From 71f86eed347fa6233a3e79334900daf24b4c44ce Mon Sep 17 00:00:00 2001 From: Aaron Axvig Date: Mon, 13 Apr 2026 14:56:21 -0500 Subject: [PATCH] Revise PAN-OS 11.2 addressed issues --- reference/PAN-OS/addressed/11.2.0-h1.html | 61 + reference/PAN-OS/addressed/11.2.0.html | 389 + reference/PAN-OS/addressed/11.2.1-h1.html | 61 + reference/PAN-OS/addressed/11.2.1.html | 146 + reference/PAN-OS/addressed/11.2.10-h1.html | 96 + reference/PAN-OS/addressed/11.2.10-h2.html | 339 + reference/PAN-OS/addressed/11.2.10-h3.html | 160 + reference/PAN-OS/addressed/11.2.10-h4.html | 224 + reference/PAN-OS/addressed/11.2.10-h5.html | 549 ++ reference/PAN-OS/addressed/11.2.10.html | 1130 +++ reference/PAN-OS/addressed/11.2.11.html | 6655 +++++++++++++++++ reference/PAN-OS/addressed/11.2.2-h1.html | 31 + reference/PAN-OS/addressed/11.2.2-h2.html | 61 + reference/PAN-OS/addressed/11.2.2.html | 96 + reference/PAN-OS/addressed/11.2.3-h3.html | 87 + reference/PAN-OS/addressed/11.2.3-h5.html | 95 + reference/PAN-OS/addressed/11.2.3.html | 1816 +++++ reference/PAN-OS/addressed/11.2.4-h1.html | 61 + reference/PAN-OS/addressed/11.2.4-h10.html | 732 ++ reference/PAN-OS/addressed/11.2.4-h11.html | 196 + reference/PAN-OS/addressed/11.2.4-h12.html | 458 ++ reference/PAN-OS/addressed/11.2.4-h14.html | 503 ++ reference/PAN-OS/addressed/11.2.4-h15.html | 37 + reference/PAN-OS/addressed/11.2.4-h2.html | 69 + reference/PAN-OS/addressed/11.2.4-h4.html | 350 + reference/PAN-OS/addressed/11.2.4-h5.html | 103 + reference/PAN-OS/addressed/11.2.4-h6.html | 559 ++ reference/PAN-OS/addressed/11.2.4-h7.html | 112 + reference/PAN-OS/addressed/11.2.4-h8.html | 44 + reference/PAN-OS/addressed/11.2.4-h9.html | 577 ++ reference/PAN-OS/addressed/11.2.4.html | 544 ++ reference/PAN-OS/addressed/11.2.5-h2.html | 32 + reference/PAN-OS/addressed/11.2.5.html | 2761 +++++++ reference/PAN-OS/addressed/11.2.6.html | 1143 +++ reference/PAN-OS/addressed/11.2.7-h1.html | 349 + reference/PAN-OS/addressed/11.2.7-h10.html | 300 + reference/PAN-OS/addressed/11.2.7-h11.html | 233 + reference/PAN-OS/addressed/11.2.7-h12.html | 525 ++ reference/PAN-OS/addressed/11.2.7-h2.html | 135 + reference/PAN-OS/addressed/11.2.7-h3.html | 349 + reference/PAN-OS/addressed/11.2.7-h4.html | 708 ++ reference/PAN-OS/addressed/11.2.7-h7.html | 96 + reference/PAN-OS/addressed/11.2.7-h8.html | 578 ++ reference/PAN-OS/addressed/11.2.7.html | 2129 ++++++ reference/PAN-OS/addressed/11.2.8.html | 5860 +++++++++++++++ reference/PAN-OS/addressed/11.2.9.html | 280 + web/data/issues/PAN-OS/addressed/11.2.0-h1.md | 2 +- web/data/issues/PAN-OS/addressed/11.2.0.md | 4 +- web/data/issues/PAN-OS/addressed/11.2.1-h1.md | 2 +- web/data/issues/PAN-OS/addressed/11.2.1.md | 4 +- .../issues/PAN-OS/addressed/11.2.10-h2.md | 6 +- .../issues/PAN-OS/addressed/11.2.10-h3.md | 2 +- .../issues/PAN-OS/addressed/11.2.10-h4.md | 8 +- web/data/issues/PAN-OS/addressed/11.2.10.md | 21 +- web/data/issues/PAN-OS/addressed/11.2.11.md | 4 +- web/data/issues/PAN-OS/addressed/11.2.2-h2.md | 2 +- web/data/issues/PAN-OS/addressed/11.2.2.md | 2 +- web/data/issues/PAN-OS/addressed/11.2.3-h3.md | 2 +- web/data/issues/PAN-OS/addressed/11.2.3-h5.md | 4 +- web/data/issues/PAN-OS/addressed/11.2.3.md | 30 +- web/data/issues/PAN-OS/addressed/11.2.4-h1.md | 2 +- .../issues/PAN-OS/addressed/11.2.4-h10.md | 6 +- .../issues/PAN-OS/addressed/11.2.4-h11.md | 8 +- .../issues/PAN-OS/addressed/11.2.4-h12.md | 4 +- .../issues/PAN-OS/addressed/11.2.4-h14.md | 6 +- .../issues/PAN-OS/addressed/11.2.4-h15.md | 4 +- web/data/issues/PAN-OS/addressed/11.2.4-h2.md | 2 +- web/data/issues/PAN-OS/addressed/11.2.4-h4.md | 8 +- web/data/issues/PAN-OS/addressed/11.2.4-h5.md | 2 +- web/data/issues/PAN-OS/addressed/11.2.4-h6.md | 8 +- web/data/issues/PAN-OS/addressed/11.2.4-h7.md | 2 +- web/data/issues/PAN-OS/addressed/11.2.4-h9.md | 10 +- web/data/issues/PAN-OS/addressed/11.2.4.md | 6 +- web/data/issues/PAN-OS/addressed/11.2.5.md | 54 +- web/data/issues/PAN-OS/addressed/11.2.6.md | 20 +- web/data/issues/PAN-OS/addressed/11.2.7-h1.md | 8 +- .../issues/PAN-OS/addressed/11.2.7-h10.md | 9 +- .../issues/PAN-OS/addressed/11.2.7-h11.md | 4 +- web/data/issues/PAN-OS/addressed/11.2.7-h2.md | 4 +- web/data/issues/PAN-OS/addressed/11.2.7-h3.md | 4 +- web/data/issues/PAN-OS/addressed/11.2.7-h4.md | 6 +- web/data/issues/PAN-OS/addressed/11.2.7-h8.md | 10 +- web/data/issues/PAN-OS/addressed/11.2.7.md | 32 +- web/data/issues/PAN-OS/addressed/11.2.8.md | 162 +- 84 files changed, 32057 insertions(+), 236 deletions(-) create mode 100644 reference/PAN-OS/addressed/11.2.0-h1.html create mode 100644 reference/PAN-OS/addressed/11.2.0.html create mode 100644 reference/PAN-OS/addressed/11.2.1-h1.html create mode 100644 reference/PAN-OS/addressed/11.2.1.html create mode 100644 reference/PAN-OS/addressed/11.2.10-h1.html create mode 100644 reference/PAN-OS/addressed/11.2.10-h2.html create mode 100644 reference/PAN-OS/addressed/11.2.10-h3.html create mode 100644 reference/PAN-OS/addressed/11.2.10-h4.html create mode 100644 reference/PAN-OS/addressed/11.2.10-h5.html create mode 100644 reference/PAN-OS/addressed/11.2.10.html create mode 100644 reference/PAN-OS/addressed/11.2.11.html create mode 100644 reference/PAN-OS/addressed/11.2.2-h1.html create mode 100644 reference/PAN-OS/addressed/11.2.2-h2.html create mode 100644 reference/PAN-OS/addressed/11.2.2.html create mode 100644 reference/PAN-OS/addressed/11.2.3-h3.html create mode 100644 reference/PAN-OS/addressed/11.2.3-h5.html create mode 100644 reference/PAN-OS/addressed/11.2.3.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h1.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h10.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h11.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h12.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h14.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h15.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h2.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h4.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h5.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h6.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h7.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h8.html create mode 100644 reference/PAN-OS/addressed/11.2.4-h9.html create mode 100644 reference/PAN-OS/addressed/11.2.4.html create mode 100644 reference/PAN-OS/addressed/11.2.5-h2.html create mode 100644 reference/PAN-OS/addressed/11.2.5.html create mode 100644 reference/PAN-OS/addressed/11.2.6.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h1.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h10.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h11.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h12.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h2.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h3.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h4.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h7.html create mode 100644 reference/PAN-OS/addressed/11.2.7-h8.html create mode 100644 reference/PAN-OS/addressed/11.2.7.html create mode 100644 reference/PAN-OS/addressed/11.2.8.html create mode 100644 reference/PAN-OS/addressed/11.2.9.html diff --git a/reference/PAN-OS/addressed/11.2.0-h1.html b/reference/PAN-OS/addressed/11.2.0-h1.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.0-h1.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.2.0.html b/reference/PAN-OS/addressed/11.2.0.html new file mode 100644 index 0000000..8b15b85 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.0.html @@ -0,0 +1,389 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PLUG-16383
+
+
+ (VM-Series firewalls only) Fixed an issue where + the PAN_NET_FILE_TMP was not + found after an upgrade, which caused the firewall to enter maintenance + mode. +
+
+
PAN-240174
+
+
+ Fixed an issue where, when LSVPN serial numbers and IP address + authentication were enabled, IPv6 address ranges and complete IPv6 + addresses that were manually added to the IP address allow or exclude + list were not usable after a restart of the + gp_broker + process or the firewall. +
+
+
PAN-230362
+
+
+ Fixed an issue where the firewall truncated the payload of a TCP Out + of Order segment with a FIN flag. +
+
+
PAN-228386
+
+
+ Fixed an issue with session caching where the + reportd + process stopped responding due to null values. +
+
+
PAN-227344
+
+
+ Fixed an issue on Panorama where + PDF Summary Reports (Monitor > PDF Reports > Manage PDF Summary) displayed no data and were blank when predefined widgets were + included in the summary report. +
+
+
PAN-227305
+
+
+ Fixed an issue where SCEP certificate generation failed when a service + route was used to reach the SCEP server. +
+
+
PAN-227224
+
+
+ (PA-1400 Series firewalls) Fixed an issue where + the firewall was unable to handle GRE packets for Point-to-Point + Tunneling Protocol (PPTP) connections. +
+
+
PAN-226626
+
+
+ Fixed an issue where the firewall generated numerous + logrcvr + error messages related to netflow. +
+
+
PAN-225394
+
+
+ Fixed an issue on the firewall where SNMP incorrectly reported high + packet descriptor usage. +
+
+
PAN-225240
+
+
+ Fixed an issue where the OSPF neighbor state remained in + exstart when the OSPF network had + more than 40 routes. +
+
+
PAN-225183
+
+
+ Fixed an issue where SSH tunnels were unstable due to ciphers used as + part of the high availability SSH configuration. +
+
+
PAN-224772
+
+
+ Fixed a high memory usage issue with the + mongodb + process that caused an OOM condition. +
+
+
PAN-224365
+
+
+ Fixed an issue where excessive network path monitoring messages were + generated in the system logs. +
+
+
PAN-224067
+
+
+ Fixed an issue where cookie authentication did not work for + GlobalProtect when an authentication override domain was configured in + the SAML authentication profile. +
+
+
PAN-223501
+
+
+ Fixed an issue where diagnostic information for the dataplane in the + dp-monitor.log file was not complete. +
+
+
PAN-223365
+
+
+ Fixed an issue where Panorama was unbale to query any logs if the + Elasticsearch health status for any log collector was degraded. +
+
+
PAN-220881
+
+
+ Fixed an issue where the CLI command + show logging-status did not + correctly display the last log created and forwarded timestamps. +
+
+
PAN-220640
+
+
+ (PA-220 firewalls only) Fixed an issue where + the firewall CPU percentage was miscalculated, and the values that + were displayed were incorrect. +
+
+
PAN-219768
+
+
+ Fixed an issue where you were unable to filter Data Filtering logs + with Threat ID/NAME for custom data + patterns created over Panorama. +
+
+
PAN-219585
+
+
+ Fixed an issue where enabling + syslog-ng debugs from the root + caused 100% disk utilization. +
+
+
PAN-217510
+
+
+ Fixed an issue where inbound DHCP packets received by a DHCP client + interface that were not addressed to itself were silently dropped + instead of forwarded. +
+
+
PAN-208567
+
+
+ Fixed an issue with email formatting where, when a scheduled email + contained two or more attachments, only one attachment was visible. +
+
+
PAN-207003
+
+
+ Fixed an issue where the + logrcvr + process netflow buffer was not reset which resulted in duplicate + netflow records. +
+
+
PAN-202095
+
+
+ Fixed an issue on the web interface where the language setting is not + retained. +
+
+
PLUG-16385
+
+
+ Fixed an issue where the file + PAN_NET_FILE_TMP was missing after the + upgrade causing the VM-Series firewall to go into maintenance mode. +
+
diff --git a/reference/PAN-OS/addressed/11.2.1-h1.html b/reference/PAN-OS/addressed/11.2.1-h1.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.1-h1.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.2.1.html b/reference/PAN-OS/addressed/11.2.1.html new file mode 100644 index 0000000..ac5ade8 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.1.html @@ -0,0 +1,146 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-257919
+
+
+ Fixed an issue where, when using explicit proxy with SAML + authentication, initiating SAML authentication with a non-GET request + resulted in a 302 redirect response + instead of the expected + 200 ok response. +
+
+
PAN-256343
+
+
+ Fixed an issue where, when Advanced Routing Engine was enabled and + OSPFv3 was configured, the CLI command + show advanced-routing ospf interface + caused traffic to be disrupted, and the interface and area information + did not display in CLI or the web interface. +
+
+
PAN-255868
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall entered maintenance mode after enabling kernel data + collection during the silent reboot. +
+
+
PAN-252661
+
+
+ Fixed an issue where changes to the gp-ip-mgmt service route did not + take effect after a commit. +
+
+
PAN-255227
+
+
+ Fixed an issue where the the MAC address was sent to the DHCP server + instead of the hostname on macOS endpoints. +
+
+
PAN-254236
+
+
+ Fixed an issue where Client Hello packets were dropped when SSL/TLS + handshake inspection was enabled. +
+
+
PAN-249292
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where CPU usage was higher than expected after a + hotplug event when Accelerated Networking was enabled for the + management interface. +
+
+
PAN-236909
+
+
+ Fixed an issue where, when you committed the first configuration + change after booting up the firewall, the external dynamic list file + download failed until the list was refreshed. This occurred when the + configuration was pushed with a certificate profile. +
+
+
PAN-164885
+
+
+ Fixed an issue on Panorama where + Commit and Push or + Push to Devices operations failed + when an external dynamic list was configured to check for updates + every 5 minutes due to the commit and external dynamic fetch processes + overlapping. +
+
diff --git a/reference/PAN-OS/addressed/11.2.10-h1.html b/reference/PAN-OS/addressed/11.2.10-h1.html new file mode 100644 index 0000000..92201e5 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.10-h1.html @@ -0,0 +1,96 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-306534
+
+
+ Fixed an issue were the + all_task + process repeatedly restarted due to memory pool corruption when + processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred + due to incorrect buffer length calculations during memory deallocation + when the query name field spanned multiple packets. +
+
+
PAN-305480
+
+
+ Fixed an issue where the + pan_task + process stopped responding while processing DoH JSON format traffic + with DoH Security enabled, which caused missing cross-packet bytes in + the decoded DNS query type field, and the dataplane went down. +
+
+
PAN-305301
+
+
+ Fixed an issue where GlobalProtect notifications in tunnels caused + processes to stop responding and the dataplane to restart due to the + session lookup returning an incorrect session, which resulted in the + data being sent through the wrong tunnel. +
+
+
PAN-303836
+
+
+ Fixed an issue where the AIRS VM on session table reset intermittently + dropped packets, which resulted in packet loss on responses to egress + traffic. +
+
diff --git a/reference/PAN-OS/addressed/11.2.10-h2.html b/reference/PAN-OS/addressed/11.2.10-h2.html new file mode 100644 index 0000000..5ab6f57 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.10-h2.html @@ -0,0 +1,339 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-306306
+
+
+ (Panorama appliances in FIPS-CC mode only) + Fixed interdevice TLS communication failures that occurred with RSA + and RSA-PSS signature algorithms across multiple layer 7 application + services. +
+
+
PAN-303051
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the + reportd + process due to retaining memory that was temporarily used for report + generation instead of releasing the memory for reuse, which resulted + in continuous accumulation and memory exhaustion. +
+
+
PAN-302927
+
+
+ Fixed an issue where, after upgrading Panorama, the + Push to Devices option did not + display selected devices, and the + OK and + Cancel + buttons did not function as expected. Selecting + OK did not close the window, and + selecting Cancel returned to the + main push screen with the push selected devices displaying as empty. + Despite this, selecting Push or + Validate Device Group Push still + pushed to the previously canceled, non-displayed devices. +
+
+
PAN-301801
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process + fluctuated intermittently between green and red states, which led to + interruptions in log collection. This issue occurred when the number + of shards exceeded the cluster's maximum supported threshold of + greater than 1000 shards per Elasticsearch instance. +
+
+
PAN-301691
+
+
+ Fixed an issue where BGP stopped responding with the error message + Too many open files when pushing + 1000 eBGP (External BGP) neighbor configurations. With this fix, the + number of file descriptors for the BGP process is increased from 1024 + to 8192. +
+
+
PAN-301456
+
+
+ Fixed an issue on Panorama where the + debug system reset-ztp CLI + command was unavailable. +
+
+
PAN-300216
+
+
+ Fixed an issue where, when SD-WAN Direct Internet Access was + configured and traffic traversed the cellular interface without a NAT + policy rule, intermittent cellular modem connectivity issues occurred, + which caused the firewall to disconnect and reconnect to the cellular + network. +
+
+ To use this fix, run the CLI command + set session teardown-upon-fwd-zonechange yes. +
+
+
PAN-300138
+
+
+ Fixed an issue where DNS queries stalled or repeatedly time out due to + multiple DNS responses with different CNAME values causing evasion + false positive alerts. +
+
+
PAN-299815
+
+
+ Fixed an issue on multi-vsys firewalls where a host was not removed + from the quarantine list after receiving a redistribution message from + Panorama. This occurred when Panorama was configured to redistribute + quarantine messages to a firewall cluster, and the GlobalProtect + configuration and redistribution were built out in a vsys other than + vsys1. +
+
+
PAN-298387
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP + addresses did not display in traffic and threat logs. +
+
+
PAN-297610
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade + due to the + fsck + command scanning drive partitions in parallel with the root partition, + which caused the process to take an extended amount of time. +
+
+
PAN-297005
+
+
+ Fixed an issue where exporting custom reports resulted in empty CSV + files. +
+
+
PAN-296977
+
+
+ Fixed an issue where the web interface became unresponsive when + attempting to view + Ethernet interface details after + applying a filter in + NetworkInterfaces +
+
+
PAN-296694
+
+
+ Fixed an issue where the firewall rebooted due to the + useridd + process repeatedly restarting during an IP-port data type writes to + the redis from multiple sources such as TSA or XML in a scale + environment. +
+
+
PAN-296535
+
+
+ Fixed an issue on the firewall where BGP peers disconnected when more + than 500 BGP neighbors were configured in a single Logical Router +
+
+
PAN-295899
+
+
+ Fixed an issue where DNS resolution failed on Linux machines running + GlobalProtect client version 6.2.6 when connected with DNS Security + enabled. This occurred because the firewall incorrectly discarded DNS + packets when processing multiple DNS requests or responses over the + same session, even when no malicious verdict was received. +
+
+
PAN-276525
+
+
+ Resolved multiple issues affecting IPSec tunnels using NAT Traversal + (NAT-T) when a Dynamic NAT policy was configured (including Dynamic + NAT or DIPP). During rekey events, tunnels could go down or flap due + to incorrect session handling. This issue impacted both cluster and + standalone deployments. +
+
+
PAN-209516
+
+
+ Fixed an issue where, when creating an interface, an error occurred + when you clicked OK without + providing a value in the Tag field + even though the field was not displayed as mandatory. +
+
+
PAN-185731
+
+
+ Fixed an issue where the firewall was unable to parse the URL path and + host when the host header was located in a different packet, which + resulted in the firewall not logging the URL path in the first packet. +
+
+ The fix is disabled by default. The following CLI commands can be used + to enable/disable the feature: set system setting ctd + url-crosspkt-host-path-caching enable set system setting ctd + url-crosspkt-host-path-caching disable set system setting ctd + url-crosspkt-host-path-caching default +
+
diff --git a/reference/PAN-OS/addressed/11.2.10-h3.html b/reference/PAN-OS/addressed/11.2.10-h3.html new file mode 100644 index 0000000..bbfa8d5 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.10-h3.html @@ -0,0 +1,160 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-307901
+
+
+ Fixed an issue where a leak in decryption counters caused resource + exhaustion, which led to a GlobalProtect service outage. +
+
+
PAN-307702
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where traffic passing through AE layer 2 interfaces was + interrupted during HA failovers. +
+
+
PAN-306451
+
+
+ (VM-Series firewalls on AWS environments only) + Fixed an issue where, after upgrading the firewall to an affected + release, GlobalProtect clients did not connect with IPSec and instead + connected using SSL due to traffic flow being disabled when checking + for health check packets. +
+
+
PAN-306103
+
+
+ (PA-3400 and PA-5400 Series firewalls only) + Fixed an issue where the firewall dataplane frequently restarted when + lockless QoS was enabled +
+
+
PAN-303959
+
+
+ Fixed an issue where traffic was incorrectly identified as + unknown-tcp/unknown-udp due to App-ID resource leak and eventually + dropped. +
+
+
PAN-301409
+
+
+ Fixed an issue where Panorama failed to perform a selective push to a + managed device when device tags were added or modified on the policy + rules. The selective push failed with the error message + Failed to generate selective push configuration. Schema validation + failed. Please try a full push. +
+
+
PAN-301222
+
+
+ Fixed an issue where DNS Security logs incorrectly displayed a + sinkhole action for benign DNS categories due to the firewall saving + the drop or sinkhole action in session flags without discarding the + session. +
+
+
PAN-300638
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall stopped responding due to an out-of-bounds read when + parsing TLS 1.3 clientHello messages with large TLS clientHello + extensions where the + supported_versions extension fell + outside the first TCP segment. +
+
+
PAN-295803
+
+
+ Addressed a memory leak issue under sc3 and automatic commit recovery + (ACR) code path. +
+
+
PAN-289723
+
+
+ Fixed an issue where the firewall web interface continuously loaded + and not display any output when viewing the Route Table or FIB table + (More Runtime Stats). This issue + occurred when L3 configurations were added to ethernet and AE + interfaces. +
+
diff --git a/reference/PAN-OS/addressed/11.2.10-h4.html b/reference/PAN-OS/addressed/11.2.10-h4.html new file mode 100644 index 0000000..81dadd5 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.10-h4.html @@ -0,0 +1,224 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308902
+
+
+ Fixed an issue where, after upgrading to an affected release, the + firewall did not add mTLS websites that required client certificate + authentication via DN list to the ssl-decrypt exclude-cache list. +
+
+
PAN-308654
+
+
+ Fixed an issue where the Elasticsearch Close Indices process closed + more indices than expected and dropped the number of open shards below + the minimum of 800 per Elasticsearch instance. This occurred because + the process did not correctly account for the number of Elasticsearch + instances when calculating the maximum number of allowed open shards. +
+
+
PAN-304718
+
+
+ Fixed an issue where OSPF and BGP outages occurred due to an + all_task + process restart during clientless VPN content rewrite processing. +
+
+
PAN-304576
+
+
+ Fixed an issue where the firewall entered a non-functional state due + to segmentation fault within the + all_pktproc + process that was caused by a session that involved http2 cleartext + traffic +
+
+
PAN-304496
+
+
+ Fixed an issue where, after unregistering an IP tag and registering a + different IP tag for the same IP address via XML API, the dynamic + address group membership was not updated on the dataplane, which + resulted in Security policy rules being enforced incorrectly. +
+
+
PAN-303722
+
+
+ Fixed an issue on the firewall where configuring spyware and + vulnerability profiles in Security policy rules caused a memory leak + in the + devsrvr + process with each configuration commit. +
+
+
PAN-302790
+
+
+ Fixed an issue where, with Sender Side Loop Detection enabled, BGP + WITHDRAWAL updates were not sent to peers after a route was removed, + which caused stale routes to persist in the BGP table of neighboring + firewalls. +
+
+
PAN-288001
+
+
+ Fixed an issue where devices with 5G cellular modems did not support + the ATT FirstNet auto Access Point Name (APN). +
+
+
PAN-285181
+
+
+ Fixed an issue where the wifclient ran out of memory when Enhanced + Application Logging was enabled and a sudden traffic increase caused a + surge in EAL messages sent through WIF. +
+
+ To use this fix, run the CLI command + debug iot eal memory-gc native +
+
+
PAN-278688
+
+
+ Fixed an issue where DNS Security threat logs were not displayed on + the firewall when packet capture was enabled and the domain name + length was 62 characters. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where an incorrect ASIC configuration caused silent packet drops or + application slowness when receiving a mix of jumbo and non-jumbo + packets. +
+
+
PAN-269228
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused a split brain condition. +
+
diff --git a/reference/PAN-OS/addressed/11.2.10-h5.html b/reference/PAN-OS/addressed/11.2.10-h5.html new file mode 100644 index 0000000..e61bfb7 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.10-h5.html @@ -0,0 +1,549 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-318275
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall became unresponsive and did not automatically reboot, + which led to prolonged outages. With this fix, the Linux kernel + configuration will trigger a system panic and reboot. +
+
+
PAN-316911
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where a newly bootstrapped firewall required a + management server restart, relicensing, or license push from Panorama + to invoke the device certificate. +
+
+
PAN-315912
+
+
+ Fixed an issue where the Maximum Segment Size (MSS) rewrite + functionality for packets ingressing through SD-WAN interfaces on + firewalls was not optimized. +
+
+
PAN-314147
+
+
+ Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces + with member having different MTU. +
+
+
PAN-313623
+
+
+ Fixed an issue where the + /opt/pancfg/mgmt/ssl/private/ + directory on Palo Alto Networks devices with TPM support became 100% + utilized due to an accumulation of undeleted + .pub_pem files. This occurred + because executing the + show device-certificate status + CLI command initiated a process that generated these files but failed + to remove them, which prevented the fetching of new device + certificates. +
+
+
PAN-313216
+
+
+ Fixed an issue where firewalls with Prisma Access incorrectly + displayed some traffic as unsanctioned in traffic logs for cloud + applications that were tagged as + sanctioned. +
+
+
PAN-312706
+
+
+ Fixed an issue where the firewalls restarted due to a function lacking + a NULL-pointer sanity check. +
+
+
PAN-311512
+
+
+ Fixed an issue where HIP (Host Information Profile) reports were + blocked on GlobalProtect when + Authentication Cookie Usage Restrictions + was enabled and the Prisma Access Agent protocol was in use. This + occurred because the system failed to correctly process HIP messages + that were relayed via IPSec tunnels with a Virtual IP as the source, + leading to their rejection. +
+
+
PAN-309300
+
+
+ Fixed an issue where management plane system resources configuration + size exceeded 28 MB for over 4 hours, and the following error message + was displayed: + Configuration size reaching device capacity limit. +
+
+
PAN-308786
+
+
+ (Panorama appliances only) Fixed an issue where + traffic log queries using the + device_name filter returned no + results, and complex log queries that included negation operators + produced incorrect outputs. +
+
+
PAN-308564
+
+
+ Fixed an issue where packets were dropped on SD-WAN interfaces when a + proxy was enabled due to an MTU inconsistency where the firewall + failed to rewrite the maximum segment size in SYN/ACK packets based on + the SD-WAN virtual interface MTU. +
+
+ Note: This fix does not apply when the traffic + egress interface is SD-WAN Direct Internet Access (DIA) interface + and proxy is enabled. +
+
+
PAN-308507
+
+
+ (Panorama managed firewalls only) Fixed an + issue where the firewall intermittently failed to maintain active log + forwarding streams to Strata Logging Service (SLS) even when duplicate + logging and enhanced application logging were enabled. +
+
+
PAN-308418
+
+
+ Fixed an issue where, when Advanced DNS Security was enabled and + experienced unusually high loads, DNS resolution failures occurred + with the error + resources-unavailable. +
+
+
PAN-306555
+
+
+ Fixed an issue where the firewall stopped responding, which led to + service outages. +
+
+
PAN-304019
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall did not send traffic to SCM or SLS via a configured + explicit proxy IP address when the proxy username was not configured. +
+
+
PAN-303745
+
+
+ Fixed an issue where inter-dataplane forwarding did not work for + sessions ingressing on Slot 2, which resulted in intermittent ping + failures to interfaces on Network Card 2 when traffic was forwarded to + Slot 3. +
+
+ Note: With this fix, after a slot restart, the + global counter will still show dot1q errors for a short period. +
+
+
PAN-302564
+
+
+ Fixed an issue on the firewall where a path monitoring failure + occurred and caused the dataplane to restart. +
+
+
PAN-301653
+
+
+ Fixed an issue where DNS traffic sessions prematurely terminated with + the message + resources-unavailable. This occurred due to IPv4 fragmented DNS responses causing the + Advanced DNS Security module to incorrectly pack the DNS payload + multiple times when forwarding to the cloud for inspection. +
+
+
PAN-302983
+
+
+ Fixed an issue where, after committing changes on Panorama, a shared + post-rule moved to the end of the + post shared rulebase on the + managed device instead of remaining at the top. +
+
+
PAN-300837
+
+
+ Fixed an issue where firewalls experienced multiple reboots due to the + pan_task + process restarting with a SIGSEGV signal. This occurred because the + client-to-firewall side assumed TLS 1.3 for the firewall-server side. +
+
+
PAN-300671
+
+
+ Fixed an issue where traffic reports that were generated with + destination/source and destination/source hostnames were not displayed + in IPv4 format. +
+
+
PAN-300423
+
+
+ Fixed an issue where Data Processing Cards (DPCs) installed in slots 5 + and 6 remained stuck in a starting state with the error + Signal detected for port xeS5-DP0 but Link Down + alerts, which resulted in device instability. +
+
+
PAN-299242
+
+
+ Fixed an issue where the firewall's SSL proxy sent an empty HTTP2 + SETTINGS message to the client before confirming server support, which + caused some clients to incorrectly assume HTTP/2 support and not fall + back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad + Request frames from the server, which prevented the client from + correctly detecting the lack of HTTP/2 support. +
