+ PAN-285285
+ |
+
+
+ Fixed an issue where commits remained at 98% completion when static
+ route configuration cleanup was in progress.
+
+ |
+ ||||||||||||
|
+ PAN-284907
+ |
+
+
+ Fixed an issue where the Panorama web interface displayed
+ No Data when viewing configuration
+ logs to see changes before and after a configuration change.
+
+ |
+ ||||||||||||
|
+ PAN-284878
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where commits failed due the
+ useridd
+ process restarting.
+
+ |
+ ||||||||||||
|
+ PAN-284866
+ |
+
+
+ Fixed an issue where the LFC failed to validate Certificate Revocation
+ Lists (CRL) for SSL syslog connections, which caused a failure to
+ forward logs to external syslog servers.
+
+ |
+ ||||||||||||
|
+ PAN-284840
+ |
+
+
+ (PA-5220 firewalls only) Fixed an issue where
+ custom reports were delayed when sent via email instead of being sent
+ at the scheduled time.
+
+ |
+ ||||||||||||
|
+ PAN-284717
+ |
+
+
+ Fixed an issue where a PBF (Policy Based Forwarding) policy rule using
+ an AE (Aggregate Ethernet) interface configured with DHCP as the
+ egress interface incorrectly transitioned to an active state after a
+ commit operation, even when the DHCP lease had expired and the
+ interface had no assigned IP address.
+
+ |
+ ||||||||||||
|
+ PAN-284527
+ |
+
+
+ Fixed an issue where, when a firewall had more than 4,400 logical
+ interfaces, commits failed with the error message
+ Error pre-installing config failed to handle CONFIG_COMMIT.
+
+ |
+ ||||||||||||
|
+ PAN-284441
+ |
+
+
+ Fixed an issue where, after upgrading the firewall, GlobalProtect
+ connections failed with the error message
+ Network Connection is unreachable.
+
+ |
+ ||||||||||||
|
+ PAN-284380
+ |
+
+
+ Fixed an issue where committing a custom report in Panorama
+ incorrectly generated a pending push to devices.
+
+ |
+ ||||||||||||
|
+ PAN-284283
+ |
+
+
+ Fixed an issue on Palo Alto Networks firewalls running PAN-OS 11.1.6
+ where the CLI command
+ traceroute ipv4 yes host <host>
+ failed with a
+ missing argument error message.
+
+ |
+ ||||||||||||
|
+ PAN-284184
+ |
+
+
+ (VM-Series firewalls with Advanced Routing Engine enabled only) Fixed an issue where the
+ frr_ns2_bgpd
+ process repeatedly restarted after committing a configuration that
+ included the same route-map in both the exist and non-exist clauses of
+ a conditional advertisement or when the same route-map was used in
+ both the Advertise-out and conditional exist out map configurations.
+
+ |
+ ||||||||||||
|
+ PAN-284176
+ |
+
+
+ Fixed an issue where QoS throughput limits were not enforced correctly
+ on aggregate ethernet interfaces. As a result, when QoS was enabled on
+ aggregate interfaces, the subnet index was not handled correctly,
+ which caused traffic shaping to be misdirected.
+
+ |
+ ||||||||||||
|
+ PAN-284090
+ |
+
+
+ Fixed an issue where GlobalProtect (GP) portal authentication for
+ satellites using RADIUS authentication failed due to the
+ authentication timeout value being set to 0.
+
+ |
+ ||||||||||||
|
+ PAN-284069
+ |
+
+
+ Fixed an issue where, after an upgrade, the total number of logout
+ records in the HIP database incorrectly displayed as zero.
+
+ |
+ ||||||||||||
|
+ PAN-284067
+ |
+
+
+ Fixed a cumulative memory leak in the
+ devsrvr
+ process that occurred whenever the CLI command
+ show running application statistics
+ was issued. This memory leak would gradually consume system memory and
+ produce an out-of-memory (OOM) condition, causing the firewall to
+ reboot.
+
+ |
+ ||||||||||||
|
+ PAN-284003
+ |
+
+
+ Fixed an issue where clients did not receive a valid response when
+ searching a website due to a compression error.
+
+ |
+ ||||||||||||
|
+ PAN-283979
+ |
+
+
+ Fixed an issue where the firewall became non-functional due to high
+ root partition use.
+
+ |
+ ||||||||||||
|
+ PAN-283954
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding due to a circular reference between address
+ groups.
+
+ |
+ ||||||||||||
|
+ PAN-283936
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ the
+ configd
+ process intermittently restarted, which caused Panorama to be
+ temporarily unavailable.
+
+ |
+ ||||||||||||
|
+ PAN-283864
+ |
+
+
+ Fixed an issue where DNS Security Category exceptions created with DNS
+ category UTID were not ignored.
+
+ |
+ ||||||||||||
|
+ PAN-283741
+ |
+
+
+ Fixed an issue where HTTP/2 child streams were blocked by
+ strict-ip-check zone protection
+ when traffic passed through a transparent proxy.
+
+ |
+ ||||||||||||
|
+ PAN-283613
+ |
+
+
+ Fixed an issue on the web interface where the
+ IP Tag
+ Quota(%) value displayed as 2 even
+ when changed.
+
+ |
+ ||||||||||||
|
+ PAN-283575
+ |
+
+
+ Fixed an issue where iPerf file transfers between a client and server
+ were slower than expected when the firewall was involved in the
+ traffic flow due to
+ cfg.uplink-buffer-resize not
+ being enabled by default.
+
+ |
+ ||||||||||||
|
+ PAN-283563
+ |
+
+
+ Fixed an issue where the GlobalProtect gateway firewall intermittently
+ failed to assign an IP address to GlobalProtect clients from the DHCP
+ server, even after successfully receiving a DHCP offer. This occurred
+ when the DHCP retry and timeout settings were overwritten due to
+ parsing results being stored in the same variable, which caused the
+ last gateway configuration to take effect.
+
+ |
+ ||||||||||||
|
+ PAN-283544
+ |
+
+
+ Fixed an issue where a failover event caused packet loss due to a
+ delay in the child error indication.
+
+ |
+ ||||||||||||
|
+ PAN-283524
+ |
+
+
+ Fixed an issue where commits failed when a certificate with a
+ cryptographic setting of RSA 4096 was used in the Syslog Service
+ Profile due to the firewall being unable to decrypt the private key
+ due to an incorrectly hardcoded private key length.
+
+ |
+ ||||||||||||
|
+ PAN-283522
+ |
+
+
+ Fixed an issue where the SAML single log out (SLO) URL was not
+ correctly displayed in the web interface after it was changed in the
+ SAML profile.
+
+ |
+ ||||||||||||
|
+ PAN-283333
+ |
+
+
+ Fixed an issue where threat logs displayed logs from the
+ N/A threat category when a random
+ string was used for the
+ category-of-threatid filter in
+ threat logs.
+
+ |
+ ||||||||||||
|
+ PAN-283316
+ |
+
+
+ Fixed an issue where a software download job reported a completion
+ timestamp that occurred before the software loading process was
+ finished.
+
+ |
+ ||||||||||||
|
+ PAN-283304
+ |
+
+
+ Fixed an issue where the OSPFv3 area nssa
+ default-information-originate CLI
+ command was not applied due to a configuration error in the backend
+ advanced-routing stack.
+
+ |
+ ||||||||||||
|
+ PAN-283206
+ |
+
+
+ Fixed an issue where configuring an HTTP profile to send Webhook
+ alerts to Microsoft Teams failed with a 400 Bad request error when
+ clicking Send Test Log.
+
+ |
+ ||||||||||||
|
+ PAN-283168
+ |
+
+
+ Fixed an issue related to syslog forwarding that caused the
+ logrcvr
+ process stopped responding.
+
+ |
+ ||||||||||||
|
+ PAN-283165
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected after a period of inactivity due to the Panorama management
+ server unnecessarily reading the
+ running-config.xml file.
+
+ |
+ ||||||||||||
|
+ PAN-283138
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding when exporting CSV files when decryption
+ logs were included in the unified logs.