+
+
PAN-298617
+
+
+ Optimized the commit workflow to reduce the size of the effective + configuration, resulting in lower memory consumption. +
+
+
PAN-297708
+
+
+ Fixed an issue where a long-lived session with many Machine Learning + (ML) model triggers caused a memory leak of feature states associated + with the ML model runs. This resulted in Spyware_State failure + increases, allocation max outs, and impaired policy matching. +
+
+
PAN-295802
+
+
+ Fixed an issue where a memory leak related to the + configd + process occurred. +
+
+
PAN-295309
+
+
+ Fixed an issue where OSPF session using MD5 authentication experienced + intermittent flapping due to out-of-order packet processing. +
+
+
PAN-293644
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the + configd + process stopped responding during an External Dynamic List (EDL) + refresh. +
+
+
PAN-290938
+
+
+ Fixed an issue where multiple memory leaks occurred related to the + configd + process. +
+
+
PAN-264762
+
+
+ Fixed an issue where the firewall showed the status of SFP+ interfaces + as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was + connected. +
+
+
PAN-263691
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a + memory leak in the + all_task + process. +
+
+
PAN-250339
+
+
+ Added an improvement to automatically clean up idle HTTP connection + pools to address an issue where idle connection pools accumulated when + a circuit breaker limit was reached, which caused client requests to + fail with a 503 + no_healthy_upstream error. +
+
+
PAN-248913
+
+
+ Fixed an issue where the Elasticsearch client certificate was not auto + renewed, which caused it to enter a Red state, and logs were not + displayed in Panorama. +
+
diff --git a/reference/PAN-OS/addressed/11.2.10.html b/reference/PAN-OS/addressed/11.2.10.html new file mode 100644 index 0000000..d23d1e2 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.10.html @@ -0,0 +1,1130 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304088
+
+
+ Fixed an issue where TCP traffic stopped working from Prisma Access + clients to TCP services behind the Service Connection (SC) after a + dataplane upgrade. +
+
+
PAN-304075
+
+
+ Fixed an issue where the firewall did not detect evasions due to TCP + checksum offloading not being enabled. +
+
+
PAN-303737
+
+
+ Fixed an issue where XML API commands failed with a + Method not found (policy_xml) + error in dagger.log. The issue was due to session-distribution + commands in dagger files handling. +
+
+
PAN-303559
+
+
+ Fixed an issue where, after manuallly creating a device telemetry + bundle, the + hour_cli_output.txt file within + the bundle had a file size of 0 bytes. This occurred when checking the + bundle content after enabling device telemetry and setting the device + telemetry upload endpoint. +
+
+
PAN-301828
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud + Manager and configured to use a proxy server for external connections, + the management server did not use the configured settings to connect + to the Cloud Management service. +
+
+
PAN-300906
+
+
+ Fixed an issue where XML API commands failed with a + Method not found (policy_xml) + error in dagger.log. The issue was due to missing XML-related + functions for inline-cloud-proxy. +
+
+
PAN-300096
+
+
+ Fixed an issue where a local commit on a firewall breaks template + stack overrides, preventing the enabling of LACP (Link Aggregation + Control Protocol). After a local commit, the LACP enable check was + unexpectedly unchecked, causing an outage. Attempting to re-enable + LACP through the web interface was unsuccessful, requiring manual + removal of the LACP configuration from the Panorama CLI. +
+
+
PAN-299785
+
+
+ (PA-7500 and PA-5450 firewalls in FIPS-CC mode) + Fixed an issue where the affected firewalls would boot into + maintenance mode when a reboot was initiated from the web interface. + This was due to a device reboot triggering a power down to all slots, + leading to maintenance mode. A hard reboot would allow the firewall to + boot normally. +
+
+
PAN-299772
+
+
+ (VM-Series firewalls in active/passive configurations only) Fixed an issue where, after an HA failover event, the newly active + firewall DHCP client interfaces failed to obtain IP addresses + automatically. This occurred because the DHCP client processes did not + initiate the necessary DHCP discover or renew requests +
+
+
PAN-298872
+
+
+ (PA-400 Series firewalls in HA configurations only) Fixed an issue where ports went down after an HA failover. +
+
+
PAN-298684
+
+
+ Fixed an issue where an Application Override policy rule was not + applied using an IPv4 source IP address with IPv6 enabled and + Network > + Zones > + Pre-NAT Identification enabled. +
+
+
PAN-298654
+
+
+ Fixed an issue where the firewall generated false positive threat logs + during updates to a large domain list (EDL) when a DNS lookup for a + domain being added or removed occurred during the update process. This + resulted in a threat log being generated for a different, unrelated + domain that remained on the list. +
+
+
PAN-298505
+
+
+ Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, + the vsys ID changed in sequence, causing autocommit failures with + validation errors. This occurred when the multi-vsys firewall had + virtual systems created and pushed from Panorama, and the vsys ID was + not in a correct sequence because the unused vsys was deleted from + Panorama and pushed to devices. +
+
+
PAN-298252
+
+
+ Fixed an issue where Data Loss Prevention (DLP) inspection of chunked + transfer encoding over TLS resulted in incomplete file downloads on + Outlook Web App (OWA) due to the WIF page size limit, which led to + corrupted or incomplete PDF attachments. +
+
+
PAN-298241
+
+
+ Fixed an issue where the NAT IP address pool was exhausted, which led + to intermittent connectivity issues with call applications and + outbound call failures. This occurred due to the firewall not properly + releasing NAT dynamic ports back to the address pool. +
+
+
PAN-297976
+
+
+ Fixed an issue where the firewall experienced extended boot times + after a reboot due to the + configd + process needing to rebuild the ACE catalog after detecting + discrepancies that were caused by duplicate application checking + between the ACE catalog and content. +
+
+
PAN-297975
+
+
+ Fixed an issue where Panorama was unable to push the Trusted Root CA + configuration to Log Collectors via a Collector Group push due to the + Log Collector not supporting the + trusted-root-CA configuration. +
+
+
PAN-297797
+
+
+ Fixed an issue where, during a refresh of a large External Dynamic + List (EDL), traffic that matched a domain on the list was incorrectly + identified as a different domain, which resulted in false positive + threat logs. +
+
+
PAN-297775
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release, + the Visible Virtual System field referenced the vsys name instead of + the vsys ID, which caused inter-vsys routing to fail. This occurred + when a vsys display name matched one of the vsys IDs. If you're using + a multivsys environment, you must upgrade your firewalls to a fixed + PAN-OS version. The best practice is to upgrade both the firewalls and + Panorama to a fixed PAN-OS version. +
+
    +
  • + If you don't upgrade Panorama to a fixed version, you'll encounter + PAN-245064, where a commit on a multivsys firewall fails with the + message "vsys name should end with a number vsys is invalid" after + you "Export or push device config bundle" from 11.1.1 Panorama. +
  • +
  • + After you upgrade Panorama to a fixed version, you'll encounter + PAN-214177, which causes an "Export or Push device config bundle" + from Panorama to the firewall to fail. The workaround for PAN-214177 + is to first push only the template configuration and then push the + device group configurations. +
  • +
+
+
PAN-297321
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where return packets from a phone gateway looped + between the HA pair instead of being encapsulated into the + GlobalProtect tunnel. This occurred when the inner session and the + outer IPSec tunnel terminated on different nodes, which led to + excessive retries and packet drops. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high + packet rates on the synthetic path in DPDK mode. +
+
+
PAN-296752
+
+
+ Fixed an issue where the firewall experienced high management CPU + usage and repeatedly rebooted when attempting to retrieve SMART data. +
+
+
PAN-296490
+
+
+ (Firewalls with FIPS-CC mode enabled only) + Fixed an issue where Panorama on GCP rebooted every hour after + upgrading. +
+
+
PAN-296453
+
+
+ Fixed an issue where decryption exclusion lists were not working for + untrusted certificates, and SSL sessions were still being decrypted + even after adding them to the exclusion list. This occurred because + the firewall was not adding sessions to the exclude cache until after + receiving a non-RFC alert (BadCertificate) from the server. The fix + ensures that the first session is added to the exclude cache, allowing + subsequent sessions to skip decryption. This issue affects firewalls + configured as clients in server-client communication. +
+
+
PAN-295644
+
+
+ Fixed an issue where Strata Logging Service (SLS) log forwarding + streams intermittently displayed as inactive. +
+
+
PAN-295560
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors, + tunnel logs were not visible in Panorama or Splunk even though traffic + and threat logs were received. +
+
+
PAN-295385
+
+
+ Fixed an issue where syslog forwarding dropped due to FQDN resolution + failures. +
+
+
PAN-295257
+
+
+ Fixed an issue where, after onboarding a firewall to Panorama, IPsec + tunnels displayed IKEv2 in Panorama, even though the tunnels were + configured with IKEv1 locally on the firewall. +
+
+
PAN-295221
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors, + Traffic and Threat logs were not forwarded to a Splunk server over + UDP. +
+
+
PAN-294893
+
+
+ Fixed an issue where firewalls with the + Send handshake messages to CTD for inspection + setting enabled caused incorrect security policy rules to be matched. + Specifically, traffic not identified as openai-base or openai-chatgpt + applications was incorrectly matched by the + ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected + response page for blocked URLs was not displayed. +
+
+
PAN-294770
+
+
+ (Firewalls in active/passive HA configurations) + Fixed an issue on firewalls where, after failover, certain subnets + were missing from the Link State Database, which prevented OSPF routes + from being immediately learned due to a Type-7 to Type-5 LSA + translation conflict in the ABR when the same LSA was advertised by + two peers in the NSSA area. +
+
+
PAN-294524
+
+
+ Fixed an issue where firewalls and Panorama management servers were + unable to view or download WildFire reports from a WF-500 appliance, + resulting in a 401 error in the report tab. +
+
+
PAN-294161
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to the + useridd + process restarting and causing an HA failover. This occurred due to + the + configd + process timing out when running the CLI command + show user user-id-agent config all. +
+
+
PAN-293985
+
+
+ Fixed an issue with the Panorama web interface where admin users were + unable to log in and received the error message + 504: Gateway Timeout. +
+
+
PAN-293877
+
+
+ (Firewalls with Hub vsys (virtual system) configurations enabled + only) Fixed an issue where, when using the Hub vsys feature to + redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP + policy enforcement failed intermittently on the active secondary + firewall. This occurred when traffic destined for specific non-Hub + vsys was routed to the active secondary, and the HIP query was not + triggered due to an incorrect check for the HIP mask in the Hub vsys. +
+
+
PAN-293848
+
+
+ Fixed an issue where Panorama failed to push the default value of + None for the secondary NTP server + address to managed firewalls, resulting in a commit validation error. + This occurred even when configuring the secondary NTP server address + as None in Panorama's web interface, + and affected both newly deployed and long-standing production + firewalls after upgrading. +
+
+
PAN-293511
+
+
+ Fixed an issue where renaming a BGP filtering profile in Panorama does + not update the corresponding BGP peer group in the virtual router, + leading to commit failures. +
+
+
PAN-293440
+
+
+ Fixed an issue where setting the + logdb-quota for the + desum log type to + 0 caused the /opt/panlogs + partition to reach capacity. +
+
+
PAN-292447
+
+
+ Fixed an issue where Panorama did not display data in the + Feature Adoption tab in Strata Cloud + Manager due to the system creating and deleting a CLI user for each + interval instead of reusing a permanent CLI user for telemetry. +
+
+
PAN-292393
+
+
+ Fixed an issue where TFTP file transfers intermittently timed out in + active-active HA pairs when the TFTP control channel was processed by + one firewall and the data channel was processed by the other. This + occurred because the firewall receiving the data channel failed to + match the predicted session due to asynchronous processing of HA + messages. +
+
+
PAN-292261
+
+
+ Fixed an issue where the firewall repeatedly reported an unreachable + syslog server as back online when + the server remained unavailable. This resulted in misleading + alternating connection status messages in the system logs. +
+
+
PAN-292242
+
+
+ Fixed an issue on M-200 and logging appliances where traffic logs were + intermittently truncated when forwarded using a TCP syslog + configuration. This issue occurred during the log forwarding stage due + to intermittent syslog drops caused by exceeding the forwarding queue + capacity. +
+
+
PAN-292228
+
+
+ Fixed an issue where, after configuring dual stack GlobalProtect with + both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with + the error message + flow-basic error; packet dropped, tunnel resolution failure. +
+
+
PAN-292019
+
+
+ Fixed an issue on the Panorama web interface where cloud applications + were not displayed under + Objects > Applications after a + new content upgrade and Cloud App Catalog download, and were only + visible in application groups, security policy rules, and the CLI. +
+
+
PAN-291883
+
+
+ Fixed an issue where Prisma Access logs were not visible in the + Security Logging Service (SLS) and Panorama. +
+
+
PAN-291792
+
+
+ (PA-7050 firewalls on vwire instances only) + Fixed an issue where Bidirectional Forwarding Detection (BFD) echo + packets were dropped due to the firewall dropping packets with the + same source and destination IP addresses. +
+
+
PAN-291716
+
+
+ Fixed an issue where during a commit, the firewall experienced an + out-of-memory (OOM) condition due to a memory leak and displayed an + error message. This issue caused the device to stop responding and + reboot unexpectedly. +
+
+
PAN-291661
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after + an upgrade, Elasticsearch intermittently entered into a Red state + before automatically recovering. +
+
+
PAN-291660
+
+
+ Fixed an issue where the firewall incorrectly reported the speed of + 25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID. +
+
+
PAN-291653
+
+
+ Fixed an issue where the GlobalProtect host ID field was + intermittently blank in traffic logs on Prisma Access, even when the + user was connected and had the correct host ID information. This + occurred when the IP address to host ID entry expired and the entry + was re-insterted without the dataplane flag being set. +
+
+
PAN-291635
+
+
+ Fixed an issue where cookie surrogate cache entries remained + unresolved after an + idmgr + process reset due to the request not being retransmitted. This + occurred because the timestamp in the cache entry was refreshed even + when the UID was 0, which prevented the retransmission of the request + if the initial response was not received. +
+
+
PAN-291067
+
+
+ Fixed an issue where the + devsrvr + process periodically exceeded its virtual memory limit and restarted, + which led to intermittent outages. +
+
+
PAN-290665
+
+
+ Fixed an issue with firewalls enabled with Security profiles where + certain traffic conditions caused high dataplane CPU utilization and + packet buffer exhaustion, which caused LACP flapping conditions. +
+
+
PAN-290640
+
+
+ (VM-Series firewalls on Microsoft Azure environments in HA + configurations only) Fixed an issue where, when an interface was configured with IPv6, + the firewall displayed the message + Unknown error during validation + after the client secret expired, which caused DNS resolution to fail + when resolving FQDNs and HA failovers to occur. +
+
+
PAN-290455
+
+
+ Fixed an issue where the + Pprof + path was missing in the + logrcvr + script, which prevented the conversion and decoding of addresses in + the resulting stack when running + Pprof + against + Logrcvr. +
+
+
PAN-289716
+
+
+ Fixed an issue where return traffic was dropped on service connection + firewalls due to routing failover and asymmetric return in service + connection firewalls. +
+
+
PAN-288388
+
+
+ Fixed an issue where, after an EDL certificate update or repository + migration, authentication failures caused the firewall to not fall + back to the last successfully cached EDL entries, which led to policy + rules that referenced the EDL to not be enforced. +
+
+
PAN-287803
+
+
+ Fixed an issue where, after upgrading the firewall, certain websites + weren't accessible when the accumulation proxy was enabled. The proxy + did not use the same DF bit state as the original traffic, causing it + to be fragmented and dropped elsewhere in the network. +
+
+
PAN-287782
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP + values from AF11 to CS0 on traffic passing through the firewall, even + when QoS policy rules and DSCP rewrite settings were not configured. +
+
+
PAN-287693
+
+
+ Fixed an issue where Panorama did not use the configured proxy + settings to check WildFire private cloud content and instead connected + directly to the WildFire device using the management interface. This + occurred even when + Use Proxy Settings for Private Cloud + was enabled. +
+
+
PAN-287622
+
+
+ Fixed an issue where IPv6 traffic was affected after upgrading the + firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption + enabled and a decryption policy configured for the traffic, the + firewall dropped packets due to receiving a + Packet Too Big ICMP message. This + occurred because the PathMTU information update was incorrect for the + TCB (pan-server) when the firewall was acting as a server. + Additionally, the flow label under the IPv6 header was set to zero + while the packet was being transmitted out of the firewall. +
+
+
PAN-287387
+
+
+ Fixed an issue on Panorama where API jobs failed with the error + message + Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a + large number of address objects in a single set call. +
+
+
PAN-285169
+
+
+ Fixed an issue on Panorama where Kerberos superusers were unable to + edit policy rules because the target device tab was grayed out. +
+
+
PAN-283053
+
+
+ Fixed an issue where the firewall experienced high disk space + utilization, which caused the firewall to become non-functional. +
+
+
PAN-282961
+
+
+ Fixed an issue where the firewall rebooted unexpectedly after a commit + due to a memory leak related to the + rasmgr + process and displayed the error message + Management server failed to send phase 1 to client l2ctrld + before rebooting. +
+
+
PAN-282956
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 and later PAN-OS + releases where the portal and gateway configuration view did not + display rows and columns. +
+
+
PAN-267450
+
+
+ Fixed an issue where the + reportd + process stopped responding with a SIGSEGV at + schedule_report_es_response. +
+
+
PAN-263422
+
+
+ Fixed an issue where SaaS Policy Recommendations policy rules created + at the tenant level were not displayed on the firewall. +
+
diff --git a/reference/PAN-OS/addressed/11.2.11.html b/reference/PAN-OS/addressed/11.2.11.html new file mode 100644 index 0000000..8a9273e --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.11.html @@ -0,0 +1,6655 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-316911
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where a newly bootstrapped firewall required a + management server restart, relicensing, or license push from Panorama + to invoke the device certificate. +
+
+
PAN-314142
+
+
+ Fixed an issue where establishing log forwarding connections to the + Strata Logging Service (SLS) took longer than expected, which resulted + in delayed log visibility on SLS. +
+
+
PAN-313623
+
+
+ Fixed an issue where the + /opt/pancfg/mgmt/ssl/private/ + directory on Palo Alto Networks devices with TPM support became 100% + utilized due to an accumulation of undeleted + .pub_pem files. This occurred + because executing the + show device-certificate status + CLI command initiated a process that generated these files but failed + to remove them, which prevented the fetching of new device + certificates. +
+
+
PAN-313572
+
+
+ (VM-Series firewalls only) Fixed an issue where + the dataplane restarted due to a segmentation fault. +
+
+
PAN-313258
+
+
+ Fixed an issue where PIM multicast routing failed on appliances with + advanced routing enabled. +
+
+
PAN-312706
+
+
+ Fixed an issue where the firewalls restarted due to a function lacking + a NULL-pointer sanity check. +
+
+
PAN-312618
+
+
+ Fixed an issue where the firewall was unable to activate GlobalProtect + client software and displayed + SW LIMIT messages related to + max-profiles and unsupported major and minor versions in the downgrade + list, which prevented successful software installation. +
+
+
PAN-311524
+
+
+ Fixed an issue where config-lock was not displayed on the web + interface. +
+
+
PAN-311412
+
+
+ Fixed an issue where the + show advanced-routing resource + CLI command failed to execute successfully when invoked through the + XML API and returned an error message. +
+
+
PAN-311261
+
+
+ Fixed an issue where the firewall generated duplicate URL Filtering + logs due to an error condition when the new XFF feature was enabled. +
+
+
PAN-311250
+
+
+ (Panorama appliances and Log Collectors only) + Fixed an issue where logs from multiple devices were not visible on + Panorama even though the Elasticsearch health status on the dedicated + Log Collectors appeared green. +
+
+
PAN-311074
+
+
+ Fixed an issue where GRE tunnels took significantly longer to + establish when the hold timer was configured to a value of 10 or + higher, which resulted in a tunnel requiring more successful keepalive + packets than expected to transition to an + Up state. +
+
+
PAN-311073
+
+
+ (Panorama managed firewalls in HA configurations only) Fixed an issue where firewalls incorrectly updated the modified + date and MD5 hash of policy rules during an HA sync commit job or a + subsequent local commit, even when no changes were made to the policy + rules. +
+
+
PAN-310868
+
+
+ Fixed an issue where PA Explicit proxy blocked ICMP packets from + flowing towards Envoy for Geneve due to the router not camping MSS + when the MTU was lower in the path. +
+
+
PAN-310499
+
+
+ Fixed an issue on Panorama where, while configuring an an Application + Filter with Generative AI tags, the web interface did not retain + application exclusions that were added across multiple pages until you + clicked OK. +
+
+
PAN-310263
+
+
+ (VM-Series firewalls only) Fixed an issue where + enabling TLS1.3 in a decryption profile prevented access to websites. +
+
+
PAN-309853
+
+
+ (Firewalls with FIPS-CC enabled only) Fixed an + issue where, when attempting to make changes to the GlobalProtect + portal, an error message was displayed and configuration updates + failed. +
+
+
PAN-309831
+
+
+ Fixed an issue where an AI Runtime Security Firewall rebooted when + processing Cursor traffic. +
+
+
PAN-309826
+
+
+ (VM-Series firewalls only) Fixed an issue where + files from SSL decrypted sessions were incorrectly forwarded to the + WildFire cloud for analysis even when + Allow Forwarding of Decryption Content + was disabled. +
+
+
PAN-309459
+
+
+ Fixed an issue where on PA-5420 firewalls, configuring security rules + with a number of static IMSI/IMEI/NSSAI entries exceeding 5,000 + resulted in a commit failure. This occurred because the firewall + incorrectly reported the maximum supported static IMSI/IMEI/NSSAI IDs + as 5,000 (as seen in the + cfg.mobile-nw-id.max-static-entries + system state variable), instead of the documented limit of 100,000 for + the platform. +
+
+
PAN-309392
+
+
+ Fixed an issue where the scroll bar did not appear when editing + Destination Addresses for Policy + Based forwarding policy rules. +
+
+
PAN-309379
+
+
+ Fixed an issue where the + logrcvr + process stopped responding on DPCs, which prevented logs from being + forwarded. +
+
+
PAN-309300
+
+
+ Fixed an issue where management plane system resources configuration + size exceeded 28 MB for over 4 hours, and the following error message + was displayed: + Configuration size reaching device capacity limit. +
+
+
PAN-309258
+
+
+ Fixed an issue where you were unable to delete a HIP object with + OR in the name, even though you were + able to successfully create and commit the object. +
+
+
PAN-309009
+
+
+ Fixed an issue where log ingestion stopped on the Elasticsearch + cluster when the number of open shards was significantly higher than + the number of data nodes. +
+
+
PAN-308902
+
+
+ Fixed an issue where, after upgrading to an affected release, the + firewall did not add mTLS websites that required client certificate + authentication via DN list to the ssl-decrypt exclude-cache list. +
+
+
PAN-308786
+
+
+ (Panorama appliances only) Fixed an issue where + traffic log queries using the + device_name filter returned no + results, and complex log queries that included negation operators + produced incorrect outputs. +
+
+
PAN-308727
+
+
+ Fixed an issue where traffic logs for + Remote Networks displayed the source + zone as trust instead of the remote + network name. +
+
+
PAN-308668
+
+
+ Fixed an issue on Prisma Access Remote Network firewalls where high + CPU utilization caused slowness and command timeouts. +
+
+
PAN-308654
+
+
+ Fixed an issue where the Elasticsearch Close Indices process closed + more indices than expected and dropped the number of open shards below + the minimum of 800 per Elasticsearch instance. This occurred because + the process did not correctly account for the number of Elasticsearch + instances when calculating the maximum number of allowed open shards. +
+
+
PAN-308606
+
+
+ Fixed an issue where traffic was blocked due to a mismatch between the + URL category specified in the Security policy rule and the URL filter + profile when custom URL categories with the same FQDN were configured. +
+
+
PAN-308468
+
+
+ Fixed an issue where the firewall rebooted due to the + all_task + process restarting. +
+
+
PAN-308418
+
+
+ Fixed an issue where, when Advanced DNS Security was enabled and + experienced unusually high loads, DNS resolution failures occurred + with the error + resources-unavailable. +
+
+
PAN-308377
+
+
+ (PA-7050 firewalls in HA configurations only) + Fixed an issue where the firewall reached 100% disk utilization due to + the + logrcvr + process repeatedly restarting and dumping core files due to a blocked + hints processing thread, which caused a failover. +
+
+
PAN-308261
+
+
+ Fixed an issue where the firewall failed to send SNMPv3 traps when the + SNMP destination was configured with an FQDN that resolved to multiple + IP address through DNS load balancing. +
+
+
PAN-308085
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where, after resizing the VM, the HA2 link became + unstable. Frequent keep-alive failures occurred, and HA2 keep-alive + packets were simultaneously transmitted to multiple destination MAC + addresses and the peer firewall's interface MAC). This issue occurred + on firewalls with Accelerated Networking enabled. +
+
+
PAN-308060
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where the BFD session went down and did not recover + even though the BGP remained in an established state, which caused the + firewall to cease route learning and advertisement with the peer, even + though BGP keep-alives were exchanged correctly. +
+
+
PAN-307901
+
+
+ Fixed an issue where a leak in decryption counters caused resource + exhaustion, which led to a GlobalProtect service outage. +
+
+
PAN-307893
+
+
+ Fixed an issue where the Strata Cloud Manager (SCM) web interface + failed to fetch External Dynamic List (EDL) details from Prisma Access + and displayed the error message + Could not fetch the EDL main info. This occurred because the XML query returned an external list + authentication failed response when the EDL entry lacked a valid + certificate. +
+
+
PAN-307806
+
+
+ Fixed an issue where, after replacing the MPC (Management Processor + Card) on a firewall, the + logdb process incorrectly wrote + logs to the root partition instead of the /opt/panlogs partition, + which led to high root partition usage and a non-functional state. +
+
+
PAN-307795
+
+
+ Fixed an issue where Panorama incorrectly generated system logs + indicating a lost connection to its peer after an upgrade even when + High Availability was not configured. +
+
+
PAN-307773
+
+
+ Fixed an issue on Panorama where enabling Post-Quantum Pre-Shared Key + (PPK) within an IKE Gateway profile that was configured as a part of a + template stack failed or was inconsistent when attempted via the web + interface, even when the keys were properly configured. +
+
+
PAN-307714
+
+
+ VM-Series firewalls only) Fixed an issue where + insufficient i-node space was available on the sysroot0 partition. +
+
+
PAN-307702
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where traffic passing through AE layer 2 interfaces was + interrupted during HA failovers. +
+
+
PAN-307597
+
+
+ Fixed an issue where BGP peering sessions between a hub firewall and a + satellite firewall over GlobalProtect LSVPN failed to connect. +
+
+
PAN-307453
+
+
+ Fixed an issue for Panorama management servers where commit push + failed when + customer_info status was a + failure received from the + orchestrator, which prevented the system from processing and + validating the specified telemetry region correctly during the commit. +
+
+
PAN-307072
+
+
+ Fixed an issue where SNMP interface speed reporting incorrectly + identified 5Gbps interfaces as 1Gbps interfaces during an SNMP walk. +
+
+
PAN-307066
+
+
+ Fixed an issue where static DNS entries that were configured on the + firewall failed to resolve for client machines when DNS over TLS (DoT) + was enabled on the firewall DNS proxy for both client and server + settings. +
+
+
PAN-306934
+
+
+ Fixed an issue where traffic was unexpectedly blocked due to a + misconfiguration with an empty or invalid application filter. The + firewall incorrectly interpreted the empty filter as + match all cloud-apps, which caused + the traffic to be denied. +
+
+
PAN-306903
+
+
+ Fixed an issue on the firewall where, after upgrading, the system log + displayed the error message + Last config fetch FAILED. A commit is required for userid + functionality to work. +
+
+
PAN-306886
+
+
+ Fixed an issue where the root partition on the firewall or Panorama + management server filled up due to a file leak in the logging process. +
+
+
PAN-306884
+
+
+ Fixed an issue where after changing Panorama to logger mode, commits + failed due to the + panorama-admin role assigned to + plugin management configuration users. +
+
+
PAN-306555
+
+
+ Fixed an issue where the firewall stopped responding, which led to + service outages. +
+
+
PAN-306502
+
+
+ Fixed two issues that impacted TLSv1.2 or earlier sessions when the + traffic matched a decryption policy rule with the no-decrypt action: +
+
    +
  • + Connections failed when both HTTP header insertion (Objects > Security Profiles > URL Filtering > HTTP + Header Insertion) and + Send handshake messages to CTD for inspection + (Device > Setup > Session > Decryption Settings > SSL + Decryption Settings) were enabled. +
  • +
  • + New sessions failed due to software packet buffer resource + depletion, which occurred when + Log Successful SSL Handshake + was disabled in the decryption policy rule and the decryption + profile attached to the rule had both + Block sessions with expired certificates + and + Block sessions with untrusted issuers + disabled. +
  • +
+
+
PAN-306451
+
+
+ (VM-Series firewalls on AWS environments only) + Fixed an issue where, after upgrading the firewall to an affected + release, GlobalProtect clients did not connect with IPSec and instead + connected using SSL due to traffic flow being disabled when checking + for health check packets. +
+
+
PAN-306306
+
+
+ (Panorama appliances in FIPS-CC mode only) + Fixed interdevice TLS communication failures that occurred with RSA + and RSA-PSS signature algorithms across multiple layer 7 application + services. +
+
+
PAN-306226
+
+
+ Fixed an issue where the TLS handshake did not complete and the + session did not go through. This occurred if the HTTP header insertion + applied to an HTTP CONNECT request passing through the firewall, the + scan-handshake feature was enabled, the session matched a decryption + policy rule with the decrypt action, and if the TLS client hello was + in a single packet and TLS 1.2 or below. +
+
+
PAN-306225
+
+
+ Fixed an issue on the firewall where the + sslmgr + process memory utilization continually increased due to memory + fragmentation. +
+
+
PAN-306215
+
+
+ Fixed an issue where creating device groups in bulk via XML API took + significantly more time and the web interface stopped responding. +
+
+
PAN-306103
+
+
+ (PA-3400 and PA-5400 Series firewalls only) + Fixed an issue where the firewall dataplane frequently restarted when + lockless QoS was enabled +
+
+
PAN-305922
+
+
+ Fixed an issue on Panorama where the CLI output for the running + configuration intermittently inserted + set template stack commands + within certificate hash data. +
+
+
PAN-305835
+
+
+ Fixed an issue where firewalls with Memory Integrity Checking + Architecture enabled rebooted unexpectedly due to accessing an invalid + memory address. This occurred because the forwarding data structure + index exceeded its designed limit. +
+
+
PAN-305605
+
+
+ Fixed an issue where GlobalProtect gateway authentication failed due + to the firewall incorrectly bypassing SAML. +
+
+
PAN-305557
+
+
+ Fixed an issue where LSVPN (Large Scale VPN) satellites failed to + authenticate to the gateway because the portal was providing a + zeroized certificate. +
+
+
PAN-305552
+
+
+ Fixed an issue where DLP logs displayed an incorrect file type when + the firewall did not set the file type field. +
+
+
PAN-305549
+
+
+ Fixed an issue where the firewall's service route functionality was + impacted due to a missing service route support code. +
+
+
PAN-305502
+
+
+ Fixed an issue where Panorama was unable to forward logs to a syslog + server over TLSv1.3 when configured with SSL on a custom port. The + connection was established, but logs were not forwarded due to a + failure in the CRL check. +
+
+
PAN-305412
+
+
+ Fixed an issue where the Logging Service License Status displayed a + license failure when the license status transitioned from valid to + expired and then back to valid even when the connection to the + Security Logging Service (SLS) was working. +
+
+
PAN-305411
+
+
+ Fixed an issue where, after creating a logical interface with an + assigned IP address and adding it to a virtual router, the connected + route for the interface did not appear in the + show routing route CLI command + output. This occurred even when the interface was up and learning ARP + entries. +
+
+
PAN-305374
+
+
+ Fixed an issue on Panorama where the first letter of a custom URL + category was not displayed in generated reports. +
+
+
PAN-305301
+
+
+ Fixed an issue where the timing of GlobalProtect lifetime expiry or + inactivity logout notifications used for GlobalProtect SSL tunnels + could cause the + pan_task + process to stop responding and the dataplane to restart. +
+
+
PAN-305188
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric + routing environments if the Client Hello was split into multiple + segments and arrived out of order. +
+
+
PAN-305105
+
+
+ Fixed an issue where commits involving routing related network + configuration changes experienced slower than usual completion times + or remaining at 20% completion. +
+
+
PAN-304840
+
+
+ Fixed an issue where multiple firewalls experienced high management + CPU utilization after upgrading to an affected release due to repeated + index regeneration occurring every 15 minutes, which caused periodic + CPU spikes above 90%. +
+
+
PAN-304756
+
+
+ Fixed an issue on Panorama where, after you disabled the shared + optimization feature, a full configuration push to multi-vsys devices + caused a validation error. +
+
+
PAN-304746
+
+
+ (Panorama appliances and Panorama virtual appliances only) Fixed an issue where the + configd + process restarted when committing and pushing configuration for a new + WildFire cluster. +
+
+
PAN-304718
+
+
+ Fixed an issue where OSPF and BGP outages occurred due to an + all_task process restart during + clientless VPN content rewrite processing. +
+
+
PAN-304696
+
+
+ Fixed an issue where the Cloud User-ID connection timed out because + the firewall took too long to process the OCSP response. +
+
+
PAN-304689
+
+
+ Fixed an issue on Panorama where device group users were able to view + and commit configuration changes that had been created by Superusers + but not yet committed, even with access domains configured. +
+
+
PAN-304636
+
+
+ Fixed an issue where BGP aggregate routes were not created and discard + routes were not installed in the routing table. +
+
+
PAN-304576
+
+
+ Fixed an issue where the firewall entered a non-functional state due + to segmentation fault within the + all_pktproc + process that was caused by a session that involved http2 cleartext + traffic. +
+
+
PAN-304538
+
+
+ Fixed an issue where traffic logs did not populate the + Source EDL or + Destination EDL fields when traffic + matched a Security policy rule that used predefined external dynamic + lists. +
+
+
PAN-304496
+
+
+ Fixed an issue where, after unregistering an IP tag and registering a + different IP tag for the same IP address via XML API, the dynamic + address group membership was not updated on the dataplane, which + resulted in Security policy rules being enforced incorrectly. +
+
+
PAN-304397
+
+
+ Fixed an issue on the web interface where you were unable to test the + SCP server connection for Scheduled Log Exports, and the error message + key is invalid was displayed. +
+
+
PAN-304229
+
+
+ Fixed an issue on the Panorama web interface where you were unable to + disable Lifesize (Templates > Network > Network Profiles > IPSec + Crypto). +
+
+
PAN-304205
+
+
+ Fixed an issue on Panorama where, after upgrading to an affected + release, a partial commit via the API did not push configuration + changes to managed firewalls, and a full commit was required to + synchronize the configuration. +
+
+
PAN-304148
+
+
+ Fixed an issue where a large number of GlobalProtect users experienced + failed gateway pre-logins with the error + Failed to create SAML SSO request + during peak login times. +
+
+
PAN-304088
+
+
+ Fixed an issue where TCP traffic stopped working from Prisma Access + clients to TCP services behind the Service Connection (SC) after a + dataplane upgrade to PAN-OS 10.2.10-h26. +
+
+
PAN-304075
+
+
+ Fixed an issue where the firewall did not detect evasions due to TCP + checksum offloading not being enabled. +
+
+
PAN-303959
+
+
+ Fixed an issue where traffic was incorrectly identified as + unknown-tcp/unknown-udp due to App-ID resource leak and eventually + dropped. +
+
+
PAN-303954
+
+
+ Fixed an issue where, when configuring Safenet HSMs in HA and + authentication HSM manually, the second HSM server failed to + authenticate due to the firewall overwriting the first HSM server's + certificate with the second HSM server's certificate. +
+
+
PAN-303836
+
+
+ Fixed an issue where intermittent session-table resets on the AIRS VM + triggered packet drops, which led to packet loss in egress response + traffic. +
+
+
PAN-303833
+
+
+ Fixed an issue where Panorama and managed devices incorrectly + displayed warning messages that indicated that an Advanced DNS + Security license and an Advanced Threat Prevention license were + required, even when a traditional DNS Security license was installed. +
+
+
PAN-303826
+
+
+ Fixed an issue where scheduled software upgrades from the Software + Change Management (SCM) server to the firewall failed with a timeout + error during download. +
+
+
PAN-303791
+
+
+ Fixed an issue where configuring a service route on a loopback + interface caused intermittent connectivity issues and disrupted + traffic due to the firewall being unable to resolve domain names. +
+
+
PAN-303765
+
+
+ Fixed an issue on Panorama where selective pushes failed when a + scheduled job was deleted from the Panorama configuration. +
+
+
PAN-303745
+
+
+ Fixed an issue where inter-dataplane forwarding did not work for + sessions ingressing on Slot 2, which resulted in intermittent ping + failures to interfaces on Network Card 2 when traffic was forwarded to + Slot 3. +
+
+ Note: With this fix, after a slot restart, the global counter will + still show dot1q errors for a short period. +
+
+
PAN-303722
+
+
+ Fixed an issue on the firewall where configuring spyware and + vulnerability profiles in Security policy rules caused a memory leak + in the + devsrvr + process with each configuration commit. +
+
+
PAN-303671
+
+
+ Fixed an issue where third-party clients were unable to connect to the + GlobalProtect gateway after a successful login when the username was + entered in the domain\username format. +
+
+
PAN-303663
+
+
+ Fixed an issue on the firewall where SolarWinds monitoring systems + reported 100% usage for + Slot1 Data Processor-0 Hardware Packet Buffers + due to an inaccurate reported packet buffer. +
+
+
PAN-303627
+
+
+ Fixed an issue where, after committing a configuration change, the + firewall experienced traffic issues, + pan_task + crashes, and LACP interface failures. +
+
+
PAN-303559
+
+
+ Fixed an issue where, after manuallly creating a device telemetry + bundle, the + hour_cli_output.txt file within + the bundle had a file size of 0 bytes. This occurred when checking the + bundle content after enabling device telemetry and setting the device + telemetry upload endpoint. +
+
+
PAN-303508
+
+
+ Fixed an issue where the firewall failed to fetch the device + certificate during initial installation. +
+
+
PAN-303487
+
+
+ Fixed an issue where Panorama appliances in FIPS-CC mode did not push + the configured values for + max-session-count and + max-session-time to managed + firewalls that were not in FIPS mode. +
+
+
PAN-303390
+
+
+ Fixed an issue on the firewall where the DNS cache capacity was set to + an incorrect value, which caused the firewall to repeatedly send DNS + requests for FQDN objects even after receiving valid responses. This + resulted in the firewall not storing DNS responses in the cache for + more than 10-15 seconds despite the minimum FQDN refresh interval + being set to a higher value. +
+
+
PAN-303379
+
+
+ Fixed an issue where the + show system resources CLI command + displayed incorrect CPU usage values that did not add up to 100%. +
+
+
PAN-303156
+
+
+ Fixed an issue where the session timer for a custom application did + not transition from the initial 3-way handshake timer to the + application timeout when out-of-order 3-way handshake packets were + detected. +
+
+
PAN-303051
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the + reportd + process due to retaining memory that was temporarily used for report + generation instead of releasing the memory for reuse, which resulted + in continuous accumulation and memory exhaustion. +
+
+
PAN-302983
+
+
+ Fixed an issue where, after committing changes on Panorama, a shared + post-rule moved to the end of the + post shared rulebase on the + managed device instead of remaining at the top. +
+
+
PAN-302927
+
+
+ Fixed an issue where, after upgrading Panorama, the + Push to Devices option did not + display selected devices, and the + OK and + Cancel buttons did not function as + expected. Selecting + Push to Devices did not populate any + results, and clicking OK after + selecting a device under + Edit selections did not work. + Despite this, selecting Push or + Validate Device Group Push still + pushed to the previously canceled, non-displayed devices. +
+
+
PAN-302921
+
+
+ Fixed an issue where the + set auth radius-require-msg-authentic yes + and + show auth radius-require-msg-authentic + CLI commands were unavailable on Log Collectors. +
+
+
PAN-302834
+
+
+ Fixed an issue where Panorama did not display decryption logs after a + certain date due to the decryption index being purged. +
+
+
PAN-302811
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where network traffic was disrupted due to the + all_pktproc + process repeatedly restarting, which caused an HA failover. +
+
+
PAN-302767
+
+
+ Fixed an issue where IPv6 IPsec WAN support was not available in + Prisma Access. +
+
+
PAN-302737
+
+
+ Fixed an issue where API key generation failed after renewing an + expired API certificate, and the system continued to use the expired + certificate. +
+
+
PAN-302703
+
+
+ (Panorama virtual appliances only) Fixed an + issue where Panorama was inaccessible with the error message + Timed out while getting config lock. +
+
+
PAN-302567
+
+
+ Fixed an issue where firewalls incorrectly returned the message + API Error: Success with the error + code 403 instead of the correct message + API Error: Invalid Credential, when + Cisco-ISE server was used for MSCHAP-PEAP Radius auth. +
+
+
PAN-302564
+
+
+ Fixed an issue on the firewall where a path monitoring failure + occurred and caused the dataplane to restart. +
+
+
PAN-302551
+
+
+ Fixed an issue where the firewall displayed as disconnected in the SLS + due to the serial number not being retrieved +
+
+
PAN-302428
+
+
+ Fixed an issue on Panorama where daily scheduled report emails for + custom reports were delivered with no content and instead incorrectly + displayed the message + No matching data found. With this + fix, the content is displayed correctly. +
+
+
PAN-302317
+
+
+ Fixed an issue where the + all_task + process stopped responding after a commit, which cause the dataplane + to reboot repeatedly. +
+
+
PAN-302254
+
+
+ Fixed an issue where the web interface made calls to retrieve cloud + authentication service regions even when creating a non-cloud + authentication service profile. +
+
+
PAN-302127
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where adding a 26th floating IP address to an + aggregate ethernet interface in one vsys caused IPSec tunnels on + another vsys to stop working due to rekeying. This occurred due to the + routed + process not detecting the unchanged virtual address, uninstalling it, + and then reinstalling it, which ended the + ikemgr + connection on the virtual address. +
+
+
PAN-302085
+
+
+ Fixed an issue where network values were not displayed in Panorama + with the error message + There is no value for the selected item. This was due to the device group passing vsysName in Panorama. +
+
+
PAN-301975
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the passive firewall incorrectly triggered PBP alerts even + with low packet rates. +
+
+
PAN-301965
+
+
+ Fixed an issue on Panorama where enabling Advanced Routing in a + template did not work. +
+
+
PAN-301937
+
+
+ Fixed an issue where Microsoft Defender for Cloud detected cleartext + SSH private keys in the /var/appweb and /etc/appweb directories on + PA-VM firewalls deployed in Azure. +
+
+
PAN-301912
+
+
+ Fixed an issue where Panorama stopped responding when deploying + dynamic updates to managed devices. +
+
+
PAN-301848
+
+
+ Fixed an issue where websites were incorrectly categorized with high + severity alerts (Monitoring > URL Filtering) even though they were assessed as low risk. This occurred due to + session information being unavailable during logging. +
+
+
PAN-301828
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud + Manager and configured to use a proxy server for external connections, + the management server did not use the configured settings to connect + to the Cloud Management service. +
+
+
PAN-301801
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process + fluctuated intermittently between green and red states, which led to + interruptions in log collection. This issue occurred when the number + of shards exceeded the cluster's maximum supported threshold of + greater than 1000 shards per Elasticsearch instance. +
+
+
PAN-301733
+
+
+ Fixed an issue where the + show cloud-auth-service-regions + CLI command took longer than expected to complete due to timeouts + while fetching Cloud Authentication Service (CAS) regions. +
+
+
PAN-301691
+
+
+ Fixed an issue where BGP stopped responding with the error message + Too many open files when pushing + 1000 eBGP (External BGP) neighbor configurations. With this fix, the + number of file descriptors for the BGP process is increased from 1024 + to 8192. +
+
+
PAN-301662
+
+
+ Fixed an issue where direct application URLs for Clientless VPN did + not work on one device in a high availability (HA) pair because the + RelayState in the SAML assertion was not encoded by the firewall. +
+
+
PAN-301653
+
+
+ Fixed an issue where DNS traffic sessions prematurely terminated with + the message + resources-unavailable. This + occurred due to IPv4 fragmented DNS responses causing the Advanced DNS + Security module to incorrectly pack the DNS payload multiple times + when forwarding to the cloud for inspection. +
+
+
PAN-301600
+
+
+ Fixed an issue on the firewall where, after upgrading Panorama, OSPF + adjacencies remained in the exchange start state, which resulted in an + incomplete routing table. +
+
+
PAN-301456
+
+
+ Fixed an issue on Panorama where the + debug system reset-ztp CLI + command was unavailable. +
+
+
PAN-301430
+
+
+ Fixed an issue where the web server did not specify the content type + in the header for font files, which could allow a browser to + misinterpret the content and potentially lead to cross-site scripting + (XSS) vulnerabilities. +
+
+
PAN-301409
+
+
+ Fixed an issue where Panorama failed to perform a selective push to a + managed device when device tags were added or modified on the policy + rules. The selective push failed with the error message + Failed to generate selective push configuration. Schema validation + failed. Please try a full push. +
+
+
PAN-301386
+
+
+ Fixed an issue where BFD echo packets were dropped on Vwire interfaces + due to being incorrectly detected as a land attack when the source and + destination ports of the BFD packets were different. +
+
+
PAN-301305
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the + all_task + process stopped responding and caused the passive firewall to reboot. +
+
+
PAN-301290
+
+
+ Fixed an issue on the Panorama web interface where a custom + administrator with device group and template permissions was unable to + upgrade devices to non-preferred releases due to the options to + uncheck base and preferred releases not being displayed. +
+
+
PAN-301222
+
+
+ Fixed an issue where DNS Security logs incorrectly displayed a + sinkhole action for benign DNS categories due to the firewall saving + the drop or sinkhole action in session flags without discarding the + session. +
+
+
PAN-301186
+
+
+ Fixed an issue on the Panorama web interface where + Enable pushing device monitoring data to Panorama + was always checked, regardless of the actual configuration. +
+
+
PAN-301113
+
+
+ Fixed an issue where the XML API returned the error + Access to this vsys is unauthorized + when generating a report for a specific vsys, even when the + administrator had access to that vsys. This was due to the API session + not correctly populating the + vsysvector field with the user's + allowed vsys. +
+
+
PAN-301089
+
+
+ Fixed an issue where Kubernetes pod health checks failed when the + pan-fw annotation was added. When the annotation was present, health + check traffic from the host's public IP address range to the pod CIDR + range was tunneled to the firewall by the pan-cni, which resulted in + asymmetric flows and no response from the pod endpoints. +
+
+
PAN-301018
+
+
+ Fixed an issue on Panorama where API queries for correlated category + logs incorrectly returned a count of 0. +
+
+
PAN-301014
+
+
+ Fixed an issue where the GlobalProtect portal used an outdated + bootstrap version for clientless VPN. +
+
+
PAN-300933
+
+
+ Fixed an issue on Panorama where, after downgrading to an affected + release, the commit-all operation + failed due to a missing downgrade script. +
+
+
PAN-300922
+
+
+ Fixed an issue where the syslog connection was handled by the syslog + forwarding thread. +
+
+
PAN-300916
+
+
+ Fixed an issue where Panorama management servers failed to forward + syslog messages via TLS to a syslog server when DNS resolution for + IPv6 addresses failed, and the system did not automatically fall back + to IPv4. +
+
+
PAN-300906
+
+
+ Fixed an issue where XML API commands failed with a + Method not found (policy_xml) + error in dagger.log. The issue was due to missing XML-related + functions for inline-cloud-proxy. +
+
+
PAN-300837
+
+
+ Fixed an issue where firewalls experienced multiple reboots due to the + pan_task + process restarting with a SIGSEGV signal. This occurred because the + client-to-firewall side assumed TLS 1.3 for the firewall-server side. +
+
+
PAN-300833
+
+
+ Fixed an issue where the static default route remained active even + when the path or SaaS monitor was down when SD-WAN was used for local + internet breakout. This was due to missing validation handling in the + FRR routed code for link up/down status. +
+
+
PAN-300671
+
+
+ Fixed an issue where traffic reports that were generated with + destination/source and destination/source hostnames were not displayed + in IPv4 format. +
+
+
PAN-300664
+
+
+ Fixed an issue on the Panorama and firewall web interface where + Applications pages became unresponsive after activating the SaaS + Inline license. +
+
+
PAN-300638
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall stopped responding due to an out-of-bounds read when + parsing TLS 1.3 clientHello messages with large TLS clientHello + extensions where the + supported_versions extension fell + outside the first TCP segment. +
+
+
PAN-300637
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the firewall unexpectedly rebooted due to + repeated + varrcvr + process restarts. +
+
+
PAN-300617
+
+
+ Fixed an issue where the Elasticsearch cluster status displayed as red + due to unassigned shards, which prevented logs from updating. +
+
+
PAN-300555
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the HA1-A interface reported an incorrect SNMP down value + even when the interface was physically up on the active firewall. +
+
+
PAN-300548
+
+
+ Fixed an issue where using the IKEv2 multiplier setting for VPN + re-authentication resulted in the firewall not re-authenticating at + the expected intervals when both sides initiated rekeying. The + internal re-authentication counter incremented when the local side + triggered the rekey, but not when the peer side triggered it. +
+
+
PAN-300423
+
+
+ Fixed an issue where Data Processing Cards (DPCs) installed in slots 5 + and 6 remained stuck in a starting state with the error + Signal detected for port xeS5-DP0 but Link Down + alerts, which resulted in device instability. +
+
+
PAN-300280
+
+
+ Fixed an issue where, on firewalls configured as an Area Border Router + (ABR) with a backbone area (0.0.0.0) and a stub area, external Type-5 + Link State Advertisement (LSA) routes were not installed in the + routing table. +
+
+
PAN-300186
+
+
+ Fixed an issue where the GlobalProtect portal exposed the internal IP + address of the gateway when accessed via the SAML20/SP/ACS endpoint. +
+
+
PAN-300138
+
+
+ Fixed an issue where DNS queries stalled or repeatedly time out due to + multiple DNS responses with different CNAME values causing evasion + false positive alerts. +
+
+
PAN-299915
+
+
+ Fixed an issue where the Elasticsearch cluster health status displayed + as red on dedicated log collectors due to an expired Elasticsearch CC + certificate, which prevented log visibility from Panorama. +
+
+
PAN-299815
+
+
+ Fixed an issue on multi-vsys firewalls where a host was not removed + from the quarantine list after receiving a redistribution message from + Panorama. This occurred when Panorama was configured to redistribute + quarantine messages to a firewall cluster, and the GlobalProtect + configuration and redistribution were built out in a vsys other than + vsys1. +
+
+
PAN-299785
+
+
+ (PA-7500 and PA-5450 firewalls in FIPS-CC mode) + Fixed an issue where the affected firewalls would boot into + maintenance mode when a reboot was initiated from the web interface. + This was due to a device reboot triggering a power down to all slots, + leading to maintenance mode. A hard reboot would allow the firewall to + boot normally. +
+
+
PAN-299772
+
+
+ (VM-Series firewalls in active/passive configurations only) Fixed an issue where, after an HA failover event, the newly active + firewall DHCP client interfaces failed to obtain IP addresses + automatically. This occurred because the DHCP client processes did not + initiate the necessary DHCP discover or renew requests +
+
+
PAN-299757
+
+
+ Fixed an issue where Router Advertisements for IPv6 were not sent at + the configured time intervals. +
+
+
PAN-299751
+
+
+ Fixed an issue where the firewall was unable to connect to the + Subscription License Service (SLS) due to a public and private key + pair mismatch with the device certificate. +
+
+
PAN-299738
+
+
+ Fixed an issue where excessive dataplane debug logs were generated due + to the + pan_task + process restarting, even without any dataplane debug logs or captures + being enabled by the administrator. +
+
+
PAN-299706
+
+
+ Fixed an issue where the firewall repeatedly sent DNS requests for + FQDN objects despite even after receiving valid responses. +
+
+
PAN-299705
+
+
+ Fixed an issue where API calls to commit changes on Panorama + intermittently failed when using the XML API with refresh=no, which caused changes to not be applied to the partial-commit + configuration. +
+
+
PAN-299622
+
+
+ Fixed an issue where the MFA timestamp was not redistributed between + standalone firewalls behind an Azure load balancer after upgrading, + which resulted in users being prompted to reauthenticate multiple + times. +
+
+
PAN-299615
+
+
+ Fixed an issue where, when the Network Packet Broker feature was + enabled, forward TLS (non-decrypted) traffic was not working as + expected when there were segmented client hellos and a no-decrypt rule + existed. This issue occurred when Zone Protection profiles were + configured for trust/untrust zones but not attached to NPB zones. +
+
+
PAN-299495
+
+
+ Fixed an issue where the + show system setting ssl-decrypt certificate + CLI command did not display certificates when XML output was enabled. +
+
+
PAN-299450
+
+
+ Fixed an issue where PAN-OS + logrotate did not rotate large + log files until the + cron.daily + process ran, which resulted in the root partition filling up. +
+
+
PAN-299242
+
+
+ Fixed an issue where the firewall's SSL proxy sent an empty HTTP2 + SETTINGS message to the client before confirming server support, which + caused some clients to incorrectly assume HTTP/2 support and not fall + back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad + Request frames from the server, which prevented the client from + correctly detecting the lack of HTTP/2 support. +
+
+
PAN-299228
+
+
+ Fixed an issue where a session process consumed excessive CPU + resources, even when Data Loss Prevention (DLP) was not enabled. This + occurred due to the active threat list being iterated twice when + active threats were present in the session. +
+
+
PAN-299193
+
+
+ Fixed an issue on the firewall where, after upgrading, autocommits + repeatedly failed until after a second reboot due to a timing issue + between content loading on the management plane card (MPC) and the log + receiver startup. +
+
+
PAN-299161
+
+
+ Fixed an issue where the bytes number overflowed for a specific + application, which caused Network Monitor graphs to display an + unexpectedly large volume of traffic. +
+
+
PAN-299027
+
+
+ (Panorama virtual appliances in Management Mode only) Fixed an issue where a maximum configuration size of 120 was + incorrectly enforced instead of 150 MB. +
+
+
PAN-298945
+
+
+ Fixed an issue where OSCP HTTP POST requests were not formatted + correctly, which caused failures with strict responders. +
+
+
PAN-298929
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where, after upgrading the ESXi host to version 8.0.3, the + firewall interface went down on the active firewall due to a behavior + change in ESXi 8. +
+
+
PAN-298907
+
+
+ Fixed an issue on PA-VM in AWS where, in a two-arm deployment + integrated with Gateway Load Balancer (GWLB), the firewall did not + preserve the GENEVE source port for internet traffic, resulting in + increased latency. The fix ensures the firewall preserves the outer + UDP source port of GENEVE encapsulation when sending traffic back to + GWLB. +
+
+
PAN-298872
+
+
+ (PA-400 Series firewalls in HA configurations only) Fixed an issue where ports went down after an HA failover. +
+
+
PAN-298788
+
+
+ Fixed an issue where the /pancfg partition on the Azure Cloud NGFW + reached 100% utilization, which caused commit failures. +
+
+
PAN-298684
+
+
+ Fixed an issue where an Application Override policy rule was not + applied using an IPv4 source IP address with IPv6 enabled and + Network > + Zones > + Pre-NAT Identification enabled. +
+
+
PAN-298654
+
+
+ Fixed an issue where the firewall generated false positive threat logs + during updates to a large domain list (EDL) when a DNS lookup for a + domain being added or removed occurred during the update process. This + resulted in a threat log being generated for a different, unrelated + domain that remained on the list. +
+
+
PAN-298617
+
+
+ Optimized the commit workflow to reduce the size of the effective + configuration, resulting in lower memory consumption. +
+
+
PAN-298460
+
+
+ (Panorama appliances in HA configurations on Microsoft Azure + environments only) Fixed an issue on the web interface where the plugin versions that + were displayed when hovering the cursor over the Green Match icon were + inconsistent even though the Panorama web interface reported the + versions as matching. +
+
+
PAN-298387
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP + addresses did not display in traffic and threat logs. +
+
+
PAN-298288
+
+