+
+ |
+ ||||||||||||
|
+ PAN-283004
+ |
+
+
+ Fixed an issue where the firewall bypassed Content Threat Detection
+ (CTD) for sessions with STARTTLS large client hello out-of-order with
+ No Decrypt.
+
+ |
+ ||||||||||||
|
+ PAN-282607
+ |
+
+
+ Fixed an issue where the DHCP process stopped responding when the
+ firewall was configured as a DHCP relay agent.
+
+ |
+ ||||||||||||
|
+ PAN-282578
+ |
+
+
+ Fixed an issue where ping commands from both the management plane and
+ dataplane interfaces incorrectly prioritized IPv6 addresses over IPv4
+ addresses, even when IPv6 was disabled. This caused connectivity
+ issues when pinging FQDNs that resolved to IPv6 addresses.
+
+ |
+ ||||||||||||
|
+ PAN-282571
+ |
+
+
+ Fixed an issue where the Border Gateway Protocol (BGP) established
+ time was displayed inaccurately due to a 32-bit counter wrapping
+ issue.
+
+ |
+ ||||||||||||
|
+ PAN-282533
+ |
+
+
+ Fixed an issue where firewalls in air-gapped environments attempted to
+ connect to a Google IP address for Machine Learning AV (MLAV)
+ functionality, even when MLAV was not licensed or configured.
+
+ |
+ ||||||||||||
|
+ PAN-282454
+ |
+
+
+ Fixed an issue where, when you added the
+ Virtual System Name column under
+ Unified Logs, the column did not
+ remain visible in the table if you closed and re-opened the tab.
+
+ |
+ ||||||||||||
|
+ PAN-282277
+ |
+
+
+ Fixed an issue where an OOM condition on the
+ logrcvr
+ process caused interface flapping, and the interface unexpectedly went
+ down and then recovered without intervention.
+
+ |
+ ||||||||||||
|
+ PAN-281797
+ |
+
+
+ Fixed an issue where firewalls became unstable and stopped responding,
+ which resulted in an OOM condition.
+
+ |
+ ||||||||||||
|
+ PAN-281776
+ |
+
+
+ Fixed an issue on the Panorama web interface where the error message
+ PPPoEv6 Client Interface cannot be enabled with DHCPv6 client
+ was generated when overriding aggregate interfaces even when no DHCPv6
+ or PPPoE was configured.
+
+ |
+ ||||||||||||
|
+ PAN-281596
+ |
+
+
+ Fixed an issue where, when the firewall was configured as an explicit
+ proxy, connections were intermittently dropped.
+
+ |
+ ||||||||||||
|
+ PAN-281576
+ |
+
+
+ Fixed an issue where SNMP traps messages were not sent after system
+ startup.
+
+ |
+ ||||||||||||
|
+ PAN-281488
+ |
+
+
+ Fixed an issue where searching configuration logs for an
+ audit_uuid did not return a
+ result if the rule was created with a clone operation.
+
+ |
+ ||||||||||||
|
+ PAN-281294
+ |
+
+
+ Fixed an issue where, after an
+ authd
+ process restart, the username, password, and source IP address
+ displayed in plain text on the console when attempting to log in via
+ the web interface.
+
+ |
+ ||||||||||||
|
+ PAN-281198
+ |
+
+
+ Fixed an issue on Panorama managed firewalls where, when the service
+ route configuration was set to VLAN as the source, attempting to
+ import the variable CSV into the template resulted in the validation
+ error
+ Failed to parse variable configuration file. This issue occurred because the system incorrectly validated the
+ VLAN interface name in the service route configuration within the
+ template.
+
+ |
+ ||||||||||||
|
+ PAN-281096
+ |
+
+
+ Fixed an issue on HA clusters where, when link and path monitoring was
+ configured and the failover condition was set to
+ all, disconnecting and reconnecting
+ monitored ethernet ports caused the firewall to switch to a
+ nonfunctional role, which resulted in all interfaces except the HA
+ interface going down.
+
+ |
+ ||||||||||||
|
+ PAN-281017
+ |
+
+
+ Fixed an issue where shared objects were displayed in the
+ Push Scope after pushing the
+ configuration from Panorama to managed firewalls.
+
+ |
+ ||||||||||||
|
+ PAN-280910
+ |
+
+
+ Fixed an issue on firewalls with Advanced Routing Engine enabled where
+ BGP route maps were not correctly configured for IPv6 next-hop
+ selection. The firewall rejected the IPv6 configuration provided as
+ the next hop due to an incorrect command sent to FRR (Free Range
+ Routing).
+
+ |
+ ||||||||||||
|
+ PAN-280901
+ |
+
+
+ Fixed an issue where DHCP Based IP Address Assignment for Global
+ protect failed when the management interface was configured to receive
+ its own IP address from DHCP.
+
+ |
+ ||||||||||||
|
+ PAN-280695
+ |
+
+
+ Fixed an issue where all data interfaces went down due to a Forward
+ Error Correction (FEC) mode mismatch. The firewall defaulted to FEC
+ Auto mode, while the peer Cisco switch was configured for FC-FEC.
+
+ |
+ ||||||||||||
|
+ PAN-280409
+ |
+
+
+ Fixed an issue where the popup window did not appear as expected for
+ Clientless VPN users.
+
+ |
+ ||||||||||||
|
+ PAN-280302
+ |
+
+
+ Fixed an issue where the
+ show session cache CLI command
+ was unavailable on VM-Series firewalls with VM license types smaller
+ than VM-200 when session resiliency was enabled.
+
+ |
+ ||||||||||||
|
+ PAN-280101
+ |
+
+
+ Fixed an issue where set and edit commands took longer than expected
+ when adding address objects with a large number of dynamic groups due
+ to the completion cache being enabled. With this fix, the completion
+ cache is disabled by default.
+
+ |
+ ||||||||||||
|
+ PAN-280099
+ |
+
+
+ Fixed an issue in the URL filtering logs where the columns and the
+ displayed contents did not match.
+
+ |
+ ||||||||||||
|
+ PAN-280013
+ |
+
+
+ Fixed an issue where User-ID custom reports were unable to exclude IP
+ address 0.0.0.0 when using the filter
+ ip notin 0.0.0.0.
+
+ |
+ ||||||||||||
|
+ PAN-279829
+ |
+
+
+ Fixed an issue where NAT pool leaks occurred during a test when RTSP
+ traffic hit NAT rules.
+
+ |
+ ||||||||||||
|
+ PAN-279706
+ |
+
+
+ (M-600 appliances only)) Fixed an issue where
+ Panorama did not update all
+ panreplay database entries after
+ performing a commit and full push to all devices.
+
+ |
+ ||||||||||||
|
+ PAN-279690
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused the firewall to unexpectedly
+ restart.
+
+ |
+ ||||||||||||
|
+ PAN-279647
+ |
+
+
+ Fixed an issue where threat names were displayed differently on the
+ web interface and the exported CSV file.
+
+ |
+ ||||||||||||
|
+ PAN-279584
+ |
+
+
+ Fixed an issue where, during software deployment from Panorama to
+ multiple firewalls, some firewalls did not automatically reboot after
+ the upgrade, even when
+ Reboot device after install was
+ selected. This was due to the Panorama timing out before the software
+ deployment completed on the affected firewalls, which prevented the
+ reboot request from being sent.
+
+ |
+ ||||||||||||
|
+ PAN-279415
+ |
+
+
+ Fixed an issue where service routes configured to use a data plane
+ interface incorrectly used the management plane interface for traffic
+ transmission. This issue affected syslog and CRL status traffic when a
+ custom service route was not configured.
+
+ |
+ ||||||||||||
|
+ PAN-279366
+ |
+
+
+ Fixed an issue where the firewall used an unnecessary configuration
+ lock when running operational commands.
+
+ |
+ ||||||||||||
|
+ PAN-279209
+ |
+
+
+ Fixed an issue where changes made to the management interface
+ permitted IP address list in a global template were not pushed to the
+ template stack or firewalls.
+
+ |
+ ||||||||||||
|
+ PAN-279195
+ |
+
+
+ Fixed an issue on Panorama where
+ Device Health displayed the device
+ memory as 0%.
+
+ |
+ ||||||||||||
|
+ PAN-278836
+ |
+
+
+ Fixed an issue where, after an upgrade, GlobalProtect attempted to use
+ the embedded browser instead of the default browser for gateway
+ authentication even when it was configured to use the default browser.
+
+ |
+ ||||||||||||
|
+ PAN-278628
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the
+ configd
+ process restarted during a configuration push from Panorama, which
+ caused the active firewall to lose management access for 20-30
+ minutes.
+
+ |
+ ||||||||||||
|
+ PAN-278507
+ |
+
+
+ Fixed an issue where the OCSP Signing purpose was not included in the
+ Extended Key Usage field when a
+ certificate was generated on the firewall with the OCSP responder
+ called in the certificate. This caused the GlobalProtect connection to
+ fail with the error
+ Missing OCSP signing purpose in the ExtendedKeyUsage.
+
+ |
+ ||||||||||||
|
+ PAN-278364
+ |
+
+
+ Fixed an issue where a stack overflow occurred when the DNS domain
+ name length exceeded 255 characters.
+
+ |
+ ||||||||||||
|
+ PAN-278288
+ |
+
+
+ Fixed an issue where IPv6 BGP peering established between virtual
+ routers even without dataplane connectivity. This occurred because the
+ firewall used the kernel for lookups instead of the dataplane.
+
+ |
+ ||||||||||||
|
+ PAN-278276
+ |
+
+
+ Fixed an issue on Panorama where custom reports displayed an incorrect
+ log count with critical severity when the report filter was built with
+ and without explicitly specifying severity as critical.
+
+ |
+ ||||||||||||
|
+ PAN-278126
+ |
+
+
+ Fixed an issue where the number of registered IP Tags on Panorama did
+ not match the number of registered IP Tags on the managed firewalls
+ due to a change in file format between PAN-OS releases.
+
+ |
+ ||||||||||||
|
+ PAN-277987
+ |
+
+
+ (VM-Series firewalls in AWS environments only)
+ Fixed an issue where HA failover mode incorrectly changed from
+ interface move to
+ secondary IP move after a reboot.
+
+ |
+ ||||||||||||
|
+ PAN-277759
+ |
+
+
+ Fixed an issue where Panorama failed to upgrade due to duplicate
+ path-monitor names configured across different static routes within
+ the same virtual router or logical router.
+
+ |
+ ||||||||||||
|
+ PAN-277755
+ |
+
+
+ Fixed an issue that caused the
+ request system private-data-reset
+ CLI command to fail.
+
+ |
+ ||||||||||||
|
+ PAN-277682
+ |
+
+
+ Fixed an issue where moving an address object from a device group to
+ shared and renaming it did not
+ reflect in the address group, which caused commits to fail.
+
+ |
+ ||||||||||||
|
+ PAN-277617
+ |
+
+
+ Fixed an issue where deleting the NTP server address caused a commit
+ validation error. This occurred when the configuration included both
+ primary and secondary NTP servers and the secondary server was
+ removed.
+
+ |
+ ||||||||||||
|
+ PAN-277306
+ |
+
+
+ Fixed an issue where the XML API and REST API failed to run commands
+ with an error.
+
+ |
+ ||||||||||||
|
+ PAN-277162
+ |
+
+
+ Fixed an issue where random characters were added to the
+ proxy_authorization in HTTP
+ messages when the firewall accessed certain services through a
+ configured proxy server. This caused proxy server authentication to
+ intermittently fail.
+
+ |
+ ||||||||||||
|
+ PAN-277034
+ |
+
+
+ Fixed an issue where WildFire reports were not fully displayed and
+ were not downloadable due to static resources not being found.
+
+ |
+ ||||||||||||
|
+ PAN-277018
+ |
+
+
+ Fixed an issue where FTP data connections did not work for EPRT with
+ Source IP + Port translation enabled on the firewall.
+
+ |
+ ||||||||||||
|
+ PAN-277000
+ |
+
+
+ Fixed an issue where the firewall stopped responding after upgrading
+ to PAN-OS 11.0.2 with lockless-qos enabled.
+
+ |
+ ||||||||||||
|
+ PAN-276961
+ |
+
+
+ Fixed an issue where adding an SD-WAN interface profile to an
+ overridden interface on a template stack failed with an
+ sdwan-interface-profile is invalid
+ error.
+
+ |
+ ||||||||||||
|
+ PAN-276936
+ |
+
+
+ Fixed an issue where the CLI command syntax was incorrect when
+ configuring the
+ deviceconfig values from the
+ Template Stack.
+
+ |
+ ||||||||||||
|
+ PAN-276862
+ |
+
+
+ Fixed an issue on Panorama where the
+ logd
+ process stopped responding unexpectedly.
+
+ |
+ ||||||||||||
|
+ PAN-276795
+ |
+
+
+ Fixed an issue where the GlobalProtect client displayed an error
+ message when you clicked
+ Check Now and
+ Preferred Releases and
+ Base Releases were unchecked (Device > Software).
+
+ |
+ ||||||||||||
|
+ PAN-276694
+ |
+
+
+ Fixed an issue where the firewall unexpectedly rebooted when the
+ show dns-proxy ddns interface name all
+ CLI command was executed with the error
+ Server error: op command for client dnsproxyd timed out as client
+ is not available.
+
+ |
+ ||||||||||||
|
+ PAN-276616
+ |
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet
+ were not visible.
+
+ |
+ ||||||||||||
|
+ PAN-276599
+ |
+
+
+ Fixed an issue where the password expiry prompt was not visible when
+ logging in via the web interface.
+
+ |
+ ||||||||||||
|
+ PAN-276491
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where Panorama stopped responding when running reports.
+
+ |
+ ||||||||||||
|
+ PAN-276484
+ |
+
+
+ Fixed an issue where Panorama did not display license information for
+ Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
+
+ |
+ ||||||||||||
|
+ PAN-276412
+ |
+
+
+ Fixed an issue where you were unable to download XML files from
+ Panorama > Summary > Backups.
+
+ |
+ ||||||||||||
|
+ PAN-276352
+ |
+
+
+ Fixed an issue where multicast flows were dropped due to a missing
+ sysd
+ variable for maximum multicast routes.
+
+ |
+ ||||||||||||
|
+ PAN-276321
+ |
+
+
+ Fixed an issue where User-ID mappings were not correctly redistributed
+ from Panorama to firewalls, causing some users to be identified as
+ unknown, which prevented access to
+ resources based on AD group membership.
+
+ |
+ ||||||||||||
|
+ PAN-276144
+ |
+
+
+ Fixed an issue on the web interface where the
+ Response Page
+ action column was not accessible.
+
+ |
+ ||||||||||||
|
+ PAN-276033
+ |
+
+
+ Fixed an issue on Panorama managed firewalls where
+ SAML identity provider and
+ Clientless Apps objects did not have
+ override or revert options.
+
+ |
+ ||||||||||||
|
+ PAN-276000
+ |
+ + + | +||||||||||||
|
+ PAN-275653
+ |
+
+
+ Fixed an issue where the Log Collector service did not start on a new
+ Log Collector appliance added to a Log Collector group. As a result,
+ the new Log Collector appliance did not appear in the cluster and the
+ number of nodes in the cluster was incorrect.
+
+ |
+ ||||||||||||
|
+ PAN-275601
+ |
+
+
+ Fixed an issue where, when Panorama was not internet connected and you
+ attempted to upload images to managed firewalls using the
+ Validate option, the upload failed
+ with the error
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+ ||||||||||||
|
+ PAN-275451
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ sequence numbers were lost when forwarded from Panorama, which
+ resulted in missing or lost logs.
+
+ |
+ ||||||||||||
|
+ PAN-275272
+ |
+
+
+ Fixed an issue where a dataplane restart was not triggered as expected
+ when internal packet path monitoring failure occurred.