+ Fixed an issue where traffic loss occurred when two aggregate ethernet + interfaces were configured as vwire with only one member link active + in the aggregate ethernet interface, which occurred due to an + incorrect logic in active port map of AE interfaces. +
+
+
PAN-298279
+
+
+ Fixed an issue where Panorama administrators defined in a SAML + Identity Provider (IdP) were unable to authenticate if their username + exceeded 32 characters, and the system logs displayed the failed + authentication attempt with a truncated username. +
+
+
PAN-298252
+
+
+ Fixed an issue where Data Loss Prevention (DLP) inspection of chunked + transfer encoding over TLS resulted in incomplete file downloads on + Outlook Web App (OWA) due to the WIF page size limit, which led to + corrupted or incomplete PDF attachments. +
+
+
PAN-298241
+
+
+ Fixed an issue where the NAT IP address pool was exhausted, which led + to intermittent connectivity issues with call applications and + outbound call failures. This occurred due to the firewall not properly + releasing NAT dynamic ports back to the address pool. +
+
+
PAN-298141
+
+
+ Fixed an issue where the firewall experienced recurring kernel + segfaults related to multiple processes, which led to a SIGSEGV error. +
+
+
PAN-298000
+
+
+ Fixed an issue where the + useridd + process stopped responding after an upgrade, which led to high packet + buffer congestion and an OOM condition. +
+
+
PAN-297976
+
+
+ Fixed an issue where the firewall experienced extended boot times + after a reboot due to the + configd + process needing to rebuild the ACE catalog after detecting + discrepancies that were caused by duplicate application checking + between the ACE catalog and content. +
+
+
PAN-297972
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched + Inline Cloud Analysis prefiltering signatures, even when Inline Cloud + Analysis features were not enabled. +
+
+
PAN-297963
+
+
+ Fixed an issue where PA-400 Series firewalls were not properly caching + DNS responses for FQDN objects. The firewall was observed to + repeatedly send DNS requests for the same FQDN objects every 10-15 + seconds, even after receiving valid responses, despite the minimum + FQDN refresh interval being set to a much higher value. This resulted + in excessive DNS queries originating from the firewall's management + interface. +
+
+
PAN-297819
+
+
+ Fixed an issue where the firewall was unable to send device telemetry + files to Cortex Data Lake due to the firewall receiving an invalid + upload token. +
+
+
PAN-297818
+
+
+ Fixed an issue on Panorama where exporting managed device information + that included a PA-450R-5G appliance resulted in the + Cellular Firmware field being + exported into multiple cells. +
+
+
PAN-297797
+
+
+ Fixed an issue where, during a refresh of a large External Dynamic + List (EDL), traffic that matched a domain on the list was incorrectly + identified as a different domain, which resulted in false positive + threat logs. +
+
+
PAN-297796
+
+
+ Fixed an issue on Panorama where the policy review feature in + Dynamic Updates failed to display + Security policy rules when the device group was set to + All. +
+
+
PAN-297782
+
+
+ Fixed an issue on Panorama where reassociating a vsys from one device + group to another in a multi-vsys environment resulted in another vsys + from the same firewall being removed from the original device group. + This resulted in the device being moved into the + no device groups attached group, a + superuser was required to manually reattach the device. +
+
+
PAN-297775
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release, + the Visible Virtual System field referenced the vsys name instead of + the vsys ID, which caused inter-vsys routing to fail. This occurred + when a vsys display name matched one of the vsys IDs. If you're using + a multivsys environment, you must upgrade your firewalls to a fixed + PAN-OS version. The best practice is to upgrade both the firewalls and + Panorama to a fixed PAN-OS version. +
+
+ If you don't upgrade Panorama to a fixed version, you'll encounter + PAN-245064, where a commit on a multivsys firewall fails with the + message + vsys name should end with a number vsys is invalid + after you + Export or push device config bundle + from 11.1.1 Panorama. +
+
+ After you upgrade Panorama to a fixed version, you'll encounter + PAN-214177, which causes an + Export or Push device config bundle + from Panorama to the firewall to fail. The workaround for PAN-214177 + is to first push only the template configuration and then push the + device group configurations. +
+
+
PAN-297774
+
+
+ Fixed an issue on the web interface where the TLS Version was + misspelled as TLS Vesrion (Device > Server Profiles > Email). +
+
+
PAN-297761
+
+
+ Fixed an issue where the firewall incorrectly categorized some URLs as + not-resolved due to a conflict with Top Level Domain (TLD) data + handling in the PAN-DB URL cloud. This affected URLs under domains + marked as TLDs, which the firewall incorrectly assumed did not have + any category. +
+
+
PAN-297749
+
+
+ Fixed an issue where the redistribution agent status was blank on the + web interface on both the firewall and Panorama, even though the CLI + showed the agent as connected. +
+
+
PAN-297708
+
+
+ Fixed an issue where a long-lived session with many Machine Learning + (ML) model triggers caused a memory leak of feature states associated + with the ML model runs. This resulted in Spyware_State failure + increases, allocation max outs, and impaired policy matching. +
+
+
PAN-297610
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade + due to the fsck command scanning + drive partitions in parallel with the root partition, which caused the + process to take an extended amount of time. +
+
+
PAN-297609
+
+
+ Fixed an issue where the CLI command + debug user-id refresh user-id agent all + failed with the error message + Invalid agent name. Agent name should be 1 to 31 characters + long. +
+
+
PAN-297540
+
+
+ (Panorama managed firewalls in HA configurations only) Fixed an issue where the HA-Link-Monitor configuration pushed from + Panorama was converted to a local configuration on the peer device + after an HA sync, which caused subsequent Panorama pushes of link + monitor changes to be flagged as overwritten, and a forced template + push or manual clearing of the configuration on the firewall was + required. +
+
+
PAN-297458
+
+
+ Fixed an issue where the + all_task_1 + process crashed on the firewall when the wif service wasn't available + because the wif detection ID was not in the current service table. +
+
+
PAN-297412
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall rebooted unexpectedly due to a negative decoded length. +
+
+
PAN-297370
+
+
+ Fixed an issue where pushing a new object from Panorama to a Cloud + NGFW Device Group unexpectedly removed existing Panorama-pushed policy + rules, even though the + Push Preview did not show any + deletions, which led to traffic disruptions. +
+
+
PAN-297321
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where return packets from a phone gateway looped + between the HA pair instead of being encapsulated into the + GlobalProtect tunnel. This occurred when the inner session and the + outer IPSec tunnel terminated on different nodes, which led to + excessive retries and packet drops. +
+
+
PAN-297320
+
+
+ (Panorama virtual appliances only) Fixed an + issue where scheduled configuration exports failed with an + invalid key error when connecting + to a SCP server using non-default SCP port. Also, additional CLIs were + added to delete the known-hosts file. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high + packet rates on the synthetic path in DPDK mode. +
+
+
PAN-297263
+
+
+ (PA-5220 firewalls only) Fixed an issue where + the + ikemgr + process crashed intermittently, which caused IPSec tunnels to go down + randomly. With this fix, the IKE Security association data structures + are accessed in a thread-safe manner, and the + ikemgr + process does not reference an invalid memory pointer during teardown + operations. +
+
+
PAN-297005
+
+
+ Fixed an issue where exporting custom reports resulted in empty CSV + files. +
+
+
PAN-296977
+
+
+ Fixed an issue where the web interface became unresponsive when + attempting to view + Ethernet interface details after + applying a filter in + Network > Interfaces. +
+
+
PAN-296752
+
+
+ (PA-1410 Firewalls only) Fixed an issue where + the firewall experienced high management CPU usage and repeatedly + rebooted when attempting to retrieve SMART data. +
+
+
PAN-296749
+
+
+ Fixed an issue where email alerts sent from the firewall were marked + as spam due to the EHLO header containing only the firewall hostname + and not the fully qualified domain name (FQDN). +
+
+
PAN-296694
+
+
+ Fixed an issue where the firewall rebooted due to the + useridd + process repeatedly restarting during an IP-port data type writes to + the redis from multiple sources such as TSA or XML in a scale + environment. +
+
+
PAN-296666
+
+
+ Fixed an issue where Prisma Access gateways did not pass usernames to + the WildFire portal, which caused the + Recipient User ID to display as + unknown on + wildfire.paloaltonetworks.com, even when the username was present in + the gateway logs. +
+
+
PAN-296635
+
+
+ Fixed an issue where the + reportd + process on passive Panorama management servers leaked memory due to + scheduled report handling from the Strata Logging Service (SLS). This + memory leak occurred daily, consuming available memory until the + process was restarted. +
+
+
PAN-296616
+
+
+ Fixed an issue where, when a PBF policy rule with a monitoring profile + was configured, the intermediate firewall dropped the PBF monitoring + traffic, which caused the PBF rule to remain disabled on the local + firewall. +
+
+
PAN-296598
+
+
+ Fixed an issue where EAL logs were not forwarded to the IoT Security + dashboard when the proxy server password contained special characters. +
+
+
PAN-296535
+
+
+ Fixed an issue on the firewall where BGP peers disconnected when more + than 500 BGP neighbors were configured in a single Logical Router +
+
+
PAN-296490
+
+
+ (Firewalls with FIPS-CC mode enabled only) + Fixed an issue where Panorama on GCP lost access to management + interface after an hour of uptime. +
+
+
PAN-296478
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10, + GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute + JavaScript links, resulting in an authorization error. This occurred + because the firewall was incorrectly injecting text into URLs when + JavaScript buttons or dropdown menus were clicked within the + Clientless VPN portal. +
+
+
PAN-296453
+
+
+ Fixed an issue where decryption exclusion lists were not working for + untrusted certificates, and SSL sessions were still being decrypted + even after adding them to the exclusion list. This occurred because + the firewall was not adding sessions to the exclude cache until after + receiving a non-RFC alert (BadCertificate) from the server. The fix + ensures that the first session is added to the exclude cache, allowing + subsequent sessions to skip decryption. This issue affects firewalls + configured as clients in server-client communication. +
+
+
PAN-296452
+
+
+ Fixed an issue where, when Panorama manages Prisma Access, filtering + GlobalProtect logs by IPv6 subnets displays all logs, including IPv4 + logs. +
+
+
PAN-296443
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the firewall had a lower maximum capacity for DIPP translated IP + addresses than the PA-5260, which caused configuration commit errors + during migration. With this fix, the maximum capacity on PA-5450 + firewalls has been increased to 8000. +
+
+
PAN-296397
+
+
+ Fixed an issue on the Panorama web interface where previewing changes + after a commit to shared objects were not accurately displayed in the + push scope. +
+
+
PAN-296283
+
+
+ Fixed an issue where, on hardware platforms with the SaaS inline + license, Additional Header Logging (AHL) hash table creation proceeded + even when the feature was disabled through the CLI, potentially + leading to crashes. +
+
+
PAN-296224
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where adding a 26th floating IP address to an + aggregate interface on one vsys caused IPSec tunnels in another vsys + to stop working due to rekeying issues. +
+
+
PAN-296208
+
+
+ Fixed an issue where the firewall did not accept address groups in the + filter condition of a Log Forwarding Match list. +
+
+
PAN-296206
+
+
+ Fixed an issue where the firewall incorrectly routed external Type-5 + Link State Advertisements (LSAs) within a stub area when the firewall + was configured as an Area Border Router (ABR) in a stub area and + learned about an external prefix from another ABR connected to the + backbone area. +
+
+
PAN-296202
+
+
+ (Firewalls in active/active HA configurations only) Added a log enhancement to capture an issue where, when a commit + operation was in progress, newly deployed IP address tags that used + the XML API were not immediately reflected in address group + resolution, which delayed IP address mapping to address groups and + caused traffic to be incorrectly allowed or denied. +
+
+
PAN-296195
+
+
+ Fixed an issue where, in an SD-WAN Branch Multi-VR environment, ping + traffic initiated from the firewall's internal interface resulted in + improper zone mapping during session setup, which resulted in the + firewall being unable to reach the internet. This occurred due to the + ingress zone being incorrectly used as the egress zone. +
+
+
PAN-296020
+
+
+ Fixed an issue where commit operations failed during phase 1 when + configuring a non-default value for the Graceful Restart Hello Delay + due to an FRR parse error if the configured value was between 1 and 9. +
+
+
PAN-295958
+
+
+ Fixed an issue where multicast output interfaces (OIFs) were missing + for up to 5 minutes after an HA failover or routing process restart, + which impacted new multicast sessions. This occurred due to an age-out + process triggered by unicast graceful restart conditions. +
+
+
PAN-295951
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where + CLI outputs incorrectly included XML formatting. +
+
+
PAN-295944
+
+
+ Fixed an issue where static routes remained active in the FIB and RIB + even when the associated physical port interface was down, which + resulted in traffic being incorrectly routed through a non-operational + interface. +
+
+
PAN-295899
+
+
+ Fixed an issue where DNS resolution failed on Linux machines running + GlobalProtect client version 6.2.6 when connected with DNS Security + enabled. This occurred because the firewall incorrectly discarded DNS + packets when processing multiple DNS requests or responses over the + same session, even when no malicious verdict was received. +
+
+
PAN-295854
+
+
+ Fixed an issue where the firewall generated two URL logs for a single + session. +
+
+
PAN-295838
+
+
+ Fixed an issue on IKEv1 tunnels where, if the peer IKE gateway was + unreachable, the IKE Phase-1 Security association (SA) was not cleared + by DPD until Phase-2 rekeying occurred or until it was manually + cleared via the CLI because the DPDs were not sent accurately + according to the configured interval due to a miscalculation of the + DPD timer. This resulted in the tunnel taking longer than expected to + recover. +
+
+
PAN-295812
+
+
+ Fixed an issue where the throughput data on the Switch Card Module + (SCM) was not accurately reported. This issue affected Standard SC + USABN and USABN-2 when using Direct-IO deployment. +
+
+
PAN-295803
+
+
+ Addressed a memory leak issue under sc3 and automatic commit recovery + (ACR) code path. +
+
+
PAN-295802
+
+
+ Fixed an issue where a memory leak related to the + configd + process occurred. +
+
+
PAN-295796
+
+
+ Fixed an issue where the firewall intermittently failed to forward + VXLAN GARP packets, which led to connectivity issues for wireless + clients in environments that used VXLAN tunnels for wireless access + points. +
+
+
PAN-295766
+
+
+ (VM-Series firewalls in HA configurations only) + Fixed an issue where Panorama displayed incorrect packet buffer values + on the web interface and the CLI. +
+
+
PAN-295728
+
+
+ Fixed an issue where configuring an OSPFv2 NSSA area range caused + OSPF-learned routes to become unreachable due to the incorrect + installation of a discard route when the NSSA range prefix matched an + existing OSPF route. +
+
+
PAN-295662
+
+
+ Fixed an issue where Panorama displayed the URL instead of the file + name for vulnerability threat logs fetched from the Logging Service. +
+
+
PAN-295644
+
+
+ Fixed an issue where Strata Logging Service (SLS) log forwarding + streams intermittently displayed as inactive. +
+
+
PAN-295586
+
+
+ Fixed an issue where, after committing changes to a Certificate + Profile or other global configurations without any making changes to + the virtual system (vsys), the Data Redistribution include/exclude + lists were ignored on the firewall. This resulted in the firewall + receiving and processing User-ID information from all sources. +
+
+
PAN-295578
+
+
+ Fixed an issue where GlobalProtect HIP data file download and + installation failed with the error message + An error occurred while processing request. Please try again after + some time or contact support + or No ETAG from response due to a + script exiting prematurely. +
+
+
PAN-295560
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors, + tunnel logs were not visible in Panorama or Splunk even though traffic + and threat logs were received. +
+
+
PAN-295484
+
+
+ Fixed an issue where SD-WAN did not generate system logs with + timestamps and reasons for degradation of Direct Internet Access + paths. +
+
+
PAN-295470
+
+
+ Fixed an issue on the firewall where the + useridd + process continuously increased its memory consumption, which resulted + in an OOM condition that caused the firewall to restart. +
+
+
PAN-295421
+
+
+ Fixed an issue where the CLI command outputs incorrectly included XML + formatting tags. +
+
+
PAN-295385
+
+
+ Fixed an issue where syslog forwarding dropped due to FQDN resolution + failures. +
+
+
PAN-295342
+
+
+ Fixed an issue where the + pan_comm + process stopped responding due to insufficient time allocated to read + file descriptors when processing long messages. +
+
+
PAN-295257
+
+
+ Fixed an issue where, after onboarding a firewall to Panorama, IPsec + tunnels displayed IKEv2 in Panorama, even though the tunnels were + configured with IKEv1 locally on the firewall. +
+
+
PAN-295245
+
+
+ Fixed an issue where the + useridd + process stopped responding because the client was unavailable. +
+
+
PAN-295240
+
+
+ Fixed an issue where the source user field was intermittently missing + in traffic logs, even when the IP address-to-user mapping was + available. This occurred due to a race condition where the log + generation process preceded the creation of the IP address-to-user + mapping. +
+
+
PAN-295221
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors from + PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not + forwarded to a Splunk server over UDP. +
+
+
PAN-295185
+
+
+ (Panorama appliances only) Fixed an issue where + a custom administrator role with the permission + Network > QoS (Read Only) was + unable to create a QoS profile, even when the + Policies > QoS (Enabled) and + Network Profiles > QoS Profile (Enabled) + permissions were also set. +
+
+
PAN-295095
+
+
+ Fixed an issue where, when you used a syslog forwarding profile with + the CEF format, an additional string was appended to the end of the + log message when viewing the log entry from the Universal Forwarder + directory. +
+
+
PAN-294898
+
+
+ (Panorama appliances only) Fixed an issue + where, when performing device software deployment to dedicated log + collectors, the Validate option did + not display the required software versions. Additionally, attempting + to download images to multiple log collectors simultaneously failed. +
+
+
PAN-294893
+
+
+ Fixed an issue where firewalls with the + Send handshake messages to CTD for inspection + setting enabled caused incorrect security policy rules to be matched + during the TLS handshake. Additionally, the expected response page for + blocked URLs was not displayed. +
+
+
PAN-294770
+
+
+ (Firewalls in active/passive HA configurations) + Fixed an issue on firewalls where, after failover, certain subnets + were missing from the Link State Database, which prevented OSPF routes + from being immediately learned due to a Type-7 to Type-5 LSA + translation conflict in the ABR when the same LSA was advertised by + two peers in the NSSA area. +
+
+
PAN-294524
+
+
+ Fixed an issue where firewalls and Panorama management servers were + unable to view or download WildFire reports from a WF-500 appliance, + resulting in a 401 error in the report tab. +
+
+
PAN-294379
+
+
+ Fixed an issue where, when SD-WAN SaaS Application path monitoring + failed for all interfaces, the firewall stopped forwarding traffic + even if the ISP links and default gateway probing were still active. +
+
+
PAN-294307
+
+
+ Fixed an issue on Panorama where a + configd + SIGSEGV crash occurred when renaming objects within policy rules, + objects, or zones. +
+
+
PAN-294191
+
+
+ Fixed an issue where BGP did not generate a system log when the number + of prefixes received from a peer exceeded the configured threshold, + even with the Address Family Identifier and Peer Group settings + configured to trigger a warning. +
+
+
PAN-294179
+
+
+ Fixed an issue where viewing, refreshing, and comparing config + versions in Config Audit caused the + configd + process to stop responding. If the page loaded successfully, some + commit versions displayed incorrect or missing data. +
+
+
PAN-294161
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to the + useridd + process restarting and causing an HA failover. This occurred due to + the + configd + process timing out when running the CLI command + show user user-id-agent config all. +
+
+
PAN-294123
+
+
+ Fixed an issue where the firewall removed all Infrastructure and Audit + logs, as well as logdb and search + engine quotas, when the configured retention period was reached + instead of only removing logs older than the configured retention + period. +
+
+
PAN-293985
+
+
+ Fixed an issue with the Panorama web interface where admin users were + unable to log in and received the error message + 504: Gateway Timeout. +
+
+
PAN-293953
+
+
+ Fixed an issue where the cellular interface LED indicator incorrectly + displayed a green light when the cellular interface was down due to a + failed packet data session. +
+
+
PAN-293879
+
+
+ Fixed an issue on the firewall where the VM monitor source remained in + the Getting All status, which + prevented dynamic address groups from updating IP addresses for new + EC2 instances. This issue occurred due to a race condition where two + threads that simultaneously retrieved IP address tag information from + AWS VM monitoring sources became stuck while reading the XML file. +
+
+
PAN-293877
+
+
+ (Firewalls with Hub vsys (virtual system) configurations enabled + only) Fixed an issue where, when using the Hub vsys feature to + redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP + policy enforcement failed intermittently on the active secondary + firewall. This occurred when traffic destined for specific non-Hub + vsys was routed to the active secondary, and the HIP query was not + triggered due to an incorrect check for the HIP mask in the Hub vsys. +
+
+
PAN-293858
+
+
+ Fixed an issue where the file URL was not displayed on SCM LogViewer + when a file was downloaded. This issue affected logs with a subtype of + 'file'. +
+
+
PAN-293848
+
+
+ Fixed an issue where Panorama failed to push the default value of + None for the secondary NTP server + address to managed firewalls, resulting in a commit validation error. + This occurred even when configuring the secondary NTP server address + as None in Panorama's web interface, + and affected both newly deployed and long-standing production + firewalls after upgrading. +
+
+
PAN-293847
+
+
+ Fixed an issue where EAL logs for traffic matching the + intrazone-default security rule were not forwarded to the IoT Security + portal. +
+
+
PAN-293825
+
+
+ Fixed an issue where packets with bad TCP checksums were transmitted + even when the + Strict TCP/IP checksum option was + enabled. +
+
+
PAN-293708
+
+
+ Fixed an issue where the + configd + process stopped responding when a partial revert operation was + performed on a newly added rule in a rulebase that was empty in the + running configuration. +
+
+
PAN-293707
+
+
+ Fixed an issue where the + iotd + process failed to install DPI Cloud server FQDN due to a configuration + parsing failure, caused by the configuration XML memory buffer not + being NULL terminated. This resulted in the accumulation of EAL logs + and DLP forwarding being stopped. +
+
+
PAN-293686
+
+
+ Fixed an issue where importing a device state file was incorrectly + allowed during an existing commit job. +
+
+
PAN-293673
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM + condition caused by a scheduled log export using FTP to an external + FTP server. +
+
+
PAN-293644
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the + configd + process stopped responding during an External Dynamic List (EDL) + refresh. +
+
+
PAN-293574
+
+
+ Fixed an issue on Panorama where Global Find returned incomplete and + inconsistent search results. +
+
+
PAN-293561
+
+
+ Fixed an issue where users with a custom role-based administrator role + were unable to download the GlobalProtect client application via the + web interface even when the + GlobalProtect Client option was + enabled in the admin role profile. +
+
+
PAN-293533
+
+
+ Fixed an issue where, in KVM environments, traffic did not work as + expected on Mellanox CX5 interfaces during multinic runs. +
+
+
PAN-293511
+
+
+ Fixed an issue where renaming a BGP filtering profile in Panorama does + not update the corresponding BGP peer group in the virtual router, + leading to commit failures. +
+
+
PAN-293440
+
+
+ Fixed an issue where setting the + logdb-quota for the + desum log type to + 0 caused the /opt/panlogs + partition to reach capacity. +
+
+
PAN-293428
+
+
+ Fixed an issue where the interval of IKEv1 Dead Peer Detection (DPD) + R-U-THERE packets did not correspond to the configured value in the + IKE Gateway profile due to using the value configured for retry + instead. +
+
+
PAN-293297
+
+
+ Fixed an issue on Panorama where a full push to device groups was + initiated instead of a selective push when using + Commit and Push Changes Made By in + the commit and push. +
+
+
PAN-293281
+
+
+ Fixed an issue where the reported throughput and packet rate were + higher than the actual interface traffic due to a double counting + error. +
+
+
PAN-293033
+
+
+ Fixed an issue on Panorama where + Push was disabled during a Selective + Push operation. +
+
+
PAN-292980
+
+
+ Fixed an issue on the web interface where the + Connected status for a User-ID agent + in a non-User-ID Hub vsys displayed as blank if the same agent was + also configured in a User-ID Hub vsys. +
+
+
PAN-292752
+
+
+ Fixed an issue where a command injection vulnerability could occur due + to improper input sanitization. +
+
+
PAN-292580
+
+
+ (Panorama appliances only) Fixed an issue where + the software deployment validation process did not display the + required software version for dedicated log collectors (DLCs), and + downloading software images to multiple DLCs failed. +
+
+
PAN-292539
+
+
+ (CN-Series firewalls only) Fixed an issue where + the firewall generated incomplete or corrupted tech support files + (TSF) due to high disk usage on the management plane. +
+
+
PAN-292529
+
+
+ Fixed an issue where HA configuration synchronization failed between + HA firewalls due to an empty interface node present only in the + passive firewall's running-config.xml file. +
+
+
PAN-292471
+
+
+ Fixed an issue where the default route (0.0.0.0/0) advertised via the + Originate Default Route in BGP AFI + profiles did not appear in the output of the + show advanced-routing bgp peer advertised-routes + CLI command, even though it was being sent to the BGP peer. +
+
+
PAN-292447
+
+
+ Fixed an issue where Panorama did not display data in the + Feature Adoption tab in Strata Cloud + Manager due to the system creating and deleting a CLI user for each + interval instead of reusing a permanent CLI user for telemetry. +
+
+
PAN-292393
+
+
+ Fixed an issue where TFTP file transfers intermittently timed out in + active-active HA pairs when the TFTP control channel was processed by + one firewall and the data channel was processed by the other. This + occurred because the firewall receiving the data channel failed to + match the predicted session due to asynchronous processing of HA + messages. +
+
+
PAN-292285
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where network outages of approximately 30 seconds + occurred after a failover due to a delay in establishing the BGP + connection between the new active firewall and one of its peers and a + second delay in advertising prefixes learned from the firewall to + another peer. +
+
+
PAN-292242
+
+
+ Fixed an issue on M-200 and logging appliances where traffic logs were + intermittently truncated when forwarded using a TCP syslog + configuration. This issue occurred during the log forwarding stage due + to intermittent syslog drops caused by exceeding the forwarding queue + capacity. +
+
+
PAN-292228
+
+
+ Fixed an issue where, after configuring dual stack GlobalProtect with + both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with + the error message + flow-basic error; packet dropped, tunnel resolution failure. +
+
+
PAN-292079
+
+
+ (Panorama appliances only) Fixed an issue where + the data on scheduled SaaS Application Usage Reports was different + than the data on on-demand reports generated via + Run Now. +
+
+
PAN-292019
+
+
+ Fixed an issue on the Panorama web interface where cloud applications + were not displayed under + Objects > Applications after a + new content upgrade and Cloud App Catalog download, and were only + visible in application groups, security policy rules, and the CLI. +
+
+
PAN-291984
+
+
+ Fixed an issue where SSH/SFTP traffic was intermittently blocked by + URL filtering due to the firewall incorrectly applying URL categories + from previous sessions. +
+
+
PAN-291945
+
+
+ Fixed an issue on PA-5220 firewalls where denied traffic logs + incorrectly displayed a byte count of 0. This occurred because the + bytes_sent value was stored in the most significant bits of + u_bytes_sent, resulting in a zero value when a small value was + assigned to u_bytes_sent. +
+
+
PAN-291940
+
+
+ Fixed an issue where the firewall established multiple TCP connections + to a syslog server, which caused logs to be dropped. This occurred + because the firewall established a new TCP session for each transfer + and the sessions were not closed, which resulted in a continuous + increase in connections over time. +
+
+
PAN-291915
+
+
+ Fixed an issue on the firewall where the PDT process experienced a + memory leak due to frequent dumping of fabric traffic statistics, + which resulted in high CPU utilization and instability. +
+
+
PAN-291804
+
+
+ Fixed an issue on Panorama where deleting objects resulted in errors + indicating references in Security policy rules. +
+
+
PAN-291792
+
+
+ (PA-7050 firewalls on vwire instances only) + Fixed an issue where Bidirectional Forwarding Detection (BFD) echo + packets were dropped due to the firewall dropping packets with the + same source and destination IP addresses. +