+
+ |
+ ||||||||||||
|
+ PAN-275089
+ |
+
+
+ Fixed an issue where a
+ devsrvr
+ process restart caused commits to fail due to cloud app validation,
+ which resulted in WildFire installs failing.
+
+ |
+ ||||||||||||
|
+ PAN-275050
+ |
+
+
+ Fixed an issue where the Japanese translation for the URL filtering
+ option to add a trailing slash to entries and the device license
+ status error was incorrect.
+
+ |
+ ||||||||||||
|
+ PAN-275026
+ |
+
+
+ Fixed an issue where you were unable to to adjust the frequency of the
+ Advanced Cloud Explorer (ACE) cloud fetch via the CLI.
+
+ |
+ ||||||||||||
|
+ PAN-274907
+ |
+
+
+ Fixed an issue on Panorama where
+ Config Audit Commit Date displayed
+ the timestamp of the configuration edit instead of the commit time.
+
+ |
+ ||||||||||||
|
+ PAN-274650
+ |
+
+
+ Fixed an issue where the firewall did not perform certificate expiry
+ validation during a commit, which resulted in successful
+ authentication even when an intermediate certificate had expired.
+
+ |
+ ||||||||||||
|
+ PAN-274622
+ |
+
+
+ Fixed an issue on the Panorama web interface where GlobalProtect
+ client images were not exported via SCP.
+
+ |
+ ||||||||||||
|
+ PAN-274333
+ |
+
+
+ Fixed an issue where the Logging Service License Status displayed as
+ red even though a valid license was installed on the firewall.
+
+ |
+ ||||||||||||
|
+ PAN-274292
+ |
+
+
+ (M-600 Appliances only) Fixed an issue where
+ the web interface was slow when logging in and filtering for policies
+ due to deep search operations taking longer than expected.
+
+ |
+ ||||||||||||
|
+ PAN-274213
+ |
+
+
+ Fixed an issue where the firewall did not properly update incremental
+ update data maintained at the management plane when an IP address was
+ part of both a Dynamic Address Group and an External Dynamic List
+ (EDL). This resulted in the firewall not matching the expected
+ Security policy rule and threat signature.
+
+ |
+ ||||||||||||
|
+ PAN-274207
+ |
+
+
+ Fixed an issue where Global Search did not redirect correctly to
+ routing profiles when searching for their names.
+
+ |
+ ||||||||||||
|
+ PAN-274086
+ |
+
+
+ Fixed an issue where the firewall incorrectly assembled SIP NOTIFY and
+ REFER messages when processing SIP TCP packets that contained a
+ partial content-body from a previous SIP message and a complete header
+ and content-body from the next SIP message.
+
+ |
+ ||||||||||||
|
+ PAN-274064
+ |
+
+
+ Fixed an issue on Panorama where the
+ request batch license info CLI
+ command displayed entries for devices that were no longer attached to
+ Panorama.
+
+ |
+ ||||||||||||
|
+ PAN-274038
+ |
+
+
+ Fixed an issue where you were unable to use the
+ s_encrypted field in custom reports
+ for the Panorama threat log database.
+
+ |
+ ||||||||||||
|
+ PAN-273991
+ |
+
+
+ Fixed an issue where the transmit power for a cable that was used on
+ port 44 displayed as N/A.
+
+ |
+ ||||||||||||
|
+ PAN-273969
+ |
+
+
+ Fixed an issue where the Panorama interface template did not include
+ the Forward Error Correction (FEC) setting.
+
+ |
+ ||||||||||||
|
+ PAN-273963
+ |
+
+
+ Fixed an issue where GlobalProtect health information (HIP) did not
+ display the certificate key usage.
+
+ |
+ ||||||||||||
|
+ PAN-273947
+ |
+
+
+ Fixed an issue where the displayed group name differed depending on
+ whether the group was configured locally on the firewall or through
+ Panorama.
+
+ |
+ ||||||||||||
|
+ PAN-273805
+ |
+
+
+ Fixed an issue where SAML authentication for GlobalProtect failed when
+ the GlobalProtect portal was accessed externally on a non-standard
+ port.
+
+ |
+ ||||||||||||
|
+ PAN-273589
+ |
+
+
+ Fixed an issue where firewalls configured with a VPN tunnel stopped
+ responding when a configuration update was applied.
+
+ |
+ ||||||||||||
|
+ PAN-273010
+ |
+
+
+ Fixed an issue where the configuration version did not increment in
+ the Audit Comment Archive after making changes to the Security policy
+ rule with an audit comment and performing a commit. As a result, all
+ subsequent changes were grouped under the same configuration version,
+ which prevented the comparison of changes in the
+ Rule Changes field of the Security
+ policy rule.
+
+ |
+ ||||||||||||
|
+ PAN-273008
+ |
+
+
+ (PA-5400 firewalls only) Fixed an issue where
+ frequent BGP/BFD flaps occurred and HA2 keep-alives went down.
+
+ |
+ ||||||||||||
|
+ PAN-272998
+ |
+
+
+ Fixed an issue where commits from Panorama to VM-Series firewalls on
+ Microsoft Azure environments failed.
+
+ |
+ ||||||||||||
|
+ PAN-272796
+ |
+
+
+ Fixed an issue where you were unable to export the GlobalProtect
+ client software version to the SCP server.
+
+ |
+ ||||||||||||
|
+ PAN-272790
+ |
+
+
+ Fixed an issue on the Panorama web interface where administrators were
+ unable to export GlobalProtect client images and received an
+ scp export failed error. This was
+ due to the system attempting to retrieve the file from an incorrect
+ directory.
+
+ |
+ ||||||||||||
|
+ PAN-272743
+ |
+
+
+ Fixed an issue where non-captive portal traffic was not visible under
+ Traffic Logs when the traffic was
+ denied by an authentication rule and the session was discarded.
+
+ |
+ ||||||||||||
|
+ PAN-272726
+ |
+
+
+ Fixed an issue on the web interface where the
+ URL Filtering change category
+ feature did not work.
+
+ |
+ ||||||||||||
|
+ PAN-272505
+ |
+
+
+ Fixed an issue where GlobalProtect cookie authentication failed with
+ the error
+ User is not in allow list.
+
+ |
+ ||||||||||||
|
+ PAN-272469
+ |
+
+
+ Fixed an issue where the DNS exception displayed
+ 0 instead of
+ no result in the anti-spyware
+ profile when no threat ID was available for a DNS Security category.
+
+ |
+ ||||||||||||
|
+ PAN-272408
+ |
+
+
+ (PA-1420 firewalls only) Fixed an issue where
+ the firewall reported unsupported SFPs when PAN-SFPPLUS10GBASE-T SFPs
+ were used on ports Ethernet 1/21 and 1/22.
+
+ |
+ ||||||||||||
|
+ PAN-272178
+ |
+
+
+ Fixed an issue where the firewall displayed packet buffers between 18
+ and 19 even when there was little or no traffic.
+
+ |
+ ||||||||||||
|
+ PAN-272172
+ |
+
+
+ Fixed an issue where
+ plugin_api_server could
+ experience a memory leak when using OpenConfig for telemetry.
+
+ |
+ ||||||||||||
|
+ PAN-271810
+ |
+
+
+ Fixed an issue where auto-negotiation advertised and negotiated 10/100
+ half and full duplex.
+
+ |
+ ||||||||||||
|
+ PAN-271637
+ |
+
+
+ Fixed an issue where the firewall did not increase the metric of the
+ default route when redistributed into OSPF when the firewall was
+ configured as an NSSA ABR.
+
+ |
+ ||||||||||||
|
+ PAN-271636
+ |
+
+
+ (PA-1400 and PA-3400 Series firewalls only)
+ Fixed an issue where the firewall displayed the error message
+ Failed to parse pbf policy when
+ you committed a configuration that included more than 8 Policy Based
+ Forwarding (PBF) rules with symmetric return enabled.
+
+ |
+ ||||||||||||
|
+ PAN-271490
+ |
+
+
+ Fixed an issue on the firewall that caused the following error message
+ to be displayed:
+ frr_ns0: failed to stop child frr_ns0_ospf6d.
+
+ |
+ ||||||||||||
|
+ PAN-271440
+ |
+
+
+ Fixed an issue where
+ PublicCloud Server certificate validation failed. Dest Addr:
+ (null), Reason: self signed certificate in certificate chain
+ generated as a high alert in the system log every 5 minutes.
+
+ |
+ ||||||||||||
|
+ PAN-271438
+ |
+
+
+ Fixed an issue where the firewall calculated available memory
+ incorrectly on CENTOS devices, which caused the firewall to display
+ high memory usage alerts even when sufficient memory was available.
+
+ |
+ ||||||||||||
|
+ PAN-271436
+ |
+
+
+ A CLI counter was added to indicate a full suppression queue.
+
+ |
+ ||||||||||||
|
+ PAN-271412
+ |
+
+
+ Fixed an issue where the character ( + ) in the authentication message
+ prompt displayed incorrectly as
+ #43; on the GlobalProtect client
+ after upgrading to a PAN-OS 10.2 release.
+
+ |
+ ||||||||||||
|
+ PAN-271301
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments with
+ GWLB integrated only) Fixed an issue where DNS queries timed out when overlay routing was
+ enabled.
+
+ |
+ ||||||||||||
|
+ PAN-271204
+ |
+
+
+ Fixed an issue where performing a factory reset caused the firewall to
+ enter a continuous boot loop due to a failure in generating the
+ global.xml configuration file.
+
+ |
+ ||||||||||||
|
+ PAN-271173
+ |
+
+
+ Fixed an issue where the firewall displayed an incorrect maximum
+ translated IP capacity when using DIPP NAT policy rules.
+
+ |
+ ||||||||||||
|
+ PAN-271061
+ |
+
+
+ Fixed an issue on the web interface where you were unable to add
+ Threat IDs to Signature Exceptions.
+
+ |
+ ||||||||||||
|
+ PAN-270747
+ |
+
+
+ Fixed an issue where the
+ show system statistics application
+ CLI command failed.
+
+ |
+ ||||||||||||
|
+ PAN-270554
+ |
+
+
+ Fixed an issue where the GlobalProtect client (UWP) or metered hotspot
+ connections triggered TLS resumption fo GlobalProtect portal
+ authentication, which caused the portal authentication to fail with a
+ valid cert required error.
+
+ |
+ ||||||||||||
|
+ PAN-270493
+ |
+
+
+ Fixed an issue where the
+ Low free buffer limit output was
+ not available.
+
+ |
+ ||||||||||||
|
+ PAN-270323
+ |
+
+
+ Fixed an issue where the firewall allowed cleartext web-browsing
+ traffic on port 443 when the Security policy rule was configured to
+ allow application: web-browsing with service: application-default.
+
+ |
+ ||||||||||||
|
+ PAN-269913
+ |
+
+
+ Fixed an issue threat reports were empty when generated from Panorama,
+ but displayed correctly when generated from the firewall.
+
+ |
+ ||||||||||||
|
+ PAN-269843
+ |
+
+
+ Fixed an issue where the firewall dropped non-SYN TCP packets even
+ when the Reject non-SYN TCP option
+ was set to No when a session rematch
+ was triggered.
+
+ |
+ ||||||||||||
|
+ PAN-269716
+ |
+
+
+ Fixed an issue where half-closed TCP sessions did not refresh the
+ session timeout when continuously receiving data after setting the
+ cfg.session.tcp-no-refresh-fin-rst
+ option toTrue.
+
+ |
+ ||||||||||||
|
+ PAN-269659
+ |
+
+
+ Fixed an issue on the firewall where you were unable to configure more
+ than 500 DHCP relay servers even though the supported limit was 4096.
+
+ |
+ ||||||||||||
|
+ PAN-269535
+ |
+
+
+ Fixed an issue where the mib ID returned an incorrect value via SNMP.
+
+ |
+ ||||||||||||
|
+ PAN-269445
+ |
+
+
+ Fixed an issue where the
+ show user ip-user-mapping all option detail
+ XML API command did not show the complete output.
+
+ |
+ ||||||||||||
|
+ PAN-269342
+ |
+
+
+ Fixed an issue where BGP aggregate routes with the AS-SET option
+ enabled had incorrect AS paths.
+
+ |
+ ||||||||||||
|
+ PAN-269303
+ |
+
+
+ Fixed an issue where the CSV export of disabled applications included
+ duplicate entries, which caused the count of disabled applications to
+ be higher in the CSV export than on the web interface.
+
+ |
+ ||||||||||||
|
+ PAN-269286
+ |
+
+
+ Fixed an issue where the firewall did not query for an AAAA record
+ when only IPv6 was enabled for the management interface.
+
+ |
+ ||||||||||||
|
+ PAN-269228
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused a split brain condition.
+
+ |
+ ||||||||||||
|
+ PAN-269191
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the aggressive clean-up threshold for disk space was set to 95% in
+ system monitor.
+
+ |
+ ||||||||||||
|
+ PAN-269176
+ |
+
+
+ Fixed an issue where the
+ domain-edl column was empty in the
+ threat log even when a threat was detected as a DNS alert.
+
+ |
+ ||||||||||||
|
+ PAN-269155
+ |
+
+
+ Fixed an issue where an OOM condition occurred, which caused processes
+ to stop responding.
+
+ |
+ ||||||||||||
|
+ PAN-269057
+ |
+
+
+ Fixed an issue where the
+ routed
+ process stopped responding due to accessing freed memory from a hash
+ table when the route vectors were resized. This occurred when a large
+ number of static routes were configured.
+
+ |
+ ||||||||||||
|
+ PAN-269051
+ |
+
+
+ Fixed an issue where, when using WildFire Private Cloud, the system
+ log displayed the error message
+ tls-X509-validation.
+
+ |
+ ||||||||||||
|
+ PAN-268922
+ |
+
+
+ (PA-3220 firewalls in HA configurations only)
+ Fixed an intermittent issue where the firewalls went out of sync after
+ a configuration push from Panorama.
+
+ |
+ ||||||||||||
|
+ PAN-268787
+ |
+
+
+ Fixed an issue where users were unable to log in to Panorama and the
+ following error message was displayed:
+ Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of
+ devices.
+
+ |
+ ||||||||||||
|
+ PAN-268680
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when a configuration merge operation
+ changed.
+
+ |
+ ||||||||||||
|
+ PAN-268606
+ |
+
+
+ Fixed an issue where GlobalProtect users with client certificates
+ received an authentication failure message without entering a password
+ and clicking connect or
+ login.
+
+ |
+ ||||||||||||
|
+ PAN-268597
+ |
+
+
+ Fixed an issue where the firewall displayed 0 bytes received for
+ GlobalProtect SSL sessions in the traffic logs.
+
+ |
+ ||||||||||||
|
+ PAN-268569
+ |
+
+
+ Fixed an issue where the web interface was slower than expected when
+ logging in and filtering for policies.
+
+ |
+ ||||||||||||
|
+ PAN-268522
+ |
+
+
+ Fixed an issue where the firewall failed to connect to the update
+ server with a customized service route when the source interface was
+ set to MGT and the source address
+ was set as IPv4.
+
+ |
+ ||||||||||||
|
+ PAN-268426
+ |
+
+
+ Fixed an issue where the firewall was unable to connect to a syslog
+ server that used a TLS certificate without a subject key identifier.
+
+ |
+ ||||||||||||
|
+ PAN-268425
+ |
+
+
+ Fixed an issue where the
+ execute show transceiver-detail all
+ XML API command returned an incorrect value for the low temperature
+ alarm threshold.
+
+ |
+ ||||||||||||
|
+ PAN-268313
+ |
+
+
+ Fixed an issue where the Priority Code Point (PCP) bits in the VLAN
+ header were not reset to 0 when a packet was received from one Layer 3
+ tagged interface and forwarded to another, which resulted in dropped
+ packets.
+
+
+ To use this fix, run the CLI command
+ set force-vlan-pcp-reset yes and
+ reboot the firewall.