+
+
PAN-291781
+
+
+ Fixed an issue on Panorama where the CLI command + show ntp displayed the error + message + server error: op command for client dagger timed out as client is + not available + even when connectivity to the NTP server was active. +
+
+
PAN-291716
+
+
+ Fixed an issue where during a commit, the firewall experienced an + out-of-memory (OOM) condition due to a memory leak and displayed an + error message. This issue caused the device to stop responding and + reboot unexpectedly. +
+
+
PAN-291661
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after + an upgrade, Elasticsearch intermittently entered into a Red state + before automatically recovering. +
+
+
PAN-291653
+
+
+ Fixed an issue where the GlobalProtect host ID field was + intermittently blank in traffic logs on Prisma Access, even when the + user was connected and had the correct host ID information. This + occurred when the IP address to host ID entry expired and the entry + was re-inserted without the dataplane flag being set. +
+
+
PAN-291650
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to an OOM + condition. +
+
+
PAN-291635
+
+
+ Fixed an issue where cookie surrogate cache entries remained + unresolved after an + idmgr + process reset due to the request not being retransmitted. This + occurred because the timestamp in the cache entry was refreshed even + when the UID was 0, which prevented the retransmission of the request + if the initial response was not received. +
+
+
PAN-291247
+
+
+ Fixed an issue where checksum values changed when downloading files + through TFTP on firewalls using subinterfaces. +
+
+
PAN-291174
+
+
+ Fixed an issue where Real Time Streaming Protocol (RTSP) video streams + did not work when connected through GlobalProtect due to the firewall + blocking 200 OK responses. This occurred because of incorrect NAT + translations for the 200 OK message from the server. +
+
+
PAN-291067
+
+
+ Fixed an issue where the + devsrvr + process periodically exceeded its virtual memory limit and restarted, + which led to intermittent outages. +
+
+
PAN-291009
+
+
+ Fixed an issue where, after a web server returned a 401 or 403 error, + the firewall was unable to decrypt HTTP/2 traffic, and the firewall + rejected all subsequent streams from the client. +
+
+
PAN-290954
+
+
+ Fixed an issue where the web server used a low HTTP Strict Transport + Security (HSTS) max-age value of 86400 seconds for the + log.query.expression.js.php page. +
+
+
PAN-290948
+
+
+ Fixed an issue where the proxy hid the Cache-Control header, which + prevented context switching. +
+
+
PAN-290938
+
+
+ Fixed an issue where multiple memory leaks occurred related to the + configd + process. +
+
+
PAN-290851
+
+
+ Fixed an issue where the Agent User Override Key was incorrectly + available for configuration on Panorama management servers when + running in FIPS-CC mode. +
+
+
PAN-290783
+
+
+ Fixed an issue where the + debug dataplane nat sync-ippool + command may not accurately account for all allocated ports or + display/sync leaks when multiple NAT rules use the same IP pool. This + could result in inaccurate reporting of leaked ports. The fix modifies + the implementation to directly compare the original pool against the + temporary pool across all vsys. +
+
+
PAN-290728
+
+
+ Fixed an issue where modifying an interface IP address on an existing + vsys caused a default vsys1 to be + created, which led to commit failures due to the maximum supported + number of vsys being reached. +
+
+
PAN-290681
+
+
+ Fixed an issue on Panorama and Panorama managed firewalls where + template settings reverted during a device group push when + Include Device and Network Templates + was checked, even if no changes were made to the template. This caused + the SAML IDP server profile certificate to revert to an older, invalid + certificate, and resulted in GlobalProtect users being unable to + authenticate via SAML. +
+
+
PAN-290665
+
+
+ Fixed an issue with firewalls enabled with Security profiles where + certain traffic conditions caused high dataplane CPU utilization and + packet buffer exhaustion, which caused LACP flapping conditions. +
+
+
PAN-290663
+
+
+ (Panorama managed firewalls in HA configurations only) Fixed an issue where the firewall did not enforce serial number + validation during HA deployment or replacement, which resulted in + pairs being established even when the serial numbers configured on + Panorama did not not match the serial number of the devices. +
+
+
PAN-290640
+
+
+ (VM-Series firewalls on Microsoft Azure environments in HA + configurations only) Fixed an issue where, when an interface was configured with IPv6, + the firewall displayed the message + Unknown error during validation + after the client secret expired, which caused DNS resolution to fail + when resolving FQDNs and HA failovers to occur. +
+
+
PAN-290449
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports + were sent in the same email, only the first attached report was + displayed. +
+
+
PAN-290157
+
+
+ Fixed an issue on Panorama where the + configd + process stopped responding when filtering in the + Config Audit window, which caused + Panorama to restart unexpectedly. +
+
+
PAN-289852
+
+
+ Fixed an issue where websites did not load when accumulation proxy was + enabled. +
+
+
PAN-289757
+
+
+ Fixed an issue where policy rule imports were blocked when + any was in the source device column, + which prevented the use of inbound policy rule recommendations. + Additionally, when the source profile name was missing for inbound + behaviors, a default policy rule name was not able to be generated. +
+
+
PAN-289736
+
+
+ Fixed an issue where partial-revert operations were taking a long + time, causing config lock timeout issues and resulting in frequent + error messages being displayed: + Timed out while getting config lock. Please try again. +
+
+
PAN-289723
+
+
+ Fixed an issue where the firewall web interface continuously loaded + and not display any output when viewing the Route Table or FIB table + (More Runtime Stats). This issue + occurred when L3 configurations were added to ethernet and AE + interfaces. +
+
+
PAN-289706
+
+
+ Fixed an issue where the + authd + process crashed intermittently on VM-Series firewalls due to + authentication sequence failures. The crashes occurred during memory + management operations within a library while releasing memory to its + central cache. +
+
+
PAN-289578
+
+
+ Fixed an issue on Panorama managed firewalls where the source user, + source device vendor, source MAC address, and OS version information + were not visible in traffic logs and SCM when the user and device + access control lists were empty. +
+
+
PAN-289249
+
+
+ Fixed an issue where a memory leak occurred on the + reportd + process when a WildFire update was initiated while device telemetry + data collection was in progress. This resulted in an OOM condition. +
+
+
PAN-289067
+
+
+ Fixed an issue where, after upgrading Panorama in a High Availability + (HA) pair, the configuration logs stopped synchronizing from the + primary Panorama to the secondary Panorama. This issue occurred + because the log forwarding flag was permanently disabled due to the + connection state not being active when the + log-fwd-ctrl message was + received. +
+
+
PAN-288938
+
+
+ Fixed an issue on the Panorama web interface where the search bar + suddenly was not displayed, or the filter/clear filter icon moved to + the left of the search bar. +
+
+
PAN-288869
+
+
+ Fixed an issue where custom administrators with visibility into + specific vsys logs were able to view logs for all vsys. +
+
+
PAN-288388
+
+
+ Fixed an issue where, after an EDL certificate update or repository + migration, authentication failures caused the firewall to not fall + back to the last successfully cached EDL entries, which led to policy + rules that referenced the EDL to not be enforced. +
+
+
PAN-288381
+
+
+ Fixed an issue where data interfaces unexpectedly went down and then + up after an HA failover, which caused intermittent traffic disruption. +
+
+
PAN-288175
+
+
+ Addressed a stack buffer overflow memory leak under plugin management + code path. +
+
+
PAN-288141
+
+
+ Fixed an issue where the + debug data-plane sync ippool CLI + command did not work for Per Destination IP Pool (PDIPP) and caused a + memory leak. +
+
+
PAN-288139
+
+
+ Fixed an issue where the firewall incorrectly identified ports as + leaking when the session was not active even though the ports were + allocated. +
+
+
PAN-287803
+
+
+ Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1, + certain websites weren't accessible when the accumulation proxy was + enabled. The proxy did not use the same DF bit state as the original + traffic, causing it to be fragmented and dropped elsewhere in the + network. +
+
+
PAN-287782
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP + values from AF11 to CS0 on traffic passing through the firewall, even + when QoS policy rules and DSCP rewrite settings were not configured. +
+
+
PAN-287713
+
+
+ Fixed an issue on Panorama where, after uninstalling a plugin, commit + validation failed with the error message + interface '-' is not a valid reference + due to cloud service plugin configuration errors. +
+
+
PAN-287693
+
+
+ Fixed an issue where Panorama did not use the configured proxy + settings to check WildFire private cloud content and instead connected + directly to the WildFire device using the management interface. This + occurred even when + Use Proxy Settings for Private Cloud + was enabled. +
+
+
PAN-287599
+
+
+ Fixed an issue where the prefix value for a BGP neighbor caused the + firewall to leak routes to a different BGP peer. +
+
+
PAN-287581
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall did not process and transmit HA + path monitoring probes received from another HA cluster when the + firewall acted as a gateway for internal monitoring IP addresses used + in the HA path monitoring group, which caused HA flapping due to path + monitoring failures. +
+
+
PAN-287392
+
+
+ Fixed the issue on the web interface where + ACC graphs displayed + No data to display when a filter was + applied to Source IP or + Destination IP. +
+
+
PAN-287387
+
+
+ Fixed an issue on Panorama where API jobs failed with the error + message + Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a + large number of address objects in a single set call. +
+
+
PAN-287165
+
+
+ Fixed an issue on the firewall CLI where autocomplete did not work for + zones in the + clear session all CLI command. + Additionally, the CLI was unable to clear sessions for a specific IP + subnet. +
+
+
PAN-287086
+
+
+ Fixed an issue where PA-3420 firewalls experienced unexpected reboots + due to the + all_task_7 + process crashing with signal 6, leading to a non-functional state. +
+
+
PAN-287034
+
+
+ Fixed an issue where sequence numbers were skipped for all types of + logs on the firewall due to audit logs being generated but not written + to disk when Audit Tracking was enabled. +
+
+
PAN-286865
+
+
+ Fixed an issue where, when you upgraded log collectors via Panorama + (Device Deployment), the software + installation on the log collector remained at 0%. +
+
+
PAN-286297
+
+
+ Fixed an issue where the firewall did not respond to ARP requests when + a subinterface was configured with source address translation using + the Translated Address option. +
+
+
PAN-285758
+
+
+ Fixed an issue where the firewall web interface became unresponsive + while adding a description that contained 1062 bytes of character data + in a Security policy rule instead of displaying an error message when + the description exceeded the maximum allowed length. +
+
+
PAN-285208
+
+
+ Fixed an issue where the firewall did not automatically recover after + a machine check exception (MCE) occurred. +
+
+
PAN-285181
+
+
+ Fixed an issue where the wifclient ran out of memory when Enhanced + Application Logging was enabled and a sudden traffic increase caused a + surge in EAL messages sent through WIF. +
+
+ To use this fix, run the CLI command + debug iot eal memory-gc native +
+
+
PAN-285169
+
+
+ Fixed an issue on Panorama where Kerberos superusers were unable to + edit policy rules because the target device tab was grayed out. +
+
+
PAN-284801
+
+
+ Fixed an issue where the OpenConfig plugin was automatically installed + on VM Panorama and firewalls after upgrading. +
+
+
PAN-284417
+
+
+ Fixed an issue where proxied traffic was shown as decrypted even when + no applicable decryption policy rule was configured. Additionally, the + show session CLI command and the + session browser web interface incorrectly displayed cleartext proxy + sessions as decrypted. +
+
+
PAN-283704
+
+
+ Fixed an issue where the PAN-OS DoS protection feature by default + blacklisted specific IP addresses, which caused outbound traffic + domain resolution to fail for clusters. +
+
+
PAN-283311
+
+
+ Fixed an issue where log forwarding to all syslog servers failed if + one syslog server that used TLS as the protocol became unreachable. +
+
+
PAN-283237
+
+
+ Fixed an issue where traffic logs incorrectly displayed the action as + allow for traffic matching a + Security policy rule configured with the action set to + deny. This issue occurred due to the + child session being used for policy rule lookup when a configuration + update triggered a rematch if the FTP-data application was not in the + rule. +
+
+
PAN-283101
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the + show wildfire status CLI command + displayed an incorrect maximum file size of 4 KB for WildFire script + uploads even though the configured value was different. +
+
+
PAN-283053
+
+
+ Fixed an issue where the firewall experienced high disk space + utilization, which caused the firewall to become non-functional. +
+
+
PAN-282961
+
+
+ Fixed an issue where the firewall rebooted unexpectedly after a commit + due to a memory leak related to the + rasmgr + process and displayed the error message + Management server failed to send phase 1 to client l2ctrld + before rebooting. +
+
+
PAN-282956
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 and later PAN-OS + releases where the portal and gateway configuration view did not + display rows and columns. +
+
+
PAN-282687
+
+
+ Fixed an issue on Panorama where performing a selective revert of + configuration changes resulted in all configuration changes being + reverted. +
+
+
PAN-281721
+
+
+ Fixed an issue where the firewall generated high-severity system + alerts indicating that the configuration size exceeded the maximum + recommended size, even when the configuration size was within the + expected limits. +
+
+
PAN-281588
+
+
+ Fixed an issue where packet buffer depletion occurred due to the a + high number of + tcp_pkt_queued packets when Jumbo + was enabled. +
+
+
PAN-280917
+
+
+ Fixed an issue on Panorama where the WildFire cloud URL contained an + extra period character, which prevented the retrieval of WildFire + analysis reports. +
+
+
PAN-280536
+
+
+ Fixed an issue where firewalls that were connected to the same Cloud + Identity Engine displayed inconsistent group membership information, + with some firewalls showing only a subset of users belonging to a + group. This occurred due to a full or incremental group sync failure. +
+
+ This fix introduces a retry mechanism for failed group queries to the + Cloud Identity Engine. To use this feature, run the following CLI + commands. +
+
+ To enable the retry mechanism: + debug user-id dscd retry-enable on. +
+
+ To set the retry time: + debug user-id dscd retry-time set-time <1-10>. The default value is 5 seconds. +
+
+ To set the number of retry attempts: + debug user-id dscd retry attempts set-attempts <3-10>. The default value is 5 attempts. +
+
+ To disable the retry mechanism: + debug user-id dscd retry-enable off. +
+
+ Additionally, a system log is now generated when a group sync fails, + and you are able to monitor the group sync status with the following + CLI commands: +
+
    +
  • + show user group count list cloud-identity-engine +
  • +
  • + show user group count name <group_name> +
  • +
+
+
PAN-279699
+
+
+ Fixed an issue on M-600 line cards where the /var/log/messages file + flooded with + i40e 0000:81:00.1: ARQ: Unknown event 0x0000 ignored + messages, causing the root partition to fill up and prevent PAN-OS + upgrades. +
+
+
PAN-278688
+
+
+ Fixed an issue where DNS Security threat logs were not displayed on + the firewall when packet capture was enabled and the domain name + length was 62 characters. +
+
+
PAN-278611
+
+
+ Fixed an issue on Panorama where software images were not purged from + the /opt/pancfg/mgmt/sw-images folder. +
+
+
PAN-277971
+
+
+ Fixed an issue where the PA-5220 firewall reports inaccurate NetFlow + statistics for DNS flows after upgrading to PAN-OS 10.2.13. +
+
+
PAN-277178
+
+
+ Fixed an issue on Panorama where you were unable to delete a shared + object due to the rulebase incorrectly referencing the shared object + instead of the device group-specific object when the name was used. +
+
+ To use this fix, delete the original shared object after cloning it to + a device group with the same name. +
+
+
PAN-276525
+
+
+ Resolved multiple issues affecting IPSec tunnels using NAT Traversal + (NAT-T) when a Dynamic NAT policy was configured (including Dynamic + NAT or DIPP). During rekey events, tunnels could go down or flap due + to incorrect session handling. This issue impacted both cluster and + standalone deployments. +
+
+
PAN-275050
+
+
+ Fixed an issue where the Japanese translation for the URL filtering + option to add a trailing slash to entries and the device license + status error was incorrect. +
+
+
PAN-274484
+
+
+ Fixed an issue where commits failed when + Data Services was in a Service route + configuration was configured with the + MGMT interface. +
+
+
PAN-273487
+
+
+ Fixed an issue where the + distributord + process restarted on firewalls in multi-vsys environments with User-ID + configured and Panorama as a redistribution client. This occurred when + a large volume of IP address-to-user mappings were learned. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where an incorrect ASIC configuration caused silent packet drops or + application slowness when receiving a mix of jumbo and non-jumbo + packets. +
+
+
PAN-273028
+
+
+ Fixed an issue where manual SCP exports from firewalls in FIPS mode + were successful to SCP servers that were not FIPS-compliant. This + occurred because the manual SCP process did not enforce FIPS security + checks. +
+
+
PAN-272432
+
+
+ Fixed an issue where Panorama and Cortex Data Lake (CDL) logs + displayed incorrect interface names without node IDs for cluster + firewalls. +
+
+
PAN-272245
+
+
+ Fixed an issue where the + dnsproxy + process stopped responding due to memory corruption caused by a race + condition when the allow list downloading was impacted by a + configuration change. +
+
+
PAN-271507
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the DPC on slot 3 intermittently stopped responding due an + all_pktproc + restart. +
+
+
PAN-271239
+
+
+ Fixed an issue where searching for the GlobalProtect client version + browser in Panorama logs returned no results. +
+
+
PAN-268038
+
+
+ Fixed an issue where the + routed process on Orion-ZTNA NGFW + Connectors stopped responding when a destination FQDN path monitor + configuration was present and the + show routing path-monitor CLI + command was executed due to the CLI command handler dereferencing a + null pointer without proper validation. +
+
+
PAN-267965
+
+
+ (Firewalls on Amazon Web Services (AWS) environments only) Fixed an issue where newly bootstrapped firewalls sent an + incorrect, non-DHCP-assigned hostname to the SNMP server. This + occurred because the SNMP process referred to a configuration file + that was not updated due to a missing configuration commit. +
+
+
PAN-267614
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to high CPU utilization on the + mongodb + process. +
+
+
PAN-267450
+
+
+ Fixed an issue where the + reportd + process stopped responding with a SIGSEGV at + schedule_report_es_response. +
+
+
PAN-266843
+
+
+ Fixed an issue on airgapped firewalls where cloud connection errors + flooded the system logs. +
+
+
PAN-265744
+
+
+ Fixed an issue where the firewall repeatedly generated false critical + alerts due to an Intel firmware issue. +
+
+
PAN-264762
+
+
+ Fixed an issue where the firewall showed the status of SFP+ interfaces + as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was + connected. +
+
+
PAN-263691
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a + memory leak in the + all_task + process. +
+
+
PAN-262353
+
+
+ Fixed an issue where, when Panorama was upgraded but log collectors + were on an earlier version, logs from a log collector group were not + viewable on a Panorama. +
+
+
PAN-259853
+
+
+ Fixed an issue where, when the DHCP server was enabled for + GlobalProtect, the commit error message was not properly displayed + when Any was selected as the source + interface in the service router configuration (Device > Setup > Service > Service Router + Configuration). +
+
+
PAN-259785
+
+
+ Fixed an issue where the + devsrvr + process restarted and created a core dump because two threads did not + terminate correctly. +
+
+
PAN-255879
+
+
+ Fixed an issue where the + threat name on the firewall report + PDF was blank. +
+
+
PAN-253504
+
+
+ Fixed an issue where commits did not return an error message when an + invalid Log Forwarding Filter was configured. +
+
+
PAN-250339
+
+
+ Added an improvement to automatically clean up idle HTTP connection + pools to address an issue where idle connection pools accumulated when + a circuit breaker limit was reached, which caused client requests to + fail with a 503 + no_healthy_upstream error. +
+
+
PAN-248913
+
+
+ Fixed an issue where the Elasticsearch client certificate was not auto + renewed, which caused it to enter a Red state, and logs were not + displayed in Panorama. +
+
+
PAN-242952
+
+
+ Fixed an issue where high SSL traffic depleted flex memory, which + prevented the firewall from revalidating SSLVPN client CAs during + configuration pushes. +
+
+
PAN-238208
+
+
+ Fixed an issue where the firewall API returned inconsistent responses + to a failed call using a valid API key. With this fix, the firewall + returns the error + Session is invalid if the session is + not available for the cookie. +
+
+
PAN-237294
+
+
+ Fixed an issue where the interface rate counter intermittently went to + zero frequently. +
+
+
PAN-209516
+
+
+ Fixed an issue where, when creating an interface, an error occurred + when you clicked OK without + providing a value in the Tag field + even though the field was not displayed as mandatory. +
+
+
PAN-185731
+
+
+ Fixed an issue where the firewall was unable to parse the URL path and + host when the host header was located in a different packet, which + resulted in the firewall not logging the URL path in the first packet. +
+
+ The fix is disabled by default. The following CLI commands can be used + to enable/disable the feature: +
    +
  • + set system setting ctd url-crosspkt-host-path-caching + enable +
  • +
  • + set system setting ctd url-crosspkt-host-path-caching + disable +
  • +
  • + set system setting ctd url-crosspkt-host-path-caching + default +
  • +
+
+
diff --git a/reference/PAN-OS/addressed/11.2.2-h1.html b/reference/PAN-OS/addressed/11.2.2-h1.html new file mode 100644 index 0000000..6ba92af --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.2-h1.html @@ -0,0 +1,31 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-263349
+
+
+ Fixed an error in the bundling of software components. +
+
diff --git a/reference/PAN-OS/addressed/11.2.2-h2.html b/reference/PAN-OS/addressed/11.2.2-h2.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.2-h2.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.2.2.html b/reference/PAN-OS/addressed/11.2.2.html new file mode 100644 index 0000000..3c9d1c5 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.2.html @@ -0,0 +1,96 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-258702
+
+
+ (WF-500 appliances only) Fixed an issue where + the + varrcvr + process stopped responding when files were being forwarded to the + WildFire cloud. +
+
+
PAN-255773
+
+
+ Fixed an issue where errors related to applications in + Content-preview caused commit + failures. +
+
+
PAN-248508
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where the firewall did not perform MSS clamping when + GWLB endpoints were mapped to static subinterfaces. +
+
+
PAN-247099
+
+
+ Fixed an issue where the firewall decrypted traffic unexpectedly when + the client hello was spread across multiple packets. +
+
+
PAN-251929
+
+
+ Fixed an issue where inbound decryption did not work when FIPS self + tests were turned on. +
+
diff --git a/reference/PAN-OS/addressed/11.2.3-h3.html b/reference/PAN-OS/addressed/11.2.3-h3.html new file mode 100644 index 0000000..0ad6d60 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.3-h3.html @@ -0,0 +1,87 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
+
PAN-247230
+
+
+ Fixed an issue where the syslog forwarding configuration did not + include the full path for Security policy rules. +
+
+
PAN-259997
+
+
+ (PA-3410, PA-3420, and PA-3430 firewalls only) + Fixed an issue where the install failed when upgrading from PAN-OS + 10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number + of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10. +
+
diff --git a/reference/PAN-OS/addressed/11.2.3-h5.html b/reference/PAN-OS/addressed/11.2.3-h5.html new file mode 100644 index 0000000..e58b800 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.3-h5.html @@ -0,0 +1,95 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-273215
+
+
+ Fixed an issue where a syntax error in the index generation script + caused a high management plane CPU load after upgrading. +
+
+
PAN-271613
+
+
+ Fixed an issue where configuration pushes from Panorama to the + firewall failed due to an OOXML commit error. +
+
+
PAN-269404
+
+
+ Fixed an issue where the firewall did not reset the maximum latency + timer for hold mode. +
+
+
PAN-268823
+
+
+ Fixed an issue where + Monitor > Log Display did not + display all logs when you applied a filter. +
+
+
PAN-264549
+
+
+ Fixed an issue where, after modifying a policy rule on Panorama, + pushes to the Cloud NGFW failed with the error + saas-user-list unexpected here. +
+
+
PAN-259078
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and + the following error message was displayed: + Error 500: Internal Server Error. +
+
diff --git a/reference/PAN-OS/addressed/11.2.3.html b/reference/PAN-OS/addressed/11.2.3.html new file mode 100644 index 0000000..949cab3 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.3.html @@ -0,0 +1,1816 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-263387
+
+
+ Fixed an issue where the firewall web interface was blank after + logging in. +
+
+
PAN-263226
+
+
+ Fixed an issue where decryption based traffic failed on Explicit Proxy + nodes. +
+
+
PAN-262593
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome + web browser on Secure Web Gateway (SWG) nodes. +
+
+
PAN-262287
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred when + App-ID stopped responding caused the firewall to restart. +
+
+
PAN-262013
+
+
+ Fixed an issue where Prisma Access mobile users did not receive + no such name DNS responses from the + firewall and were timed out. +
+
+
PAN-261991
+
+
+ Fixed an issue where traffic that did not match a decryption policy + rule, or matched a no-decrypt policy rule, failed when accumulation + proxy was enabled and a Zone Protection profile was configured with + syn-cookies enabled. +
+
+
PAN-261917
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were + decrypted in the traffic log when using a Google Chrome browser with + PQC enabled. +
+
+
PAN-261797
+
+
+ Fixed an issue where fragmented IP packets were dropped silently. +
+
+
PAN-261270
+
+
+ Fixed an issue where the firewall decremented the TTL/Hop limit for + BGPv6 packets by 1 after IPSec decryption. +
+
+
PAN-260059
+
+
+ Fixed an issue where + Device Telemetry Regions did not + show up with the latest content due to content files not being parsed + for the region list when Telemetry was turned off. +
+
+
PAN-259964
+
+
+ Fixed an issue where the firewall was not able to handle a high + traffic load, which caused some logs to be lost. +
+
+
PAN-259769
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a + web browser and displayed the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-259733
+
+
+ Fixed an issue where a custom report was not deleted on Panorama when + expected. +
+
+
PAN-259480
+
+
+ Fixed an issue where the + varrcvr + process stopped responding after running out of memory due to how the + process queued and dequeued files for WildFire file forwarding when a + WildFire Analysis Security profile was enabled. +
+
+
PAN-259473
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the chassis shut down when FAN1 was removed. +
+
+
PAN-259151
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which + caused configuration pushes to fail with the error + Number of address groups exceed platform capacity. +
+
+
PAN-258442
+
+
+ Fixed an issue where changes made to the split tunnel configuration on + the Prisma Access gateway were not reflected on the GlobalProtect + client. +
+
+
PAN-257957
+
+
+ (Firewalls and Panorama appliances in FIPS-CC mode only) Fixed an issue where the + authd + process restarted if RADIUS PAP/CHAP authentication was used. +
+
+
PAN-257925
+
+
+ (CN-Series firewalls only) Fixed an issue where + the CLI command + show system setting ctd state did + not work as expected. +
+
+
PAN-257624
+
+
+ Fixed an issue where the firewall web interface was blank after + logging in. +
+
+
PAN-257615
+
+
+ Fixed an issue on Panorama where logs did not display or displayed + intermittently on the web interface. +
+
+
PAN-257563
+
+
+ Fixed an issue where the + logrcvr + component for SASE and MCW displayed incorrect zones in the traffic + flow. +
+
+
PAN-257515
+
+
+ Fixed an issue where Possible Domain Fronting Detection for HTTP/2 + generated false positives. With this change, domain fronting is + limited to HTTP/1. +
+
+
PAN-257462
+
+
+ Fixed an issue related to the + varrcvr + process where the management plane CPU was higher than expected. +
+
+
PAN-257432
+
+
+ Fixed an issue on Panorama where the + reportd + process stopped responding, which caused a log query issue. +
+
+
PAN-257390
+
+
+ (PA-5250 firewalls only) Fixed an issue where + the + logrcvr + process stopped responding due to a segmentation fault. +
+
+
PAN-257355
+
+
+ Fixed an issue where a false positive HTTP/TLS evasion alert was + generated when the domain had DNS load balance. +
+
+
PAN-257197
+
+
+ Fixed an issue where ifType and + ifSpeed were not populated in + asynchronous mode of SNMP operations. +
+
+
PAN-256939
+
+
+ Fixed an issue on the firewall where disk space was low in + /opt/pancfg/, which caused + dynamic content installation to fail. +
+
+
PAN-256765
+
+
+ Fixed an issue where you were unable to push variables from Panorama + in service routes for non-cluster templates. +
+
+
PAN-256738
+
+
+ (VM-Series firewalls in HA configurations only) + Fixed an issue where BGP routes from the active firewall were lost + when the passive firewall was rebooted. +
+
+
PAN-256666
+
+
+ Fixed an issue where the + configd + process stopped responding when + Commit and Push operations were + performed on multiple device groups. +
+
+
PAN-256385
+
+