+
+ |
+ ||||||||||||
|
+ PAN-268032
+ |
+
+
+ Fixed an issue where importing a device configuration into Panorama
+ failed with a validation error if the configuration included a shared
+ gateways containing NAT/PBF rules.
+
+ To use this fix:
+
+ Note: This fix is supported on PAN-OS 10.2 and later releases.
+
+ |
+ ||||||||||||
|
+ PAN-267936
+ |
+
+
+ Fixed an issue where commits failed with a validation error when you
+ changed the encryption level and re-encryption option on a Panorama
+ managed firewall.
+
+ |
+ ||||||||||||
|
+ PAN-267912
+ |
+
+
+ Fixed an issue on the Panorama web interface where
+ Application and
+ Category was not able to be selected
+ under Test Policy Match.
+
+ |
+ ||||||||||||
|
+ PAN-267830
+ |
+
+
+ Fixed an issue where the snmpd.log.old file continuously increased,
+ which caused the root partition to become full.
+
+ |
+ ||||||||||||
|
+ PAN-267614
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected due to high CPU utilization on the
+ mongodb
+ process.
+
+ |
+ ||||||||||||
|
+ PAN-267426
+ |
+
+
+ (Firewalls in HA configuration only) Fixed an
+ issue where the
+ Network pre-negotiation enabled page
+ did not display on the firewall dashboard.
+
+ |
+ ||||||||||||
|
+ PAN-267381
+ |
+
+
+ Fixed an issue where the firewall failed to upload a macOSX file if
+ the file had a MIME boundary.
+
+ |
+ ||||||||||||
|
+ PAN-267330
+ |
+
+
+ Fixed an issue where the firewall dropped inbount RTP traffic after
+ using Webex Screen Sharing due to the firewall removing the NAT cache
+ when the predict timed out, which caused a new NAT to be established
+ that conflicted with existing sessions. To use this fix, run the CLI
+ command
+ set system setting ctd h323_rtp_predict timeout
+ <120-3600>
+ to increase the timeout limit.
+
+ |
+ ||||||||||||
|
+ PAN-267328
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused the firewall to stop
+ processing traffic.
+
+ |
+ ||||||||||||
|
+ PAN-267117
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ BGP route refreshes occurred when a commit was performed if
+ AS Set was enabled for BGP aggregate
+ routes.
+
+ |
+ ||||||||||||
|
+ PAN-267045
+ |
+
+
+ Fixed an issue on the firewall where ICMP ping loss occurred after
+ installing a Network Processing Card (NPC) in slot 7.
+
+ |
+ ||||||||||||
|
+ PAN-266971
+ |
+
+
+ Fixed an issue where the firewall generated AAAA DNS queries when IPv6
+ firewalling was disabled.
+
+ |
+ ||||||||||||
|
+ PAN-266905
+ |
+
+
+ Fixed an issue where sessions ended with the message
+ decrypt error in the logs for
+ traffic that matched a
+ no-decrypt policy.
+
+ |
+ ||||||||||||
|
+ PAN-266698
+ |
+
+
+ Fixed an issue where an email was able to be transferred to the
+ destination MTA even when the firewall detected a suspicious file with
+ a reset-bot action when it was encrypted by STARTTLS.
+
+ |
+ ||||||||||||
|
+ PAN-266688
+ |
+
+
+ Fixed an issue on the firewall where traffic matched a custom
+ signature even if the custom signature was removed from the
+ configuration.
+
+ |
+ ||||||||||||
|
+ PAN-266589
+ |
+
+
+ Fixed an issue where the firewall was unable to generate a tech
+ support file when management server debug was disabled.
+
+ |
+ ||||||||||||
|
+ PAN-266302
+ |
+
+
+ Fixed an issue where OSPFv3 Link State (LS) update packets (type 9)
+ were not fragmented properly, which caused the OSPF header to have an
+ incorrect checksum when sent from the firewall. This occurred when the
+ update packet size exceeded 1514 byte, which resulted in the peer
+ device rejecting the packet and the neighbor relationship going down.
+
+ |
+ ||||||||||||
|
+ PAN-265926
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the
+ all_task
+ process stopped responding, which caused the firewall to reboot.
+
+ |
+ ||||||||||||
|
+ PAN-265916
+ |
+
+
+ Fixed an issue where double-clicking the login button returned the
+ error message
+ Login session expired.
+
+ |
+ ||||||||||||
|
+ PAN-265782
+ |
+
+
+ Fixed an issue on Panorama where, after you enabled multihop in a BFD
+ profile, you were unable to disable it via the web interface.
+
+ |
+ ||||||||||||
|
+ PAN-265686
+ |
+
+
+ Fixed an issue where the GlobalProtect portal logged passwords in
+ cleartext.
+
+ |
+ ||||||||||||
|
+ PAN-264912
+ |
+
+
+ Fixed an issue where the firewall did not shut down completely.
+
+ |
+ ||||||||||||
|
+ PAN-264742
+ |
+
+
+ Fixed an issue on Panorama where the dynamic address group IP
+ addresses of the Kubernetes plugin or Prisma Cloud plugin for Secure
+ Developer Environment were not displayed.
+
+ |
+ ||||||||||||
|
+ PAN-264666
+ |
+
+
+ Fixed an issue where the
+ configd
+ process restarted when pushing configurations to multiple device
+ groups via XML API, which caused the push to fail.
+
+ |
+ ||||||||||||
|
+ PAN-264570
+ |
+
+
+ Fixed an issue where the maximum session limit for a vsys was
+ 4,194,290.
+
+ |
+ ||||||||||||
|
+ PAN-264538
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the
+ all_task
+ process stopped responding and a reboot was required.
+
+ |
+ ||||||||||||
|
+ PAN-264131
+ |
+
+
+ Fixed an issue where the
+ routed
+ process core failed the automation run.
+
+ |
+ ||||||||||||
|
+ PAN-264040
+ |
+
+
+ Fixed an issue where AAAA DNS queries went out even when
+ IPv6 firewalling was disabled.
+
+ |
+ ||||||||||||
|
+ PAN-263699
+ |
+
+
+ PA-440 firewalls only) Fixed an issue where the
+ firewall was unable to create more than 6 GlobalProtect gateways.
+
+ |
+ ||||||||||||
|
+ PAN-263674
+ |
+
+
+ (VM-Series firewalls in HA configurations only)
+ Fixed an issue where the firewall rebooted due to multiple HA
+ failovers.
+
+ |
+ ||||||||||||
|
+ PAN-263544
+ |
+
+
+ Fixed an issue where management plane CPU usage increased after
+ upgrading when there was a full-mesh User-ID redistribution
+ configuration between multiple firewalls.
+
+ |
+ ||||||||||||
|
+ PAN-263504
+ |
+
+
+ Fixed an issue where exporting managed device information from
+ Panorama in CSV format included extraneous characters.
+
+ |
+ ||||||||||||
|
+ PAN-263270
+ |
+
+
+ Fixed an issue where, after a commit was performed from Strata Cloud
+ Manager, the SD-WAN configuration containing BGP routes did not
+ display on the hub firewall.
+
+ |
+ ||||||||||||
|
+ PAN-263052
+ |
+
+
+ Fixed an issue where the
+ request logdb migrate-to-panorama start end-time <start-time>
+ <type>
+ CLI command did not work as expected, and you were unable to resend
+ logs from a firewall to Panorama or a log collector.
+
+ |
+ ||||||||||||
|
+ PAN-262599
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect policy cache
+ usage and configuration memory usage during a commit, which caused the
+ configuration commit to fail with a
+ CONFIG_UPDATE_START error. This
+ occurred when a large number of External Dynamic Lists (EDLs), shared
+ addresses, and policy rules were configured.
+
+ |
+ ||||||||||||
|
+ PAN-262521
+ |
+
+
+ Fixed an issue where imported certificates were not visible on
+ firewalls with multi-vsys disabled.
+
+ |
+ ||||||||||||
|
+ PAN-262278
+ |
+
+
+ Fixed an issue where the service route setting for HTTP was not
+ applied when the source interface IP address was set via an address
+ object, which caused HTTP traffic to be sent from the management
+ interface.
+
+ |
+ ||||||||||||
|
+ PAN-262043
+ |
+
+
+ Fixed an issue where Voice over WiFi (VoWiFi) stopped working after
+ switching from a PA-5200 Series firewall to a PA-7500 Series firewall
+ in NGFW clustering mode with NATT IPSec Passthrough and NAT policy
+ enabled. To use this fix, enter the CLI command
+ show tunnel-acceleration, disable
+ tunnel acceleration, and reboot the PA-7500 Series firewall.
+
+ |
+ ||||||||||||
|
+ PAN-261936
+ |
+
+
+ Fixed an issue where WildFire submission logs were not displayed when
+ filtered by Sender Address.
+
+ |
+ ||||||||||||
|
+ PAN-261602
+ |
+
+
+ Fixed an issue where GlobalProtect Decryption logs were not forwarded
+ to Panorama.
+
+ |
+ ||||||||||||
|
+ PAN-260879
+ |
+
+
+ Fixed an issue where the Panorama port 28270 did not adhere to the
+ restricted TLS version and ciphers set in the
+ Secure Communication Settings.
+
+ |
+ ||||||||||||
|
+ PAN-260790
+ |
+
+
+ Fixed an issue where the bytes transmitted and packet transmitted
+ counters for hardware interfaces incorrectly displayed as 0 after a
+ restart of slot-1.
+
+ |
+ ||||||||||||
|
+ PAN-260752
+ |
+
+
+ Fixed an issue where the firewall did not support TLSv1.3 in the
+ Clientless VPN, which caused the portal page to not load.
+
+ |
+ ||||||||||||
|
+ PAN-260661
+ |
+
+
+ Fixed an issue where daily email reports generated from the custom
+ report did not display the report details in PDF or CSV files.
+
+ |
+ ||||||||||||
|
+ PAN-260581
+ |
+
+
+ Fixed an issue where Panorama template changes to the zone and virtual
+ router were not pushed to managed firewalls when the template stack
+ default virtual system was set to
+ None.
+
+ |
+ ||||||||||||
|
+ PAN-260540
+ |
+
+
+ Fixed an issue where task-debug logs remained on the debug level even
+ after running the
+ debug dataplane packet-diag set log off
+ CLI command, which caused high dataplane CPU utilization.
+
+ |
+ ||||||||||||
|
+ PAN-260330
+ |
+
+
+ Fixed an issue where Panorama was unable to generate PDF reports when
+ the footer contained a GIF image.
+
+ |
+ ||||||||||||
|
+ PAN-259998
+ |
+
+
+ (M-600 Appliances only) Fixed an issue where
+ log collectors in a cluster stopped responding when running high load
+ tests.
+
+ |
+ ||||||||||||
|
+ PAN-259741
+ |
+
+
+ Fixed an issue where the firewall dropped GRE keepalive packets that
+ were encapsulated under another GRE tunnel.
+
+ |
+ ||||||||||||
|
+ PAN-259343
+ |
+
+
+ Fixed an issue on the Panorama web interface where the
+ Configuration tab did not accurately
+ display changes made to URL filtering profiles.
+
+ |
+ ||||||||||||
|
+ PAN-259284
+ |
+
+
+ Fixed an issue where IPv4 BGP routes were not included in the routing
+ table or FIB of a virtual router when ECMP was configured with more
+ than two next hops.
+
+ |
+ ||||||||||||
|
+ PAN-259091
+ |
+
+
+ Fixed an issue where the CLI command
+ show user ip-user-mapping-mp all
+ displayed the total timeout value instead of the current timeout value
+ when the
+ set cli op-command-xml-output on
+ CLI command was used.
+
+ |
+ ||||||||||||
|
+ PAN-258912
+ |
+
+
+ (PA-7000b firewalls only) Fixed an issue where
+ the firewall web interface displayed an incorrect HSM client version
+ when the client was upgraded to version 7.2.0.220.
+
+ |
+ ||||||||||||
|
+ PAN-258456
+ |
+
+
+ Fixed an issue where not all IP-TAG logs were forwarded to Log
+ Collectors.
+
+ |
+ ||||||||||||
|
+ PAN-258039
+ |
+
+
+ Fixed an issue where the firewall displayed the incorrect rule name
+ when a threat log was generated for Inline Cloud Analyzed CMD
+ Injection Traffic Detection.
+
+ |
+ ||||||||||||
|
+ PAN-257638
+ |
+
+
+ Fixed an issue where the firewall dataplane stopped responding, which
+ caused BGP flaps between hubs and branches.
+
+ |
+ ||||||||||||
|
+ PAN-257616
+ |
+
+
+ Fixed an issue where selective push operations from Panorama to
+ managed firewalls failed with the error message
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+ ||||||||||||
|
+ PAN-257362
+ |
+
+
+ Fixed an issue where GlobalProtect traffic destined for the internet
+ did not follow the path-based forwarding (PBF) rule and was sent out
+ the wrong interface.
+
+ |
+ ||||||||||||
|
+ PAN-257195
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where the mp-monitor logs did not print disk SMART data.
+
+ |
+ ||||||||||||
|
+ PAN-257074
+ |
+
+
+ Fixed an issue on the Panorama web interface where the template sync
+ status showed Out-of-Sync for
+ managed devices after a combined commit-all operation. This occurred
+ due to Panorama sending the default MD5 sum of the template to the
+ firewall instead of the correct MD5 sum.
+
+ |
+ ||||||||||||
|
+ PAN-256560
+ |
+
+
+ Fixed an issue where exporting a
+ Custom Report to CSV format did not
+ display the full report if it contained non-ASCII characters.
+
+ |
+ ||||||||||||
|
+ PAN-256552
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ stopped responding, which caused the firewall to restart.
+
+ |
+ ||||||||||||
|
+ PAN-256138
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ firewalls with a DNS server IP address received by DHCP from Amazon
+ Web Services (AWS) had a delay in resolving FQDNs after a reboot.
+
+ |
+ ||||||||||||
|
+ PAN-255860
+ |
+
+
+ (PA-5200 firewalls only) Fixed an issue where
+ the
+ all_pktproc
+ process stopped responding when the firewall was under a heavy traffic
+ load.
+
+ |
+ ||||||||||||
|
+ PAN-255806
+ |
+
+
+ Fixed an issue on Panorama where the ACC report for URL categories
+ displayed inconsistent results for the same time range when run daily.
+
+ |
+ ||||||||||||
|
+ PAN-255654
+ |
+
+
+ Fixed an issue where, when QoS was enabled on aggregate interfaces,
+ the maximum aggregate interface throughput was capped, which limited
+ network traffic. This occurred even with default QoS settings and no
+ configured egress max-bandwidth.
+
+ |
+ ||||||||||||
|
+ PAN-255547
+ |
+
+
+ Fixed an issue where commits failed when importing configurations to a
+ device with a non-default master key.
+
+ |
+ ||||||||||||
|
+ PAN-255282
+ |
+
+
+ (PA-450 firewalls in HA configurations only)
+ Fixed an issue where the firewall remained in an active state and all
+ traffic stopped until a failover to the passive firewall was
+ performed.
+
+ |
+ ||||||||||||
|
+ PAN-255253
+ |
+
+
+ Fixed an issue where the firewall did not establish a syslog
+ connection to the probe VM syslog server in ADEM Regressions.
+
+ |
+ ||||||||||||
|
+ PAN-255190
+ |
+
+
+ Fixed an issue where the TCP timeout value was reflected incorrectly
+ when using application override for a custom application in TAP mode.
+
+ |
+ ||||||||||||
|
+ PAN-255025
+ |
+
+
+ Fixed an issue where the
+ show session cache all CLI
+ command failed with the error message
+ Server error : An error occured. See dagger.log for
+ information.
+
+ |
+ ||||||||||||
|
+ PAN-254946
+ |
+
+
+ Fixed an issue where the firewall HA2 keep-alive went down multiple
+ times without a specific reason.
+
+ |
+ ||||||||||||
|
+ PAN-254875
+ |
+
+
+ (PA-410 firewalls only) Fixed an issue where
+ the firewall rebooted unexpectedly due to multiple
+ all_task
+ process restarts.