+ (CN-Series firewalls only) Fixed an issue where + communication was broken between the management plane and the + dataplane when Anti-Spyware profiles were configured in a Security + policy rule. +
+
+
PAN-256327
+
+
+ (Panorama virtual appliances on Microsoft Azure environments + only) Fixed an issue where the + logd + process repeatedly restarted due to a buffer overflow when generating + a traffic summary from a traffic log. +
+
+
PAN-256249
+
+
+ Fixed an issue on the web interface that occurred when changing the + pre-shared key to a variable (Network > Network Profiles > IKE Gateways). +
+
+
PAN-256223
+
+
+ Fixed an issue where device telemetry log collection filled the root + partition. +
+
+
PAN-256181
+
+
+ Fixed an issue where the management interface and front panel port + interface statistics were not populated in asynchronous mode of SNMP + operations. +
+
+
PAN-255895
+
+
+ Fixed an issue where Panorama administrators with the + Panorama Administrator dynamic + administrator type were not able to create or modify BGP timer + profiles or BGP dampening profiles. +
+
+
PAN-255820
+
+
+ Fixed an issue where the WildFire signature generation check box in + Panorama did not register a change in the configuration. +
+
+
PAN-255711
+
+
+ Fixed an issue where the firewall displayed a malformed request error + when selecting a custom format and clicking + OK on the configuration window due + to the log type + Correlation incorrectly being + displayed (Device > Log Setting - Correlation > Syslog Server Profile + > Custom Log Format > Correlation). +
+
+
PAN-255611
+
+
+ Fixed an issue on the firewall where newly added routes were not + automatically sorted based on subnets when added to a redistribution + profile. +
+
+
PAN-255441
+
+
+ Fixed an issue where BGP-ARE routes were not advertised due to a peer + route map filter. +
+
+
PAN-255396
+
+
+ Fixed an issue where, when using serial number and IP address + authentication, and multiple gateways were configured, the portal + returned the last gateway in the list and disregarded the satellite + assignment by serial number. +
+
+
PAN-255391
+
+
+ Fixed an issue where the firewall was unable to filter logs using the + ISO 8601 timestamp format after upgrading to PAN-OS 11.0.4 or a later + release. +
+
+
PAN-255266
+
+
+ Fixed an issue where you were unable to clone a template stack with + the Pre-Shared Key variable. +
+
+
PAN-255252
+
+
+ Fixed an issue where Panorama administrators with the type Dynamic + were unable to create, modify, or delete BGP Dampening profiles. +
+
+
PAN-255163
+
+
+ (CN-Series firewalls only) Fixed an issue where + the system database key that stored the configuration status of the + dataplane pod was not updated frequently. +
+
+
PAN-254826
+
+
+ Fixed an issue where the firewall stopped responding when processing + traffic. +
+
+
PAN-254629
+
+
+ Fixed an issue on the Management Processing Card where excessive logs + were generated for an error. +
+
+
PAN-254621
+
+
+ Fixed an issue where the firewall frequently rebooted due to the + brdagent + process not responding. +
+
+
PAN-254577
+
+
+ Fixed an issue where a core file was created on the Log Forwarding + Card (LFC) due to a third-party software issue. +
+
+
PAN-254425
+
+
+ Fixed an issue where the firewall did not restrict port 9905 to + localhost. +
+
+
PAN-254423
+
+
+ Fixed an issue on Panorama where custom role-based admin users with + read-only access were able to make changes to configurations. +
+
+
PAN-254422
+
+
+ Fixed an issue where the firewall required a restart when an SD-WAN + policy rule was pushed from Panorama. +
+
+
PAN-254411
+
+
+ Fixed an issue where the + configd + process stopped responding, which caused + ERR_CONNECTION_REFUSED error + messages to be displayed in admin sessions. +
+
+
PAN-254373
+
+
+ Fixed an issue where the firewall did not handle error code 500 + responses from the WildFire cloud correctly. +
+
+
PAN-254241
+
+
+ Fixed an issue where the firewall stopped responding due to a high + number of SD-WAN probes being sent. +
+
+
PAN-254181
+
+
+ (CN-Series firewalls only) Fixed an issue where + firewall pods and application pods repeatedly restarted. +
+
+
PAN-253829
+
+
+ Fixed an issue where the CLI command + show running security-policy + timed out when the Security policy was large. +
+
+
PAN-253819
+
+
+ Fixed an issue where a + User Activity Report was not + generated by Run Now or not emailed + through the Email Schedule when the + locale setting was not English. +
+
+
PAN-253452
+
+
+ Fixed an issue where GlobalProtect users were unable to connect to the + GlobalProtect gateway and received the error + Gateway does not exist. +
+
+
PAN-253317
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where you were unable to log in to the firewall + after a private data reset. +
+
+
PAN-252867
+
+
+ Fixed an issue where an incorrect memory reference in an IoT API + caused the wifclient process to + stop responding. +
+
+
PAN-252517
+
+
+ Fixed an issue where SNMP failed to respond to multiple Object + Identifier (OID) queries in a single SNMP GET request. +
+
+
PAN-252411
+
+
+ Fixed an issue where, when log files were purged from the rollup + summary logs, the summary report still used the rollup summary data, + which resulted in the summary report displaying less data. +
+
+
PAN-251909
+
+
+ Fixed an issue where a Panorama pushed configuration failed to commit + on the firewall due to the address object referenced by the interface + not being shared with the firewall. +
+
+
PAN-251732
+
+
+ Fixed an issue where Oracle traffic over generic routing encapsulation + (GRE) was dropped when the traffic passed through the firewall using + ttunnel content inspection (TCI). +
+
+
PAN-251676
+
+
+ Fixed an issue on Panorama appliances in large-scale deployments where + configd + process core files consumed more space in the /opt/panlogs partition + than was available. +
+
+
PAN-251661
+
+
+ Fixed an issue where a memory overwrite occurred during HTTP/2 header + inflation. +
+
+
PAN-251656
+
+
+ Fixed an issue where enabling lockless QoS caused traffic disruptions. +
+
+
PAN-251655
+
+
+ Fixed an issue where the firewall stopped forwarding files to the + WildFire cloud and a restart of the + varrcvr + process was required. +
+
+
PAN-251446
+
+
+ Fixed an issue where a critical system log was generated for a SAML + authenticated user whose username length was greater than 32 + characters. +
+
+
PAN-251047
+
+
+ Fixed an issue where the + useridd + process logs were flooded with an error message related to service + profiles. +
+
+
PAN-250948
+
+
+ Fixed an issues where GlobalProtect on Microsoft Windows devices did + not attempt CNAME resolution for sinkhole.paloaltonetworks.com. +
+
+
PAN-250909
+
+
+ Fixed an issue where, when creating a Security policy rule via the + CLI, validation was not implemented and the same object was able to be + referenced in the policy twice. +
+
+
PAN-250787
+
+
+ Fixed an issue where network issues between the firewall and the log + collector caused + logrcvr + process memory exhaustion. +
+
+
PAN-250597
+
+
+ Fixed an issue where Global Find for a Panorama pushed shared address + object displayed Others in the + results. +
+
+
PAN-250462
+
+
+ Fixed an issue where the session logout time for the firewall was + incorrect when viewing via context switch from Panorama. +
+
+
PAN-250419
+
+
+ Fixed an issue where XML API explorer inserted a plus (+) character in + the Xpath when a space was used in the object name. +
+
+
PAN-250405
+
+
+ (CN-Series firewalls only) Fixed an issue on + the firewall where + websrvr related messages + displayed repeatedly. +
+
+
PAN-250311
+
+
+ Fixed an issue where the domain was not mapped when using certificate + profile authentication on GlobalProtect. +
+
+
PAN-250258
+
+
+ Fixed an issue on the firewall where the Certificate Name character + limit was 31 characters instead of 63 characters. +
+
+
PAN-250127
+
+
+ Fixed an issue where commits failed with the error message + set is not allowed when + default originate was enabled with a + route map that included a set action. +
+
+
PAN-250024
+
+
+ Fixed an issue related to the + reportd + process where you were unable to log in to Panorama via the web + interface and received a 500 error. +
+
+
PAN-250021
+
+
+ Fixed an issue where + Change Summary and + Preview Changes displayed + inconsistent information when changing an admin user password. +
+
+
PAN-250005
+
+
+ Fixed an issue where the Advanced Routing migration script did not + migrate BGP import policy rules correctly when the policy rule was + configured with an exact match condition. +
+
+
PAN-249855
+
+
+ Fixed an issue where the firewall dropped the active source of the + Multicast source via MSDP when they were not received from the MSDP + peer firewall. +
+
+
PAN-249404
+
+
+ Fixed an issue on the Panorama web interface where the commit lock for + a device group and template with the same name was not visible. +
+
+
PAN-249266
+
+
+ Fixed an issue where the + config + process virtual memory was exceeded due to delays in post-commit + processing. +
+
+
PAN-248975
+
+
+ Fixed an issue on the Panorama web interface where no content was + displayed after logging in. +
+
+
PAN-248841
+
+
+ Fixed an issue where the SSL response time was not displayed in the + GlobalProtect log. +
+
+
PAN-248542
+
+
+ Fixed an issue where the NPB policy type was missing from + configuration policy updates, which caused error messages to + incorrectly display in the system logs. +
+
+
PAN-248211
+
+
+ Fixed an issue on Panorama where commits failed when Advanced Routing + was enabled. +
+
+
PAN-248130
+
+
+ Fixed an issue where the + AND operation under a Dynamic + Address Group comparison did not work after upgrading the AWS plugin + to 3.0.1. +
+
+
PAN-247857
+
+
+ (PA-7050 firewalls in HA configurations only) + Fixed an issue on the firewall where a dataplane process restarted + when updating the routing table. +
+
+
PAN-247754
+
+
+ Fixed an issue where successful + Commit and Push operations performed + by SAML authenticated users were not reflected on the firewall. +
+
+
PAN-247575
+
+
+ Fixed an issue where the error message + import of <issuecert> failed. Please check the validity of + the key pair and try again + for unmatched keys for EC certificates. +
+
+
PAN-247426
+
+
+ Fixed an issue where a proxy server was used for External Dynamic List + communication even when the dataplane interface was configured through + service routes. +
+
+
PAN-247257
+
+
+ Fixed an issue where the + useridd + process stopped responding, which caused the firewall to reboot. +
+
+
PAN-247230
+
+
+ Fixed an issue where the syslog forwarding configuration did not + include the full path for Security policy rules. +
+
+
PAN-246772
+
+
+ Fixed an issue on the firewall where the dataplane went down due to a + path monitor failure caused by an out-of-memory (OOM) condition + related to the + pan_task + process. +
+
+
PAN-246769
+
+
+ Fixed an issue on Panorama where deny logs were not displayed. +
+
+
PAN-246220
+
+
+ Fixed an issue where a dynamic peer connection was rejected when using + an FQDN for the peer address. +
+
+
PAN-246056
+
+
+ Fixed an issue where single TLS session packets were sent to multiple + firewalls when off-loading was enabled and ECMP was disabled. +
+
+
PAN-245892
+
+
+ Fixed an issue where Log Filtering (Monitor > Logs) was slower than expected. +
+
+
PAN-245556
+
+
+ Fixed an issue where the firewall dropped VxLAN packets via v-wire + after upgrading to PAN-OS 10.1.10 or a later release, which impacted + SMB traffic and resulted in silent packet drops. +
+
+
PAN-244746
+
+
+ Fixed an issue where changes committed on Panorama were not reflected + on the firewall after a successful push. +
+
+
PAN-243957
+
+
+ Fixed an issue where the firewall TLS/SSL service profile exclusion + settings were not correctly applied on the captive portal. +
+
+
PAN-243387
+
+
+ Fixed an issue where sessions ended with the message + resources-unavailable when traffic + hit a Security profile. +
+
+
PAN-243240
+
+
+ Fixed an issue where the using QoS caused packet buffer utilization to + increase exponentially and the + PKI POOL DFLT pool depleted until + a reboot was performed. +
+
+
PAN-243098
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security + profiles were configured. +
+
+
PAN-243081
+
+
+ Fixed an issue on the firewall where log filtering with special + characters in the username incorrectly returned results. +
+
+
PAN-242958
+
+
+ Fixed an issue where the firewall intermittently logged + connect-agent-failure messages + for service connection instances due to bi-directional host ID + redistribution. +
+
+
PAN-242331
+
+
+ Fixed an issue where Prisma Access remote network firewalls + intermittently created incorrect user-to-IP-address mappings. +
+
+
PAN-242147
+
+
+ (PA-1410 firewalls only) Fixed an issue where + the firewall did not block STP packets when the ports on the connected + routers were in access mode. +
+
+
PAN-241781
+
+
+ Fixed an issue where partial + commit and + commit-all operations took more + time than expected to create the job ID. +
+
+
PAN-241044
+
+
+ Fixed an issue where traffic was denied by the interzone-default + policy rule when a Security policy rule with an FQDN destination was + configured. +
+
+
PAN-239246
+
+
+ Fixed an issue where the CLI command + debug user-id dump hip-based-profile-database-entry + returned an incorrect value in the output for the + total size of hip reports. +
+
+
PAN-237582
+
+
+ Fixed an issue where logs were intermittently missing on the log + collector due to missing aliases for some indices. +
+
+
PAN-236497
+
+
+ Fixed an issue where the firewall was unable to purge expired GTP-U + sessions that remained as allocated sessions even after the TTL was + expired. +
+
+
PAN-235110
+
+
+ (PA-220 firewalls only) Fixed an issue where + the web interface did not load after an upgrade. +
+
+
PAN-234560
+
+
+ Fixed an issue where the daily summary report displayed IPv6 addresses + instead of IPv4 addresses. +
+
+
PAN-232550
+
+
+ Fixed an issue where SNMPv3 authentication failed when using SHA-512 + Auth protocol. +
+
+
PAN-231642
+
+
+ Fixed an issue on the Panorama web interface where users that were + logged in through multiple sessions were able to see an active lock on + only one session. +
+
+
PAN-230326
+
+
+ Fixed an issue where the Network Packet Broker (NPB) user interface + was incorrectly displayed on unsupported platforms. +
+
+
PAN-226785
+
+
+ Fixed an issue where accessing websites with HTTP to HTTPS redirect + failed via explicit proxy. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h1.html b/reference/PAN-OS/addressed/11.2.4-h1.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h1.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h10.html b/reference/PAN-OS/addressed/11.2.4-h10.html new file mode 100644 index 0000000..865d333 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h10.html @@ -0,0 +1,732 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-292503
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP + addresses did not display in traffic & threat logs. +
+
+
PAN-290996
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS + (Connections Per Second) per vsys on firewalls after upgrading to + PAN-OS 11.1.6-h3, even when active connections were present. +
+
+
PAN-290088
+
+
+ Fixed an issue where a memory leak occurred related to the + configd + process when pushing configurations from Panorama to a firewall. This + occurred when the configurations contained shared policy rules. +
+
+
PAN-287838
+
+
+ (Panorama appliances only) Fixed an issue on + the web interface where resetting the rule hit counter for multiple + policy rules failed with the error message + Failed to reset rule-hit job. +
+
+
PAN-287056
+
+
+ Fixed an issue where BGP export policy rules with next-hop matching + failed to block the advertisement of static routes, and the firewall + incorrectly matched the egress interface IP address instead of the + original next-hop IP address of the static route, which caused the + deny rule to fail. +
+
+
PAN-287023
+
+
+ Fixed an issue where a large number of logs caused the + logrcvr + process to stop responding. +
+
+
PAN-286848
+
+
+ Fixed an issue where ECMP incorrectly balanced sessions across links + based on the configured metric, which led to an imbalance in traffic + distribution and resulted in traffic assignment shifting + disproportionately to routes with lower metrics. +
+
+
PAN-286306
+
+
+ Fixed an issue where, when getting transceiver information from ESCC + for SFP 25G modules, the transceiver code was incorrectly updated with + Unknown instead of + 25GBase-SR. +
+
+
PAN-284117
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where the + vm_agent + process restarted after an upgrade. +
+
+
PAN-284073
+
+
+ Fixed an issue on the firewall that caused commits to fail and the web + interface to become inaccessible. +
+
+
PAN-284003
+
+
+ Fixed an issue where clients did not receive a valid response when + searching a website due to a compression error. +
+
+
PAN-282391
+
+
+ (Panorama appliances and Log Collectors only) + Fixed an issue where a VLD memory leak caused increased memory use, + which resulted in OOM errors. +
+
+
PAN-282359
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected. +
+
+
PAN-281649
+
+
+ Fixed an issue where the index size limit was incorrectly calculated + and indices rolled over earlier than expected, which resulted in high + memory and OOM errors. +
+
+
PAN-281509
+
+
+ (Panorama appliances only) Fixed an issue where + log exports were slower than expected or failed when filtering logs + after an upgrade, which resulted in timeouts or delays in displaying + logs on the web interface. +
+
+
PAN-279500
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric + routing environments if the firewall did not see server-to-client + (s2c) packets of the TLS handshake. +
+
+ To use this fix, run the following CLI command: + debug dataplane set ssl-decrypt accumulate-client-hello + asym-disable yes. +
+
+
PAN-279415
+
+
+ Fixed an issue where service routes configured to use a data plane + interface incorrectly used the management plane interface for traffic + transmission. This issue affected syslog and CRL status traffic when a + custom service route was not configured. +
+
+
PAN-278812
+
+
+ Fixed an issue where authentication to GlobalProtect failed with the + error message + User not in allowed list. +
+
+
PAN-278150
+
+
+ Fixed an issue where the firewall removed the Authentication Key + Identifier (AKID) from the certificate during SSL decryption, which + caused Python 3.13 to fail with a certificate verification error. +
+
+
PAN-277417
+
+
+ Fixed an memory leak issue related to TLS inbound decryption. +
+
+
PAN-277147
+
+
+ Fixed an issue where daily scheduled reports were not generated and + emailed. +
+
+
PAN-276920
+
+
+ Fixed an issue where web-advertisement traffic was not immediately + blocked which resulted in pages loading indefinitely. +
+
+
PAN-276616
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet + were not visible. +
+
+
PAN-276276
+
+
+ (PA-450 firewalls only) Fixed an issue where, + after an upgrade, data that was excluded using the query builder in a + custom report was still visible in the report, and the logs displayed + errors related to invalid threat names being queried. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) Fixed an issue + where, after an upgrade, the firewall was unable to send logs to the + Strata Logging Service (SLS) when using a specific proxy server, and + the SSL connection status displayed as failed when attempting to + forward logs through the web proxy. +
+
+
PAN-275032
+
+
+ (M-600 appliances only) Fixed an issue where + the Elasticsearch cluster certificate (CC) status displayed with a + past expiration date, which caused all shards to be unassigned. +
+
+
PAN-274671
+
+
+ Fixed an issue where empty traffic + logdb + folders were generated for each day even when trafcfic logs were not + received by the + logrcvr + process. +
+
+
PAN-272812
+
+
+ Fixed an issue where SNMP monitoring of tunnel interfaces displayed + zero values for received bytes and packets. +
+
+
PAN-271810
+
+
+ Fixed an issue where auto-negotiation advertised and negotiated 10/100 + half and full duplex. +
+
+
PAN-271700
+
+
+ Fixed an issue where User-ID connections were lost after an HA + failover. +
+
+
PAN-271560
+
+
+ Fixed an issue where DNS requests to malware sites were not blocked as + expected, and the + dns-security-categories log-level + and action displayed default values instead of + unavailable. +
+
+
PAN-270849
+
+
+ Fixed a memory leak issue related to the + configd + process that occurred when running consecutive commits for multiple + days. +
+
+
PAN-269899
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected when querying for device tags. +
+
+
PAN-269731
+
+
+ Fixed an issue where Panorama did not display logs from firewalls + after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) + getting restarted continuously. +
+
+
PAN-268787
+
+
+ Fixed an issue where users were unable to log in to Panorama and the + following error message was displayed: + Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of + devices. +
+
+
PAN-267535
+
+
+ Fixed an issue where + all_task + processes stopped responding on the remote network firewall, which + caused tunnels to go down and the + pan_task + CPU usage to approach 100%. +
+
+
PAN-267091
+
+
+ Fixed an issue on Panorama where Elasticsearch repeatedly restarted. +
+
+
PAN-266639
+
+
+ Fixed an issue where administrators were unable to edit or add virtual + router configurations when a filter was applied to the viewer. +
+
+
PAN-263369
+
+
+ Fixed an issue where commits from Panorama to Panorama virtual + appliances failed with the error message + Internal error during commit processing. Commit/Validate + failed + after upgrading Panorama. +
+
+
PAN-261209
+
+
+ (Firewalls in active/active HA configuration only) Fixed an issue where the firewall displayed the HA2 status as down + when the HSCI port was used for both HA2 and HA3. +
+
+
PAN-260604
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput + utilization stats in NetFlow analyzer tools. +
+
+
PAN-259881
+
+
+ Fixed an issue on Panorama where traffic log details were not + displayed under detailed log view. +
+
+
PAN-258757
+
+
+ Fixed an issue on Panorama where upgrades failed with validation + errors. +
+
+
PAN-255860
+
+
+ (PA-5200 firewalls only) Fixed an issue where + the + all_pktproc + process stopped responding when the firewall was under a heavy traffic + load. +
+
+
PAN-249384
+
+
+ Fixed an issue on Panorama where configuration locks were observed + during a partial rulebase commit. +
+
+
PAN-246699
+
+
+ Fixed an issue on Panorama where + Rule Usage and + Apps Seen under Security policy + rules stopped incrementing. +
+
+
PAN-245064
+
+
+ (Multi-vsys firewalls only) Fixed an issue + where commits failed on the firewall after selecting + Export or push device config bundle + on Panorama and a force push was required. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h11.html b/reference/PAN-OS/addressed/11.2.4-h11.html new file mode 100644 index 0000000..2e4f7b7 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h11.html @@ -0,0 +1,196 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-291499
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where newly deployed firewalls were unable to + connect to the Palo Alto Networks Software License Server (SLS) until + after a reboot, license fetch, or management server restart. +
+
+
PAN-290803
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom + image, and VM-Series plugin information was not displayed in the + system information. +
+
+
PAN-290241
+
+
+ Fixed an issue where the + useridd + process became unresponsive, which caused User ID CLI commands to time + out. +
+
+
PAN-288939
+
+
+ Fixed an issue where the + logrcvr + process stopped responding due to an invalid SSL context being used + for socket communication, which caused commits to fail. +
+
+
PAN-287688
+
+
+ Fixed an issue where the firewall failed to connect to the Palo Alto + Networks update server when using a customized service route with the + source interface as MGT. +
+
+
PAN-279901
+
+
+ An issue was fixed where the firewall dropped fragmented TLS + ClientHello packets, which blocked access to certain websites. This + occurred because the packets arrived truncated, in varying sizes and + orders, and the firewall's heuristics failed to handle them correctly. +
+
+ To enable this fix, run: + debug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-268680
+
+
+ Fixed an issue where the + configd + process stopped responding when a configuration merge operation + changed. +
+
+
PAN-268522
+
+
+ Fixed an issue where the firewall failed to connect to the update + server with a customized service route when the source interface was + set to MGT and the source address + was set as IPv4. +
+
+
PAN-255914
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where a newly bootstrapped firewall required a + management server restart, relicensing, or license push from Panorama + to invoke the device certificate. +
+
+
PAN-241230
+
+
+ Fixed an issue where the SNMP get request status value for Panorama + connections was incorrect. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h12.html b/reference/PAN-OS/addressed/11.2.4-h12.html new file mode 100644 index 0000000..0ec016a --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h12.html @@ -0,0 +1,458 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-296519
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an + associated error in + Wifclient + caused the entire pool to close, which resulted in a complete + disconnection. +
+
+
PAN-295560
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors, + tunnel logs were not visible in Panorama or Splunk even though traffic + and threat logs were received. +
+
+
PAN-293673
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM + condition caused by a scheduled log export using FTP to an external + FTP server. +
+
+
PAN-292229
+
+
+ Fixed an issue where Panorama was unable to retrieve + userid + logs from the firewall for subscribed user-ip-mappings after Panorama + was rebooted. +
+
+
PAN-292202
+
+
+ Fixed an issue where the system logs repeatedly displayed the alert + Clearing snmpd.log due to log overflow + due to the SNMP counters rolling over. +
+
+
PAN-291716
+
+
+ Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM) + conditions, leading to device crashes and reboots. +
+
+
PAN-291631
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall frequently rebooted. +
+
+
PAN-291288
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a + pan_task + process restart related to page allocation failures. +
+
+
PAN-291094
+
+
+ Fixed an issue the firewall experienced packet descriptor on chip and + buffer spikes, which led to dropped traffic due to an unidentified + traffic pattern. +
+
+
PAN-291067
+
+
+ Fixed an issue where the + devsrvr + process periodically exceeded its virtual memory limit and restarted, + which led to intermittent outages. +
+
+
PAN-290542
+
+
+ Fixed an issue where the + all_task + process stopped responding when an additional header logging HTTP + header was split across 2 packets. +
+
+
PAN-290449
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports + were sent in the same email, only the first attached report was + displayed. +
+
+
PAN-287818
+
+
+ Fixed an issue where sessions timed out sooner than expected due to + the + pan_proxy_accumulation_restore_timeout + not initiating when the accumulation + session_init failed. +
+
+
PAN-287803
+
+
+ Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1, + certain websites weren't accessible when the accumulation proxy was + enabled. The proxy did not use the same DF bit state as the original + traffic, causing it to be fragmented and dropped elsewhere in the + network. +
+
+
PAN-287782
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP + values from AF11 to CS0 on traffic passing through the firewall, even + when QoS policy rules and DSCP rewrite settings were not configured. +
+
+
PAN-287622
+
+
+ Fixed an issue where IPv6 traffic was affected after upgrading the + firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption + enabled and a decryption policy configured for the traffic, the + firewall dropped packets due to receiving a + Packet Too Big ICMP message. This + occurred because the PathMTU information update was incorrect for the + TCB (pan-server) when the firewall was acting as a server. + Additionally, the flow label under the IPv6 header was set to zero + while the packet was being transmitted out of the firewall. +
+
+
PAN-287601
+
+
+ Fixed an issue on Panorama where commits took longer than expected. +
+
+
PAN-287423
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites + due to the firewall incorrectly setting the IPv6 header flow label to + 0. +
+
+
PAN-286299
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 releases where, after + being offboarded from Panorama, the firewall XML configuration file + retained template information from the previous Panorama + configuration. As a result, when the firewall and its configuration + were imported to another Panorama appliance, all configurations in the + Network and + Device tabs became read-only. +
+
+
PAN-285285
+
+
+ Fixed an issue where commits remained at 98% completion when static + route configuration cleanup was in progress. +
+
+
PAN-286231
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to + multiple firewalls with different base configurations resulted in + configuration corruption, which caused the firewall to go down. +
+
+
PAN-280698
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from + client hello messages that did not fit in a single packet, which + resulted in connection issues. +
+
+
PAN-279706
+
+
+ (M-600 appliances only) Fixed an issue where + Panorama did not update all + panreplay + database entries after performing a commit and full push to all + devices. +
+
+
PAN-276484
+
+
+ Fixed an issue where Panorama did not display license information for + Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes. +
+
+
PAN-273453
+
+
+ Fixed an issue where restarting the firewall did not initiate an + autocommit job, which caused the firewall to stop responding and the + HA interface to go down. +
+
+
PAN-273300
+
+
+ Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed + with a validation error. +
+
+
PAN-265044
+
+
+ Fixed an issue where the default software packet buffer size for the + Advanced Header Learning (AHL) feature was excessively large, which + led to inefficient use of software packet buffers. +
+
+
PAN-260015
+
+
+ Fixed an issue on the firewall where enabling Inline Cloud Analysis + features might cause the firewall to unexpectedly reboot, due to an + issue related to loopback data handling. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h14.html b/reference/PAN-OS/addressed/11.2.4-h14.html new file mode 100644 index 0000000..c28b4f7 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h14.html @@ -0,0 +1,503 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-303559
+
+
+ Fixed an issue where, after manually creating a device telemetry + bundle, the + hour_cli_output.txt file within + the bundle had a file size of 0 bytes. This occurred when checking the + bundle content after enabling device telemetry and setting the device + telemetry upload endpoint. +
+
+
PAN-301456
+
+