+
+ |
+ ||||||||||||
|
+ PAN-254297
+ |
+
+
+ Fixed an issue where the
+ show pbf rule name <name>
+ CLI command failed.
+
+ |
+ ||||||||||||
|
+ PAN-253778
+ |
+
+
+ (PA-7500 Series firewalls in a cluster configuration only) Fixed an issue where users were able to enable or disable certain
+ configurations.
+
+ |
+ ||||||||||||
|
+ PAN-253187
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the class of service (CoS) priority bit was not modified, causing
+ access points to lose connectivity to the wireless controller when
+ traffic was routed through the firewall.
+
+ |
+ ||||||||||||
|
+ PAN-252706
+ |
+
+
+ Fixed an issue where the URL filtering response page for
+ Continue and
+ Override did not work with IPv6
+ Router Advertisement (RA) or Multicast Listener Query (MLQ) for
+ IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
+
+ |
+ ||||||||||||
|
+ PAN-252699
+ |
+
+
+ Fixed an issue where frequent session failures occurred due to CTD
+ resource exhaustion.
+
+ |
+ ||||||||||||
|
+ PAN-251442
+ |
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode if
+ the authentication process restarted repeatedly.
+
+ |
+ ||||||||||||
|
+ PAN-250048
+ |
+
+
+ Fixed an issue where applications did not load via the Clientless VPN
+ portal when the portal was hosted on an L3 VLAN interface.
+
+ |
+ ||||||||||||
|
+ PAN-250043
+ |
+
+
+ Fixed an issue where, on an NGFW cluster node, operations failed when
+ QoS interfaces were configured with an egress max that exceeded 68,000
+ Mbps.
+
+ |
+ ||||||||||||
|
+ PAN-249574
+ |
+
+
+ Fixed an issue where selective pushes failed due to a missing log
+ collector reference.
+
+ |
+ ||||||||||||
|
+ PAN-249194
+ |
+
+
+ Fixed an issue where SaaS quality profile probes were dropped on the
+ SD-WAN hub.
+
+ |
+ ||||||||||||
|
+ PAN-248148
+ |
+
+ Jumbo frame feature support is enabled.
+ |
+ ||||||||||||
|
+ PAN-247141
+ |
+
+
+ Fixed an issue where DNS traffic did not match the intended SD-WAN
+ policy rule when NAT was enabled.
+
+ |
+ ||||||||||||
|
+ PAN-243335
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ add static IPv6 address entries to a logical router in a cluster
+ template stack.
+
+ |
+ ||||||||||||
|
+ PAN-242777
+ |
+
+
+ Fixed and issue where users previously reported limitations due to
+ session count caps when utilizing
+ Web Proxy features on PA-5400 Series Firewalls. To
+ address these performance complaints and support higher traffic
+ volumes, we have increased the maximum session capacity on specific
+ PA-5400F series platforms, leveraging available
+ system memory. This update ensures greater capacity and stability for
+ high-volume environments.
+
+
+ The supported session limits are:
+
+
+
+
+
+
+
+
+
+
+
|
+ ||||||||||||
|
+ PAN-241953
+ |
+ + + | +||||||||||||
|
+ PAN-241694
+ |
+
+
+ Fixed an issue where memory leaks related to the
+ devsrvr
+ process occurred when downloading and pushing updates from the App-ID
+ Cloud Engine to the dataplane.
+
+ |
+ ||||||||||||
|
+ PAN-241230
+ |
+
+
+ Fixed an issue where the SNMP get request status value for Panorama
+ connections was incorrect.
+
+ |
+ ||||||||||||
|
+ PAN-238208
+ |
+
+
+ Fixed an issue where the firewall API returned inconsistent responses
+ to a failed call using a valid API key. With this fix, the firewall
+ returns the error
+ Session is invalid if the session is
+ not available for the cookie.
+
+ |
+ ||||||||||||
|
+ PAN-234993
+ |
+
+
+ Fixed an issue where CPU base gateway auto-scaling failed, which
+ caused performance issues.
+
+ |
+ ||||||||||||
|
+ PAN-221137
+ |
+
+
+ Fixed an issue where the CLI command to set the target virtual system
+ accepted a non-existent virtual system name, and the CLI prompt
+ incorrectly changed to the non-existent virtual system.
+
+ |
+ ||||||||||||
|
+ PAN-216770
+ |
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud
+ Manager and configured to use a proxy server for external connections,
+ the management server did not use the configured settings to connect
+ to the Cloud Management service.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-297972
+ |
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched
+ Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
+ Analysis features were not enabled.
+
+ |
+
|
+ PAN-297458
+ |
+
+
+ Fixed an issue where the
+ all_task_1
+ process crashed on the firewall when the wif service wasn't available
+ because the wif detection ID was not in the current service table.
+
+ |
+
|
+ PAN-297261
+ |
+
+
+ Fixed an issue where the proxy-protocol debug level was set to
+ verbose on Prisma Access
+ instances, even when it was not explicitly configured, which caused
+ excessive logging by the
+ pan_task
+ process.
+
+ |
+
|
+ PAN-296519
+ |
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an
+ associated error in
+ Wifclient
+ caused the entire pool to close, which resulted in a complete
+ disconnection.
+
+ |
+
|
+ PAN-296478
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
+ GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
+ JavaScript links, resulting in an authorization error. This occurred
+ because the firewall was incorrectly injecting text into URLs when
+ JavaScript buttons or dropdown menus were clicked within the
+ Clientless VPN portal.
+
+ |
+
|
+ PAN-296283
+ |
+
+
+ Fixed an issue where, on hardware platforms with the SaaS inline
+ license, Additional Header Logging (AHL) hash table creation proceeded
+ even when the feature was disabled through the CLI, potentially
+ leading to crashes.
+
+ |
+
|
+ PAN-295944
+ |
+
+
+ Fixed an issue where static routes remained active in the FIB and RIB
+ even when the associated physical port interface was down, which
+ resulted in traffic being incorrectly routed through a non-operational
+ interface.
+
+ |
+
|
+ PAN-295812
+ |
+
+
+ Fixed an issue where the throughput data on the Switch Card Module
+ (SCM) was not accurately reported. This issue affected Standard SC
+ USABN and USABN-2 when using Direct-IO deployment.
+
+ |
+
|
+ PAN-295342
+ |
+
+
+ Fixed an issue where the
+ pan_comm
+ process stopped responding due to insufficient time allocated to read
+ file descriptors when processing long messages.
+
+ |
+
|
+ PAN-292539
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the firewall generated incomplete or corrupted tech support files
+ (TSF) due to high disk usage on the management plane.
+
+ |
+
|
+ PAN-291940
+ |
+
+
+ Fixed an issue where the firewall established multiple TCP connections
+ to a syslog server, which caused logs to be dropped. This occurred
+ because the firewall established a new TCP session for each transfer
+ and the sessions were not closed, which resulted in a continuous
+ increase in connections over time.
+
+ |
+
|
+ PAN-289249
+ |
+
+
+ Fixed an issue where a memory leak occurred on the
+ reportd
+ process when a WildFire update was initiated while device telemetry
+ data collection was in progress. This resulted in an OOM condition.
+
+ |
+
|
+ PAN-281721
+ |
+
+
+ Fixed an issue where the firewall generated high-severity system
+ alerts indicating that the configuration size exceeded the maximum
+ recommended size, even when the configuration size was within the
+ expected limits.
+
+ |
+
|
+ PAN-277178
+ |
+
+
+ Fixed an issue on Panorama where you were unable to delete a shared
+ object due to the rulebase incorrectly referencing the shared object
+ instead of the device group-specific object when the name was used.
+
+
+ To use this fix, delete the original shared object after cloning it to
+ a device group with the same name.
+
+ |
+
|
+ PAN-272245
+ |
+
+
+ Fixed an issue where the dnsproxy process crashed due to memory
+ corruption caused by a race condition when allow list downloading was
+ impacted by config change.
+
+ |
+