+ Fixed an issue on Panorama where the + debug system reset-ztp CLI + command was unavailable. +
+
+
PAN-300216
+
+
+ Fixed an issue where, when SD-WAN Direct Internet Access was + configured and traffic traversed the cellular interface without a NAT + policy rule, intermittent cellular modem connectivity issues occurred, + which caused the firewall to disconnect and reconnect to the cellular + network. + To use this fix, run the CLI command set session + teardown-upon-fwd-zonechange yes. +
+
+
PAN-298462
+
+
+ Fixed an issue where the firewall experienced extended boot times + after a reboot due to the + configd + process needing to rebuild the ACE catalog after detecting + discrepancies that were caused by duplicate application checking + between the ACE catalog and content. +
+
+
PAN-297976
+
+
+ Fixed an issue where the firewall experienced extended boot times + after a reboot due to the + configd + process needing to rebuild the ACE catalog after detecting + discrepancies that were caused by duplicate application checking + between the ACE catalog and content. +
+
+
PAN-297972
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched + Inline Cloud Analysis prefiltering signatures, even when Inline Cloud + Analysis features were not enabled. +
+
+
PAN-297775
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release, + the Visible Virtual System field referenced the vsys name instead of + the vsys ID, which caused inter-vsys routing to fail. This occurred + when a vsys display name matched one of the vsys IDs. If you're using + a multivsys environment, you must upgrade your firewalls to a fixed + PAN-OS version. The best practice is to upgrade both the firewalls and + Panorama to a fixed PAN-OS version. +
+
+ If you don't upgrade Panorama to a fixed version, you'll encounter + PAN-245064, where a commit on a multivsys firewall fails with the + message + vsys name should end with a number vsys is invalid + after you + Export or push device config bundle + from 11.1.1 Panorama. +
+
+ After you upgrade Panorama to a fixed version, you'll encounter + PAN-214177, which causes an + Export or Push device config bundle + from Panorama to the firewall to fail. The workaround for PAN-214177 + is to first push only the template configuration and then push the + device group configurations. +
+
+
PAN-296752
+
+
+ (PA-1410 Firewalls only) Fixed an issue where + the firewall experienced high management CPU usage and repeatedly + rebooted when attempting to retrieve SMART data. +
+
+
PAN-296694
+
+
+ Fixed an issue where the firewall rebooted due to the + useridd + process repeatedly restarting during an IP-port data type writes to + the redis from multiple sources such as TSA or XML in a scale + environment. +
+
+
PAN-296535
+
+
+ Fixed an issue on the firewall where BGP peers disconnected due to + frr_ns1_bgpd restarting. +
+
+
PAN-294436
+
+
+ (PA-410, PA-440, PA-450, and PA-460 firewalls only) Fixed an issue where, after upgrading to PAN-OS 11.1.6-h6 the + Eth1/2, Eth1/3, Eth1/8, and HA interfaces failed to display counters + and statistics in the CLI and SNMP. +
+
+
PAN-292447
+
+
+ Fixed an issue where Panorama did not display data in the + Feature Adoption tab in Strata Cloud + Manager due to the system creating and deleting a CLI user for each + interval instead of reusing a permanent CLI user for telemetry. +
+
+
PAN-291940
+
+
+ Fixed an issue where the firewall established multiple TCP connections + to a syslog server, which caused logs to be dropped. This occurred + because the firewall established a new TCP session for each transfer + and the sessions were not closed, which resulted in a continuous + increase in connections over time. +
+
+
PAN-291661
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after + an upgrade, Elasticsearch intermittently entered into a Red state + before automatically recovering. +
+
+
PAN-289249
+
+
+ Fixed an issue where a memory leak occurred on the + reportd + process when a WildFire update was initiated while device telemetry + data collection was in progress. This resulted in an OOM condition. +
+
+
PAN-289109
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected during configuration operations and a configuration lock time + out occurred during a commit. +
+
+
PAN-287387
+
+
+ Fixed an issue on Panorama where API jobs failed with the error + message + Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a + large number of address objects in a single set call. +
+
+
PAN-284279
+
+
+ Fixed an issue where the policy destination always defaulted to + any, even when specific IP addresses + and FQDNs were specified during policy import. +
+
+
PAN-284067
+
+
+ Fixed a cumulative memory leak in the + devsrvr + process that occurred whenever the CLI command + show running application statistics + was issued. This memory leak would gradually consume system memory and + produce an OOM condition, causing the firewall to reboot. +
+
+
PAN-281776
+
+
+ Fixed an issue on the Panorama web interface where the error message + PPPoEv6 Client Interface cannot be enabled with DHCPv6 client + was generated when overriding aggregate interfaces even when no DHCPv6 + or PPPoE was configured. +
+
+
PAN-279829
+
+
+ Fixed an issue where NAT pool leaks occurred during a test when RTSP + traffic hit NAT rules. +
+
+
PAN-272746
+
+
+ (PA-440 firewalls only) Fixed an issue where + the firewall entered an unstable state after committing changes or + onboarding to Panorama. +
+
+
PAN-272605
+
+
+ Fixed an issue where the firewall did not display VPC endpoints when + there was a large amount of VPC endpoints to interface mappings. +
+
+
PAN-272245
+
+
+ Fixed an issue where the + dnsproxy + process stopped responding due to memory corruption caused by a race + condition when the allow list downloading was impacted by a + configuration change. +
+
+
PAN-267450
+
+
+ Fixed an issue where the + reportd + process stopped responding with a SIGSEGV at + schedule_report_es_response. +
+
+
PAN-266312
+
+
+ Fixed an issue where BFD sessions took longer than expected to + establish after an HA failover due to BGP. +
+
+
PAN-264131
+
+
+ Fixed an issue where the + routed + process core failed the automation run. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h15.html b/reference/PAN-OS/addressed/11.2.4-h15.html new file mode 100644 index 0000000..6c67fbb --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h15.html @@ -0,0 +1,37 @@ + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
+
+
+ A fix was made to address + CVE-2026-0227. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h2.html b/reference/PAN-OS/addressed/11.2.4-h2.html new file mode 100644 index 0000000..a8fccf8 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h2.html @@ -0,0 +1,69 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-273215
+
+
+ Fixed an issue where a syntax error in the index generation script + caused a high management plane CPU load after upgrading. +
+
+
PAN-271613
+
+
+ Fixed an issue where configuration pushes from Panorama to the + firewall failed due to an OOXML commit error. +
+
+
PAN-269404
+
+
+ Fixed an issue where the firewall did not reset the maximum latency + timer for hold mode. +
+
+
PAN-259078
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and + the following error message was displayed: + Error 500: Internal Server Error. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h4.html b/reference/PAN-OS/addressed/11.2.4-h4.html new file mode 100644 index 0000000..210bab8 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h4.html @@ -0,0 +1,350 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-276130
+
+
+ Fixed an issue where, when a new IKEv2 was created on Panorama on a + PAN-OS 11.2 release using the default IKE version (IKEv2) and IPSec + crypto profiles with no specific changes to the crypto profile + parameters, and the configuration was pushed to a firewall on PAN-OS + 11.2.0 to PAN-OS 11.2.4, the firewall interpreted the IKEv2 gateway as + IKEv1. +
+
+
PAN-274029
+
+
+ Fixed an issue where upgrading Panorama and pushing configurations to + the firewall caused an IKE version mismatch, which resulted in IPSec + tunnel failure with the peer device. +
+
+
PAN-273994
+
+
+ A fix was made to address + CVE-2025-0111. +
+
+
PAN-273971
+
+
+ A fix was made to address + CVE-2025-0108. +
+
+
PAN-273278
+
+
+ A fix was made to address + CVE-2025-0109. +
+
+
PAN-273197
+
+
+ Fixed an issue where the endpoint ID was not populated in logs when + the least significant word of the Geneve header was 0. +
+
+
PAN-273165
+
+
+ Fixed an issue where HTTP/2 sessions failed on the firewall when + Dynamic Memory Management was enabled. +
+
+
PAN-273085
+
+
+ Fixed an issue on the web interface where you were unable to edit or + create policy rules. +
+
+
PAN-273019
+
+
+ Fixed an intermittent issue where SSL decryption failed. +
+
+
PAN-272021
+
+
+ (M-300 Appliances only) Fixed an issue where a + split brain condition was not triggered during an inter-Log Collector + disconnect between DLC firewalls in an Elasticsearch cluster, which + resulted in missing logs. +
+
+
PAN-271926
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC + error when the firewall was configured to decrypt and inspect TLS + traffic. +
+
+
PAN-271828
+
+
+ Fixed an issue where, after an accumulation proxy changed to + no-decrypt or no proxy, only the Client Hello was sent to Content + Threat Detection. +
+
+
PAN-270549
+
+
+ Fixed an issue where some TLS connections were not handled correctly, + which led to instability in the dataplane. +
+
+
PAN-270248
+
+ Fixed an issue where the firewall failed to forward logs to a SNMP trap + server if the SNMP manager IP address was unable to be resolved. +
+
PAN-268815
+
+
+ Fixed an issue where the firewall entered a non-functional state due + to duplicate entries in the shared memory. +
+
+
PAN-268727
+
+ Fixed an issue where traffic was dropped when the accumulation proxy was + enabled and header insertion modified packets. +
+
PAN-268229
+
+
+ Fixed an issue where the firewall stopped responding during session + setup for ECMP hit-count updates. +
+
+
PAN-268215
+
+
+ (Panorama appliances in HA configurations only) + Fixed an issue where, when Elasticsearch was forming a cluster and the + port was disabled or disconnected and then reconnected, Elasticsearch + did not reform the cluster +
+
+
PAN-267781
+
+
+ Fixed an issue where Panorama did not display the Source Dynamic + Address Group. +
+
+
PAN-267671
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to the + all_task + process restarting and repeated OOM conditions occurring on the + pan_task + process. +
+
+
PAN-265742
+
+
+ Fixed an issue on the Panorama web interface where the + OK button on the GlobalProtect + gateway configuration dialog box was not clickable. +
+
+
PAN-263987
+
+
+ Fixed an issue on the firewall where, when a NAT transversal IPSec + tunnel was terminated, and the NAT rule that was applied to the NAT-T + IPSec tunnel was on the same firewall, traffic flowing through the + tunnel was not correctly translated. +
+
+
PAN-252036
+
+
+ Fixed an issue where, when the GlobalProtect portal was not + configured, accessing the GlobalProtect gateway still loaded a portal + malformed page. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h5.html b/reference/PAN-OS/addressed/11.2.4-h5.html new file mode 100644 index 0000000..df571ae --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h5.html @@ -0,0 +1,103 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-279604
+
+
+ Fixed an issue where scheduled SaaS application usage reports were + generated incorrectly, and the login page was displayed instead of the + report content. +
+
+
PAN-276177
+
+
+ Fixed an issue where + App Acceleration did not work with + Oracle databases. +
+
+
PAN-274791
+
+
+ Fixed an issue where the firewall rebooted when Shared Pool Type 32 + was depleted and traffic matched advanced features. +
+
+
PAN-269499
+
+
+ Fixed an issue where the firewall stopped responding when receiving a + high number of logs. +
+
+
PAN-252224
+
+
+ Fixed an issue where Panorama did not forward logs to a syslog server + over an SSL connection using CRL as a revocation verification method. +
+
+
PAN-234082
+
+
+ (Panorama virtual appliances only) Fixed an + issue where Saas reports were generated with a report period of 0 + days. +
+
+
PAN-216054
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while + it was idle. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h6.html b/reference/PAN-OS/addressed/11.2.4-h6.html new file mode 100644 index 0000000..291935e --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h6.html @@ -0,0 +1,559 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-284036
+
+
+ (PA-450R and PA-450R-5G firewalls only) Fixed + an issue where the maximum temperature threshold and shutdown + threshold were not set correctly. +
+
+
PAN-282236
+
+
+ Fixed an issue where large IPv6 packets were reassembled incorrectly + on the firewall when the packets arrived fragmented over an IPv4 + tunnel. +
+
+
PAN-282206
+
+
+ Fixed an issue where configuring Secure Web Gateway (SWG) in + no-auth mode led to latency when no + decryption policy rules or + No-decrypt policy rules were + present. +
+
+
PAN-282022
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700 + appliances. +
+
+
PAN-280471
+
+
+ Fixed an issue where navigating + Panorama > Monitor > Logs was + slower than expected. +
+
+
PAN-279746
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client + Hello arrived at the firewall in multiple out-of-order segments and + the traffic was not subject to SSL decryption. +
+
+
PAN-279197
+
+
+ (PA-450R-5G firewalls only) Fixed an issue + where the firewall stopped responding and displayed the error message + `Thermal temperature exceeds system threshold! Shutting down NOW` even + when the firewall was within the threshold. +
+
+
PAN-278684
+
+
+ (PA-445 firewalls only) Fixed an issue where + the firewall did not properly power cycle during a reboot. +
+
+
PAN-278296
+
+
+ Fixed an issue where the system MAC address of the aggregate interface + was the same on the active firewall and the passive firewall after an + upgrade. +
+
+
PAN-276546
+
+
+ Fixed an issue where a session lost the PBF rule mapping after a + configuration change or commit. +
+
+
PAN-275905
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected and Elasticsearch CPU usage was high. +
+
+
PAN-273949
+
+
+ Fixed an issue where the firewall generated the following error + message in the + snmpd + logs: + pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key + X2F1dGhfa2V5 import from cryptod failed. +
+
+
PAN-273026
+
+
+ Fixed an issue where traffic logs did not display correctly when + filters were applied. +
+
+
PAN-273021
+
+
+ Fixed an issue where 25G port links did not come up due to a change in + the handling of 25G DAC modules. +
+
+
PAN-272849
+
+
+ Fixed an issue where log forwarding to a UDP syslog server stopped + when an unreachable TCP syslog server was configured and applied. +
+
+
PAN-272538
+
+
+ Fixed an issue where the + configd + process stopped responding during a commit-all validation when there + were uncommitted changes and + share-unused-objects-with-devices + was set to off. +
+
+
PAN-272085
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is + enabled for DNS Security and multiple DoH transactions are sent in a + single HTTP/1 connection. +
+
+
PAN-271912
+
+
+ Fixed an issue on Panorama where the + configd + process stopped responding when filtering in the configuration audit + window after upgrading to PAN-OS 11.1.3. +
+
+
PAN-271351
+
+
+ A fix was made to address + CVE-2025-0116. +
+
+
PAN-270224
+
+
+ Fixed an issue where indices were not opened after a query. +
+
+
PAN-269956
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused internal path monitor + failures. +
+
+
PAN-269291
+
+
+ Fixed an issue where the scheduled report generation script did not + return debug information. +
+
+
PAN-269106
+
+
+ Fixed an issue where the + wifclient stopped responding + during server certificate verification for MICA gRPC connections and + caused the dataplane to restart when using a cloud-based ML detection + engine (MICA). On certain platforms, this caused the firewall to + reboot periodically. +
+
+
PAN-269091
+
+
+ Fixed an issue where the + varrcvr + process stopped responding. +
+
+
PAN-268501
+
+
+ Fixed an issue where the firewall was unable to generate a TSF file + due to a full root partition. +
+
+
PAN-267430
+
+
+ Fixed an issue where Panorama was unable to return logs for queries + that were longer than 64,000 characters. +
+
+
PAN-265179
+
+
+ Fixed an issue where a kernel race condition caused the firewall to + reboot with a kernel panic. +
+
+
PAN-263208
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an + issue where interrupts were generated at a certain packet rate, and + dataplane processes missed heartbeats, which caused the dataplane to + go down. +
+
+
PAN-262383
+
+
+ Fixed an issue where the firewall was unable to decompress the HTTP2 + header, which caused the session to be classified as unknown-tcp + instead of web-browsing. +
+
+
PAN-261739
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port + counters read from MAC. +
+
+
PAN-261484
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount + of memory as requested for pre-allocation. +
+
+
PAN-258736
+
+
+ Fixed an issue where policy rule configurations pushed from Panorama + were not reflected on the firewall if the rule had 63 characters. +
+
+
PAN-258570
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the + varrcvr + process progressively using more memory when WildFire file forwarding + is handling PE files. +
+
+
PAN-257619
+
+
+ Fixed an issue on Panorama where the + Task Manager took longer than + expected to display managed firewall report tasks. +
+
+
PAN-257028
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and + displayed the error message + Dataplane down: path monitor failure during the fail-over. +
+
+
PAN-255323
+
+
+ (PA-7050 firewalls only) Fixed an issue where + the Network Processing Card (NPC), Data Processing Card (DPC), and Log + forwarding Card (LFC) remained in a starting state after an unexpected + power cycle. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h7.html b/reference/PAN-OS/addressed/11.2.4-h7.html new file mode 100644 index 0000000..6b19ae5 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h7.html @@ -0,0 +1,112 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-286255
+
+
+ Fixed an issue where, when the firewall received an unexpected + termination request for SSL sessions, the dataplane experienced a slow + buffer resource leak. +
+
+
PAN-282968
+
+
+ Fixed an issue where the firewall did not identify the test threat + file when the content was installed via a traditional bootstrap. +
+
+
PAN-278322
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) Gateway Load + Balancer (GWLB) deployments only) Fixed an issue where the firewall did not display the correct + source user in traffic logs and session details. +
+
+
PAN-277629
+
+
+ Fixed an issue where the firewall did not match the correct policy for + SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS + 10.2.9-h1 to PAN-OS 11.2.3. +
+
+
PAN-268474
+
+
+ Fixed an issue on the firewall where the PAN-DB URL Filtering license + displayed as Valid even when the + firewall did not have the license, which caused traffic to drop. +
+
+
PAN-261999
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where enabling flow basic on firewalls caused ARP + entries to be removed on both firewalls. +
+
+
PAN-260290
+
+
+ Added support for new content size requirements on fixed model + licenses. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h8.html b/reference/PAN-OS/addressed/11.2.4-h8.html new file mode 100644 index 0000000..8e7e244 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h8.html @@ -0,0 +1,44 @@ + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-267444
+
+
+ Fixed an issue where large file downloads or uploads failed or + remained in an incomplete state when using DLP HTTP2 mirror mode. +
+
+
PAN-255619
+
+
+ Fixed an intermittent issue where file downloads from websites failed + when decrypting HTTP/2 traffic. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4-h9.html b/reference/PAN-OS/addressed/11.2.4-h9.html new file mode 100644 index 0000000..f31eeb3 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4-h9.html @@ -0,0 +1,577 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-290239
+
+
+ (PA-455 firewalls in active/passive high availability (HA) + configurations only) Fixed an issue where, after an upgrade, the TCP session for syslog + forwarding did not resume after the syslog server service was disabled + and then re-enabled, which caused logs to be dropped. This occurred + when the syslog server was down for more than 16 minutes. +
+
+
PAN-289102
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, + PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and + CN-Series firewalls only) Fixed a race condition issue related to predict processing, which + resulted in a dataplane restart and traffic loss. +
+
+
PAN-287002
+
+
+ A fix was made to address + CVE-2025-0133. +
+
+
PAN-285894
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused the firewall to reboot + unexpectedly, and traffic failures occurred. +
+
+
PAN-285651
+
+
+ (Panorama appliances in active/passive HA configurations on + Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect + unexpectedly. +
+
+
PAN-285590
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments + only) Fixed an issue where the firewall CPU usage reached 100% after + upgrading to PAN-OS 11.1.6-h1. +
+
+
PAN-284066
+
+
+ Fixed an issue where, after an upgrade, the SNMP polled values for + IF-MIB::ifInErrors displayed a + high number of errors that did not match the values in the CLI show + interface command. +
+
+
PAN-283789
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where, after an upgrade, the + mac receive error counter in + receive incoming errors increased, + which resulted in SNMP alerts. +
+
+
PAN-283467
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall unexpectedly rebooted and entered maintenance mode + due to a ctd-agent out-of-memory (OOM) condition. This occurred during + advanced services load testing and a high volume of IoT EAL log + forwarding. +
+
+
PAN-283331
+
+
+ Fixed an issue where selective pushes to managed devices failed when + the User ID Master Device was + configured. +
+
+
PAN-282069
+
+
+ Fixed an issue on Panorama where Security policy rules were removed + from device groups when you cloned or edited Security policy rules + that used more than 63 characters. +
+
+
PAN-280532
+
+
+ Fixed an issue where, after disabling and re-enabling the external + syslog server, the TCP session was not resumed, which caused all logs + that were forwarded to the syslog server to be dropped. +
+
+
PAN-279621
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward + traffic was run. +
+
+
PAN-275077
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain + URLs as Alert instead of taking a Sinkhole action, even when + configured to Sinkhole malicious DNS domains. +
+
+
PAN-274570
+
+
+ Fixed an issue where the + devsrvr + process restarted after a failed commit due to an invalid memory + access. +
+
+
PAN-274314
+
+
+ (PA-1400 Series, PA-3400 Series, and PA-5400 Series firewalls + only) Fixed an issue where, when the + pan_task + process restarted, control plane packets were dropped, which could + impact LACP and pings to host interfaces. +
+
+
PAN-272006
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump + as a large core when the CPLD (Complex Programmable Logic Device) sent + a Non-Maskable Interrupt (NMI) to the CPU. +
+
+
PAN-271913
+
+
+ Fixed an issue on firewalls in HA configurations where, when using the + Cloud Identity Engine (CIE), the firewall experienced consistent + memory leaks on the active firewall, which caused unexpected + failovers. +
+
+
PAN-271273
+
+
+ Fixed an issue where dynamic update downloads failed when + IPv6 firewalling was enabled on the + firewall and both IPv4 and IPv6 were configured on the management + interface. +
+
+
PAN-270379
+
+
+ Fixed an issue where socket files created in the /tmp directory were + not cleared. +
+
+
PAN-269052
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile + even though the Security policy rule did not have a URL filtering + profile configured. +
+
+
PAN-269027
+
+
+ Fixed an issue related to external dynamic lists that caused commit + times on the firewall to be higher than expected. +
+
+
PAN-268708
+
+
+ Fixed an issue where PDF summary and email reports displayed IPv6 + addresses instead of IPv4 addresses. +
+
+
PAN-268705
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP + traffic after upgrading to PAN-OS 10.1.14. +
+
+
PAN-268127
+
+
+ Fixed an issue where tagging devices in Panorama did not work as + expected. +
+
+
PAN-267444
+
+
+ Fixed an issue where large file downloads or uploads failed or + remained in an incomplete state when using DLP HTTP2 mirror mode. +
+
+
PAN-266900
+
+
+ Fixed an issue on the Panorama web interface where you were unable to + click OK after selecting an install + package type and file from the dropdown and selecting a firewall. +
+
+
PAN-265745
+
+
+ Fixed an issue where the firewall displayed incorrect MAC receive + error counters for VMWare devices hosted in ESXi. +
+
+
PAN-263973
+
+
+ Fixed an issue where log collectors had a low incoming log rate. +
+
+
PAN-261825
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or + Advanced URL Filtering were enabled. This occurred when the payload + size was greater than 3.5 KB. +
+
+
PAN-261673
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled, + traffic was dropped because of the + flow_parse_ip_hdr counter related + to an Nvidia driver issue. +
+
+
PAN-261429
+
+
+ Fixed an issue where the + show auth radius-require-msg-authentic + CLI command displayed no output. +
+
+
PAN-259706
+
+
+ Fixed an issue on Panorama where the web interface was slower than + expected or unresponsive when monitoring definitions were added in the + Kubernetes plugin. +
+
+
PAN-258680
+
+
+ Fixed an issue on Panorama where, when you removed Security profile + groups from a Security policy rule via the CLI and committed the + change, the Security policy rule was deleted. +
+
+
PAN-257267
+
+
+ (VM-Series firewalls only) Fixed an issue where + a warning message was displayed after a commit, and a critical system + log was generated when the configuration size exceeded the maximum + size. +
+
+
PAN-255619
+
+
+ Fixed an intermittent issue where file downloads from websites failed + when decrypting HTTP/2 traffic. +
+
+
PAN-254901
+
+
+ Fixed an issue where GlobalProtect user-to-IP address mapping was + removed even though the tunnel for the specific user was up and + traffic was being passed. +
+
+
PAN-252669
+
+
+ Fixed an issue where the + ikemgr + process stopped responding with a SIGSEGV error. +
+
diff --git a/reference/PAN-OS/addressed/11.2.4.html b/reference/PAN-OS/addressed/11.2.4.html new file mode 100644 index 0000000..fd41c3d --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.4.html @@ -0,0 +1,544 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-270802
+
+
+ Fixed an issue where, after modifying a policy rule on Panorama, + pushes to the Cloud NGFW failed with the error + saas-user-list unexpected here. +
+
+
PAN-268823
+
+
+ Fixed an issue where + Monitor > Log Display did not + display all logs when you applied a filter. +
+
+
PAN-267386
+
+
+ Fixed an issue where VPC IDs and Security keys were not mapped to the + correct interfaces for Google IPS. +
+
+
PAN-266769
+
+
+ Fixed an issue where the GlobalProtect gateway did not handle IP + address changes of the inner gateway when the NGPA new protocol was + enabled. +
+
+
PAN-266581
+
+
+ Fixed an issue where a failed SSL connection to a syslog server + resulted in a + /tmp/srvr.crt.xxxxxx file not + being removed, which caused index node (inode) exhaustion. +
+
+
PAN-266114
+
+
+ Fixed an issue where, when a new set of URL logs came in, the content + of the earlier URL and traffic logs were lost. +
+
+
PAN-265785
+
+
+ Fixed an issue where the firewall rebooted due to a + sysd + variable being modified before it was created. +
+
+
PAN-264249
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using + SNMP. +
+
+
PAN-264246
+
+
+ Fixed an issue where the Authentication Portal did not work properly + with session cookies when the request to the portal contained the + header Sec-Fetch-Site=cross-site. +
+
+
PAN-263680
+
+
+ Fixed an issue where Prisma Access gateways consistently stopped + responding with process restarts. +
+
+
PAN-263559
+
+
+ Fixed an issue where the dataplane stopped responding and the firewall + unexpectedly rebooted due to multiple process restarts. +
+
+
PAN-263287
+
+
+ The PAN-COMMON-MIB.my file was updated to support new object + identifiers (OID) to poll interface use via SNMP with table + identifiers. +
+
+
PAN-262340
+
+
+ Fixed an issue where FQDN resolution failed for address objects, and + all FQDN traffic was denied by the interzone-default policy rule. +
+
+
PAN-262254
+
+
+ Fixed an issue where the firewall experienced an OOM condition and the + useridd + process stopped responding, which caused the firewall to drop + interfaces from their respective aggregate groups. +
+
+
PAN-261489
+
+
+ Fixed an issue where an out-of-memory (OOM) condition caused a + firewall outage. +
+
+
PAN-260662
+
+
+ Fixed an issue where large file downloads were slower than expected + when private IP address visibility was enabled. +
+
+
PAN-260512
+
+
+ Fixed an issue where accessing the IP address of the device address + group objects from the user interface caused the + configd + process to stop responding. +
+
+
PAN-260316
+
+
+ Fixed an issue where the + all_task + process stopped responding and the firewall rebooted. +
+
+
PAN-259910
+
+
+ Fixed an issue where the firewall reported the same value over + consecutive SNMP polls when asynchronous mode was enabled. +
+
+
PAN-259767
+
+
+ Fixed an issue where GlobalProtect users were unable to connect when + the option + Block sessions if the certificate was not issued to the + authenticating device + was enabled in the certificate profile. +
+
+
PAN-259002
+
+
+ Fixed an issue where frequent external dynamic list updates caused the + configd + process to restart. +
+
+
PAN-257736
+
+
+ (PA-5450 firewalls only) Fixed an issue where + traffic to benign applications was was impacted by holding TCP + sequential segments for MLC inspection and not releasing the full + chain after a benign verdict was received. +
+
+
PAN-257601
+
+
+ (PA-5450 firewalls only) Fixed an issue where + Networking Cards (NC) experienced an internal link fault which caused + path monitoring failure on the Dataplane Processing Card (DPC). +
+
+
PAN-257327
+
+
+ (PA-5440 firewalls only) Fixed an issue where a + failover event occurred unexpectedly on the firewall. +
+
+
PAN-256077
+
+
+ Fixed an issue where the GlobalProtect client would disconnect + consistently due to keep-alive timeouts when using an SSL-only tunnel. +
+
+
PAN-254704
+
+
+ (LSVPN Portal firewalls in active/passive HA configurations only) Fixed an issue where the satellite cookie key did not sync between + LSVPN portal HA firewalls, which resulted in re-authentication of + satellites with the portal during the event of HA failover. +
+
+
PAN-251973
+
+
+ Fixed an issue where the firewall did not detect evasions due to TCP + checksum offloading not being enabled. +
+
+
PAN-250394
+
+
+ Fixed an issue where a large amount of group data caused serialization + errors and prevented synchronization. +
+
+
PAN-250371
+
+
+ Fixed an issue where the + logrcvr + process stopped responding, which caused commits to fail with the + error message + Management server failed to send phase 1 to client logrcvr. +
+
+
PAN-240990
+
+
+ Fixed an issue where + l3svc.py displayed incorrect + logs. +
+
+
PAN-239952
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where HA sync messages from the active firewall took + longer than expected to reach the passive firewall. +
+
+
PAN-230893
+
+
+ Added a CLI command to address an issue where system lock files + blocked authentication. +
+
+
PAN-230825
+
+
+ Fixed an issue where link flaps occurred on Panorama appliances in HA + configurations. +
+
+
PAN-225213
+
+
+ Fixed an issue where + Push All Changes displayed changes + that were already committed in the push scope for another device group + after performing a selective commit and selective push to the first + device group. +
+
+
PAN-222542
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where Log Forward Cards (LFC) were incorrectly identified as + distribution policies, which caused packet loss due to traffic, BFD, + and other control packets being forwarded to the LFC. +
+
+
PAN-214773
+
+
+ Fixed an issue where RTP packets traversing inter-vsys were dropped on + the outgoing vsys. +
+
diff --git a/reference/PAN-OS/addressed/11.2.5-h2.html b/reference/PAN-OS/addressed/11.2.5-h2.html new file mode 100644 index 0000000..048f19a --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.5-h2.html @@ -0,0 +1,32 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-282022
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700 + appliances. +
+
diff --git a/reference/PAN-OS/addressed/11.2.5.html b/reference/PAN-OS/addressed/11.2.5.html new file mode 100644 index 0000000..02e1223 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.5.html @@ -0,0 +1,2761 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-275905
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected and Elasticsearch CPU usage was high. +
+
+
PAN-274029
+
+
+ Fixed an issue where upgrading Panorama and pushing configurations to + the firewall caused an IKE version mismatch, which resulted in IPSec + tunnel failure with the peer device. +
+
+
PAN-273215
+
+
+ Fixed an issue where a syntax error in the index generation script + caused a high management plane CPU load after upgrading. +
+
+
PAN-273197
+
+
+ Fixed an issue where the endpoint ID was not populated in logs when + the least significant word of the Geneve header was 0. +
+
+
PAN-272085
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is + enabled for DNS Security and multiple DoH transactions are sent in a + single HTTP/1 connection. +
+
+
PAN-271913
+
+
+ Fixed an issue on firewalls in HA configurations where, when using the + Cloud Identity Engine (CIE), the firewall experienced consistent + memory leaks on the active firewall, which caused unexpected + failovers. +
+
+
PAN-271828
+
+
+ Fixed an issue where, after an accumulation proxy changed to + no-decrypt or no proxy, only the Client Hello was sent to Content + Threat Detection. +
+
+
PAN-271613
+
+
+ Fixed an issue where configuration pushes from Panorama to the + firewall failed due to an OOXML commit error. +
+
+
PAN-270569
+
+
+ Fixed an issue where the + userid + process stopped responding due to memory was being reset to NULL when + it was freed. +
+
+
PAN-270549
+
+
+ Fixed an issue where some TLS connections were not handled correctly, + which led to instability in the dataplane. +
+
+
PAN-270224
+
+
+ Fixed an issue where indices were not opened after a query. +
+
+
PAN-269899
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected when querying for device tags. +
+
+
PAN-269673
+
+
+ Fixed an issue where ElasticSearch was not set up after an upgrade. +
+
+
PAN-269539
+
+
+ Fixed an issue where whitespace was added before the timestamp in + syslog logs forwarded from Panorama. +
+
+
PAN-269499
+
+
+ Fixed an issue where the firewall stopped responding when receiving a + high number of logs. +
+
+
PAN-269106
+
+
+ Fixed an issue where the + wifclient might crash during + server cert verification for MICA gRPC connections and cause the + dataplane to restart when using a cloud-based ML detection engine + (MICA). On certain platforms, this caused the firewall to reboot + periodically. +
+
+
PAN-269027
+
+
+ Fixed an issue related to external dynamic lists that caused commit + times on the firewall to be higher than expected. +
+
+
PAN-269000
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL + pointer dereference when path monitoring failed. +
+
+
PAN-268972
+
+
+ Fixed an issue where Panorama was slower than expected when using a + high number of device group tags in a non-shared context. +
+
+
PAN-268909
+
+
+ Fixed an issue where IP address tags were removed from firewalls after + a management server or userid process restart. This occurred when a + Panorama serial-number based configuration was used for User-ID + redistribution. +
+
+
PAN-268815
+
+
+ Fixed an issue that caused the firewall to reboot due to the + wifclient exiting multiple times + when using IoT Security. +
+
+
PAN-268727
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy + was enabled and header insertion modified packets. +
+
+
PAN-268501
+
+
+ Fixed an issue where the firewall was unable to generate a TSF file + due to a full root partition. +
+
+
PAN-268474
+
+
+ Fixed an issue on the firewall where the PAN-DB URL Filtering license + displayed as Valid even when the + firewall did not have the license, which caused traffic to drop. +
+
+
PAN-268419
+
+
+ Fixed an issue where + Managed Devices > Summary + displayed incorrect subcolumns. +
+
+
PAN-268229
+
+
+ Fixed an issue where the firewall stopped responding during session + setup for ECMP hit-count updates. +
+
+
PAN-268228
+
+
+ Fixed an issue where Panorama administrators were unable to select + Edit Selection when pushing changes + to devices if they logged in using TACACS authentication. +
+
+
PAN-268127
+
+
+ Fixed an issue where tagging devices in Panorama did not work as + expected. +
+
+
PAN-268118
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where, + after a failover, irrelevant routing FIB entries were seen in the + routing table on the newly active firewall. +
+
+
PAN-268002
+
+
+ Fixed an issue where URL filtering response pages were not displayed + for sites that were blocked as a result of SSL/TLS handshake + inspection. +
+
+
PAN-267934
+
+
+ Fixed an issue where commits remained at 98%, which resulted in the + BGP connection flapping. +
+
+
PAN-267707
+
+
+ Fixed an issue where BFD sessions did not come up even when BGP + peering was established. +
+
+
PAN-267660
+
+
+ Fixed an issue where UserID stopped working when the + show object registered user CLI + command was used with start-point and limit options. +
+
+
PAN-267535
+
+
+ Fixed an issue where + all_task + processes stopped responding on the remote network firewall, which + caused tunnels to go down and the + pan_task + CPU usage to approach 100%. +
+
+
PAN-267285
+
+
+ Fixed an issue where a port was able to be connected from outside the + network. With this fix, the port is restricted to the local interface. +
+
+
PAN-267091
+
+
+ Fixed an issue on Panorama where Elasticsearch repeatedly restarted. +
+
+
PAN-267001
+
+
+ Fixed an issue where multicast streams were unstable with ECMP and + dropped every 30 seconds. +
+
+
PAN-266900
+
+
+ Fixed an issue on the Panorama web interface where you were unable to + click OK after selecting an install + package type and file from the dropdown and selecting a firewall. +
+
+
PAN-266704
+
+
+ Fixed an issue where filtering BGP routes by peer name in Advanced + Routing Engine (ARE) did not display the correct routes. +
+
+
PAN-266695
+
+
+ Fixed an issue on Panorama where a cyclic nested address group + configuration caused the + configd + process to stop responding after a commit. +
+
+
PAN-266653
+
+
+ Fixed an issue where unexpected path monitor failures caused the + firewall to stop responding. +
+
+
PAN-266639
+
+
+ Fixed an issue where administrators were unable to edit or add virtual + router configurations when a filter was applied to the viewer. +
+
+
PAN-266391
+
+
+ Fixed an issue where the number of hints values were not updated even + when there were no hint files on the system. +
+
+
PAN-266354
+
+
+ Fixed an issue where Hybrid-SWG explicit proxy connections failed when + the number of destination domains exceeded 1024. +
+
+
PAN-266328
+
+
+ Fixed an issue where the firewall was unable to establish a + connection. +
+
+
PAN-266312
+
+
+ Fixed an issue where BFD sessions took longer than expected to + establish after an HA failover due to BGP. +
+
+
PAN-266167
+
+
+ Fixed an issue where the + restart option for IPSec tunnels was + greyed out (Network > IPSec Tunnels > IKE Info). +
+
+
PAN-266003
+
+
+ Fixed an issue on the firewall where a configuration policy push + caused both active and passive firewalls to go down when a high number + of spyware profiles and vulnerability profiles were pushed to the + dataplane. +
+
+
PAN-265973
+
+
+ Fixed an issue where administrator sessions were logged out with an + ERR_CONNECTION_REFUSED error on + the browser. +
+
+
PAN-265963
+
+
+ Fixed an issue where the + escd + process caused a memory leak when session resiliency was enabled on + the firewall. +
+
+
PAN-265931
+
+
+ Added debug functionality in the + packet-diag log to address an + issue regarding policy rule matching. +
+
+
PAN-265742
+
+
+ Fixed an issue on the Panorama web interface where the + OK button on the GlobalProtect + gateway configuration dialog box was not clickable. +
+
+
PAN-265621
+
+
+ Fixed an issue where the + restart option for IPSec tunnels was + greyed out when you attempted to restart the tunnel from + Network > IPSec Tunnels > IKE Info. +
+
+
PAN-265462
+
+
+ Fixed an issue where you were unable to download PDFs when connected + via a Clientless VPN. +
+
+
PAN-265434
+
+
+ Fixed an issue where the flow process restarted with the error message + SIGABRT __GI_raise __GI_abort __libc_message malloc_printer. +
+
+
PAN-265399
+
+
+ Fixed an issue where DNS queries for uppercase internal domain (SRV + record) timed out when DNS Security was enabled. +
+
+
PAN-265349
+
+
+ Fixed an issue where multiple segments of HTTP proxy connect messages + were not handled correctly by proxy. +
+
+
PAN-265344
+
+
+ Fixed an issue where + Import GlobalProtect Client Package + did not work after clicking OK after + selecting a valid package under + Device > GlobalProtect Client > Upload). +
+
+
PAN-265179
+
+
+ Fixed an issue where a kernel race condition caused the firewall to + reboot with a kernel panic. +
+
+
PAN-265160
+
+
+ Fixed an issue where the firewall created multiple connections to a + syslog server and remained in the FINWAIT1 state, which caused logs to + drop while being forwarded to the syslog server. +
+
+
PAN-264981
+
+
+ Fixed an issue on the Panorama web interface where it took longer than + expected to edit Security policy rules. +
+
+
PAN-264871
+
+
+ Fixed an issue on Panorama where the + configd + process stopped responding when viewing IP addresses on dynamic + address groups with a large number of IP addresses. +
+
+
PAN-264806
+
+
+ (PA-3440 firewalls only) Fixed an issue where + the firewall was unable to validate or commit a configuration when it + was imported from another firewall model. +
+
+
PAN-264794
+
+
+ Fixed an issue where OSPF adjacencies failed to come up when using a + subinterface ID with more than 3 digits on Ethernet ports 1/10 and + higher. +
+
+
PAN-264680
+
+
+ (PA-220 firewalls only) Fixed an issue where + Device > Setup was not displayed + on the web interface. +
+
+
PAN-264678
+
+
+ Fixed an issue where + Preview Changes did not display + configuration changes in + Commit and push > + Push Scope. +
+
+
PAN-264662
+
+
+ Fixed an issue where HTTP POST requests were blocked for URLs that had + the block-continue category + configured. +
+
+
PAN-264289
+
+
+ Fixed an issue where the CLI and XML API values for the show system + environment command did not match. +
+
+
PAN-264169
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where the firewall sent correlated event logs to the syslog server + using the management interface instead of the log interface. +
+
+
PAN-263987
+
+
+ Fixed an issue on the firewall where, when a NAT transversal IPSec + tunnel was terminated, and the NAT rule that was applied to the NAT-T + IPSec tunnel was on the same firewall, traffic flowing through the + tunnel was not correctly translated. +
+
+
PAN-263973
+
+
+ Fixed an issue where log collectors had a low incoming log rate. +
+
+
PAN-263956
+
+
+ (PA-440 firewalls only) Fixed an issue where a + firewall running PAN-OS 11.1.2-h3 only displayed the + Auto option for the interface duplex + setting. +
+
+
PAN-263843
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall received no-license packet buffers instead of memory + based packet buffer numbers. +
+
+
PAN-263749
+
+
+ Fixed an issue where disk space that was used by file descriptors was + not freed, which caused the root partition to become full and Panorama + to be inaccessible. +
+
+
PAN-263505
+
+
+ (PA-850 firewalls only) Fixed an issue where + the firewall stopped responding and rebooted after upgrading to PAN-OS + 11.1.4. +
+
+
PAN-263369
+
+
+ Fixed an issue where commits from Panorama to Panorama virtual + appliances failed with the error message + Internal error during commit processing. Commit/Validate + failed + after upgrading Panorama. +
+
+
PAN-263291
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when + the GlobalProtect clientless VPN was configured. +
+
+
PAN-263278
+
+
+ Fixed an issue where the management interface flapped when IPv6 was + disabled and DHCPv6 was enabled. +
+
+
PAN-263208
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an + issue where interrupts were generated at a certain packet rate, and + dataplane processes missed heartbeats, which caused the dataplane to + go down. +
+
+
PAN-263164
+
+
+ Fixed an issue where Netflow User ID information was truncated to 31 + characters. +
+
+
PAN-263086
+
+
+ (PA-455 firewalls in HA configurations only) + Fixed an issue where the HA LED light on the front panel did not turn + on even when HA was enabled. +
+
+
PAN-263012
+
+
+ Fixed an issue where commits failed from a Panorama appliance with a + default master key to a firewall with a master key configured and a VM + Information source configured. +
+
+
PAN-262973
+
+
+ Fixed an issue where changes made by a custom role Panorama + administrator did not display in the push scope for other custom role + administrators when a full commit was performed. +
+
+
PAN-262902
+
+
+ Fixed an issue on the web interface where cloning region objects did + not work. +
+
+
PAN-262511
+
+
+ Fixed an issue on firewalls in HA configurations where OSPF neighbors + were not established after an HA failover. +
+
+
PAN-262415
+
+
+ Fixed an issue where a partial configuration load failed for + configuration files that contained + regenerate-hostkeys. +
+
+
PAN-261997
+
+
+ Fixed an issue where the firewall displayed incorrect statistics for + mac_transmit_err and send_deffered on PA-440 appliances running PAN-OS + 10.1.9-h3. +
+
+
PAN-261909
+
+
+ Fixed an issue where the GlobalProtect client did not display the + dialog box for an MFA verification code. +
+
+
PAN-261831
+
+
+ (Firewalls in HA configuration only) Fixed an + issue where link-down events did not occur after an HA failover. +
+
+
PAN-261673
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled, + traffic was dropped because of the 'flow_parse_ip_hdr' counter related + to an Nvidia driver issue. +
+
+
PAN-261671
+
+
+ Fixed an issue where GlobalProtect clients randomly fell back to the + SSL tunnel as the gateway dropped the initial three keepalive packets. +
+
+
PAN-261639
+
+
+ Fixed an issue where the firewall incorrectly logged the XFF IP in + threat logs when a single HTTP header was used. +
+
+
PAN-261570
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where packet loss occurred when dataport was used + for HA3 for asymmetrically routed traffic during commits and a virtual + wire was configured . +
+
+
PAN-261485
+
+
+ Fixed an issue where the firewall dropped the Real Time Transport + Protocol (RTP) session for the second SIP call on Persistent-DIPP + connections when the source port of the client device was reset. +
+
+
PAN-261484
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount + of memory as requested for pre-allocation. +
+
+
PAN-261371
+
+
+ (PA-5410 firewalls in active/passive HA configurations only) Fixed an issue where the + reportd + process restarted, which caused the firewall to reboot. +
+
+
PAN-261209
+
+
+ (Firewalls in active/active HA configuration only) Fixed an issue where the firewall displayed the HA2 status as down + when the HSCI port was used for both HA2 and HA3. +
+
+
PAN-261174
+
+
+ Fixed an issue on Panorama where importing a certificate for a + template stack configuration incorrectly prompted for a passphrase as + a required field. +
+
+
PAN-261028
+
+
+ Fixed an issue where the firewall did not autocommit after a reboot + when the cellular interface was configured as a local interface for + the IPSec Satellite and the IP address was allocated dynamically. +
+
+
PAN-261001
+
+
+ Fixed an issue where GlobalProtect users were unable to switch + gateways after upgrading to GlobalProtect version 6.2.3. +
+
+
PAN-260842
+
+
+ A CLI command was introduced to address an issue where TCP packets + were out of order. +
+
+
PAN-260796
+
+
+ Fixed an issue where servers were not accessible through an active SSL + GlobalProtect VPN tunnel until a new connection was established or the + session was cleared on the firewall. +
+
+
PAN-260738
+
+
+ Fixed an issue on the Panorama web interface where the progress bar + did not complete when importing a vulnerability profile configuration + through an XML file. +
+
+
PAN-260633
+
+
+ Fixed an issue where the firewall did not send a client certificate + after a TLS Certificate Request when establishing a secure syslog + connection. +
+
+
PAN-260604
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput + utilization stats in NetFlow analyzer tools. +
+
+
PAN-260564
+
+
+ Fixed an issue on firewalls in HA configurations where a network loop + was detected by switches after suspending HA on the active firewall. +
+
+
PAN-260549
+
+
+ Fixed an issue where the management plane CPU usage was not calculated + correctly on firewalls with integrated an dataplane and management + plane. +
+
+
PAN-260546
+
+
+ (PA-440 firewalls only) Fixed an issue where + the system clock reset to the epoch date and time after 8 to 12 weeks + of shelf life or no power. +
+
+
PAN-260417
+
+
+ Fixed an issue on Panorama where + UpdateLicDB was triggered every + few minutes when firewalls with PAYG licenses were onboarded. +
+
+
PAN-260358
+
+
+ Fixed an issue where the firewall did not include the NAS-ID and + NAS-IP attributes in the RADIUS Access-Request message when using + PEAP-MSCHAPv2 authentication. +
+
+
PAN-260290
+
+
+ Fixed an issue for fixed model licenses to support new content size + requirements by reducing the total sessions supported to be equivalent + to their flex memory counterpart +
+
+
PAN-260279
+
+
+ Fixed an issue where selective push operations failed with the error + message: + Failed to generate selective push configuration. Schema validation + failed. Please try a full push. +
+
+
PAN-260218
+
+
+ Fixed an issue where BGP Aggregate Advertise filters did not work as + expected when the summary option was enabled, and only summarized + routes were advertised. +
+
+
PAN-260193
+
+
+ Fixed an issue where GlobalProtect on macOS clients did not connect + when using a client certificate and the X.509 policy was set to + Use System Default. +
+
+
PAN-260149
+
+
+ Fixed an issue where the management plane DNS cache size was lower + than expected. +
+
+
PAN-260132
+
+
+ Fixed an issue where secondary IP addresses with a /32 prefix + configured on Layer 3 interfaces were not reachable in FRR mode. +
+
+
PAN-260131
+
+
+ Fixed an issue where the firewall consumed a large amount of memory + when forwarding raw logs. +
+
+
PAN-260114
+
+
+ Fixed an issue where the firewall generated a + devsrvr + core file when processes were restarted. +
+
+
PAN-259883
+
+
+ Fixed an issue where the firewalls behind an Amazon Web Services (AWS) + Gateway Load Balancer (GWLB) stopped responding when processing GENEVE + packets with the reserved bit set. +
+
+
PAN-259881
+
+
+ Fixed an issue on Panorama where traffic log details were not + displayed under detailed log view. +
+
+
PAN-259870
+
+
+ (PA-7000b firewalls only) Fixed an issue where + Luna Network Hardware Security Modules (HSM) did not work after an + upgrade or downgrade. +
+
+
PAN-259802
+
+
+ (Panorama appliances in HA clusters only) Fixed + an issue where, after replacing a secondary Panorama appliance in a + Panorama HA cluster, the ElasticSearch cluster was unable to establish + SSL tunnels due to SSLHandshakeException errors. +
+
+
PAN-259706
+
+
+ Fixed an issue on Panorama where the web interface was slower than + expected or unresponsive when monitoring definitions were added in the + Kubernetes plugin. +
+
+
PAN-259200
+
+
+ Fixed an issue where the firewall displayed truncated zone names in + the Block IP List log when a zone + name contained more than 14 characters. +
+
+
PAN-259078
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and + the following error message was displayed: + Error 500: Internal Server Error. +
+
+
PAN-258996
+
+
+ Fixed an issue where the firewall displayed the SFP ports as + PowerDown when the SFP + transceiver was removed and reinserted or the port was shut down and + brought back up on the peer device. +
+
+
PAN-258757
+
+
+ Fixed an issue on Panorama where upgrades failed with validation + errors. +
+
+
PAN-258736
+
+
+ Fixed an issue where policy rule configurations pushed from Panorama + were not reflected on the firewall if the rule had 63 characters. +
+
+
PAN-258734
+
+
+ Fixed an issue where virtual wire ports did not go down when moving + from an active state to a suspended state. +
+
+
PAN-258680
+
+
+ Fixed an issue on Panorama where, when you removed Security profile + groups from a Security policy rule via the CLI and committed the + change, the Security policy rule was deleted. +
+
+
PAN-258576
+
+
+ Fixed an issue on the Panorama web interface where products in HIP + objects were not displayed correctly. +
+
+
PAN-258570
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the + varrcvr + process progressively using more memory when WildFire file forwarding + is handling PE files. +
+
+
PAN-258240
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where HA path monitoring did not work as expected when using + vwire. +
+
+
PAN-258225
+
+
+ Fixed an issue on the Panorama web interface where Security policy + rules loaded more slowly than expected. +
+
+
PAN-258188
+
+
+ Fixed an issue on Panorama Template where the virtual wire + subinterface page did not display all fields and the + OK button did not work. +
+
+
PAN-258149
+
+
+ Fixed an issue where the firewall dropped the SYN-ACK when using the + TCP Fast Open option. +
+
+
PAN-257961
+
+
+ Fixed an issue on Panorama where + Test Security Policy Match failed + when the From or + To zone fields were populated. +
+
+
PAN-257912
+
+
+ Fixed an issue where the firewall stopped responding when it received + RADIUS traffic and user equipment (UE) traffic at the same time on a + Network Processing Card (NPC) +
+
+
PAN-257660
+
+
+ Fixed an issue where show commands were hidden for superusers in + read-only roles. +
+
+
PAN-257600
+
+
+ Fixed an issue where the firewall returned a 404 error for all sites + accessed through the clientless VPN portal. +
+
+
PAN-257267
+
+
+ (VM-Series firewalls only) Fixed an issue where + observed warning message during commit completion & critical + system log when configuration size exceeded the maximum recommended + configuration size. +
+
+
PAN-257117
+
+
+ Fixed an issue where CSV or PDF exports of zones did not contain all + zones. +
+
+
PAN-257028
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and + displayed the error message + Dataplane down: path monitor failure during the fail-over. +
+
+
PAN-257021
+
+
+ "Fixed an issue on the web interface where + Match Evidence log details for + Monitor > Correlated events did + not populate." +
+
+
PAN-256960
+
+
+ Fixed an issue where a custom portal login page was not displayed + correctly in the GlobalProtect portal when using a customized portal + landing page. +
+
+
PAN-256725
+
+
+ Fixed an issue on the Panorama interface where + Traffic and + Unified event details loaded more + slowly than expected. +
+
+
PAN-256669
+
+
+ Fixed an issue where the memory usage reported by SNMP did not match + the memory usage reported by the top command. +
+
+
PAN-256518
+
+
+ Fixed an issue where Panorama was unable to push firmware updates to a + VM-Series firewall with a PAYG license. +
+
+
PAN-256449
+
+
+ Fixed an issue where DHCPv6 relay was not working in Advanced Routing + mode when the firewall was configured as a DHCP relay agent. +
+
+
PAN-256350
+
+
+ Fixed an issue where, when you cloned an admin role or an LDAP server + profile and then changed the name of the clone, the configuration + change was not reflected on the managed firewall after pushing the + configuration from Panorama. +
+
+
PAN-256320
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where GTP sessions remained as allocated sessions on + the passive firewall even when there were no active sessions. +
+
+
PAN-256115
+
+
+ Fixed an issue where, after replacing a Panorama appliance or log + collector, the secondary Panorama appliance or log collector displayed + a disconnected status for the + inter-log collector connection. +
+
+
PAN-255930
+
+
+ Fixed an issue where persistent DIPP NAT entries were deleted even + when being used during an active session. +
+
+
PAN-255915
+
+
+ Fixed an issue where a memory leak in the + sslmgr + process caused the firewall to restart. +
+
+
PAN-255747
+
+
+ Fixed an issue on the firewall where CLI commands returned + Server error: op command for client dagger timed out as client is + not available. +
+
+
PAN-255360
+
+
+ Fixed an issue where the firewall booted into maintenance mode when + there was no connectivity to the specified hardware security module + (HSM). +
+
+
PAN-254901
+
+
+ Fixed an issue where GlobalProtect user-to-IP address mapping was + removed even though the tunnel for the specific user was up and + traffic was being passed. +
+
+
PAN-254797
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where you were unable to use SNMP polling o monitor the status of + power supply units. +
+
+
PAN-254794
+
+
+ Fixed an issue where the Panorama management server stopped + responding. +
+
+
PAN-254671
+
+
+ Fixed an issue where excessive + Timed out while getting config lock + error messages were generated when making bulk changes via XML API. +
+
+
PAN-254301
+
+
+ Fixed an issue where GlobalProtect logs showed the public IPv4 address + in the private IPv4 address field for logs generated during + portal/gateway negotiation. +
+
+
PAN-254124
+
+
+ (PA-7050 firewalls with DPC and 100G NPCs only) + Fixed an issue on the firewall where you were unable to change the + flow key type from tag to tuple. +
+
+
PAN-253626
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the + firewall, which caused the push operations to intermittently fail. +
+
+
PAN-253584
+
+
+ Fixed an issue where ikemgr process unexpectedly stopped due to a + memory mapping in an incorrect location. +
+
+
PAN-253485
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration + failed on the active firewall with the error + op command for client dagger timed out as client is not + available. +
+
+
PAN-252816
+
+
+ Fixed an issue where multiple SSHD process restarts triggered a + firewall reboot when the login banner and SSH host keys were updated + at the same time. +
+
+
PAN-252801
+
+
+ Fixed an issue where the LSVPN tunnel monitoring status displayed as + No data available after re-key + events. +
+
+
PAN-252604
+
+
+ Fixed an issue where the clientless VPN did not carry authentication + to other tabs. +
+
+
PAN-252370
+
+
+ Fixed an issue where services with the reserved keyword + application-default were allowed. +
+
+
PAN-252300
+
+
+ Fixed an issue where you were unable to select device groups in the + push scope for user accounts. +
+
+
PAN-252270
+
+
+ Fixed an issue on the firewall where changes were incorrectly applied + after a reboot or a restart of the + configd + process. +
+
+
PAN-252224
+
+
+ Fixed an issue where Panorama did not forward logs to a syslog server + over an SSL connection using CRL as a revocation verification method. +
+
+
PAN-252036
+
+
+ Fixed an issue where, when the GlobalProtect portal was not + configured, accessing the GlobalProtect gateway still loaded a portal + malformed page. +
+
+
PAN-252029
+
+
+ Fixed an issue where the firewall stopped responding when processing + authentication requests. +
+
+
PAN-251484
+
+
+ Fixed an issue where the firewall web interface displayed incorrect + PPPoE configuration options under the subinterface of an Aggregate + Ethernet interface. +
+
+
PAN-250928
+
+
+ (PA-5450 firewalls in active/active HA configurations only) Fixed an issue where firewall traffic was silently dropped when + sent to the peer owner. +
+
+
PAN-250703
+
+
+ Fixed an issue where the task manager failed with a 504 error when a + large number of previous jobs or tasks were present. +
+
+
PAN-250443
+
+
+ (VM-Series firewalls only) Fixed an issue where + multiple processes exited due to an OOM condition and caused a network + outage. +
+
+
PAN-249581
+
+
+ Fixed an issue where stale BGP routes were advertised to peers even + when they were not present in the local RIB table. +
+
+
PAN-249533
+
+
+ Fixed an issue where an internal error message was displayed when you + selected + Exclude video traffic from the tunnel (Windows and macOS + only). +
+
+
PAN-249384
+
+
+ Fixed an issue on Panorama where configuration locks were observed + during a partial rulebase commit. +
+
+
PAN-249072
+
+
+ Fixed an issue where content upgrade installation failed with the + error + Error: can't find cert &lt;cert&gt; when using cloud + interfaces. +
+
+
PAN-247052
+
+
+ Fixed an intermittent issue where the OSPF ABR option was disabled + when a static route was added. +
+
+
PAN-246567
+
+
+ Fixed an issue where a firewall with a copper SFP transceiver + (PAN-SFP-CG) flapped during a commit. +
+
+
PAN-246304
+
+
+ Fixed an issue on Panorama where commits failed due to a timeout in + the + sysd + process during decryption. +
+
+
PAN-245545
+
+
+ Fixed an issue where, when you were connected to the VPN and enabled + the client accelerator, you were disconnected from the VPN. +
+
+
PAN-245058
+
+
+ Fixed an issue on the Panorama web interface where tagging a new user + failed the error message + Tags addition failed. +
+
+
PAN-244743
+
+
+ Fixed an issue where intermittent 500 errors occurred when making API + calls to the firewall. +
+
+
PAN-244708
+
+
+ Fixed an issue where the GlobalProtect VPN connection inactivity TTL + value became negative, which caused the VPN to disconnect when the + system time was changed back to the past time. +
+
+
PAN-244039
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the firewall dropped packets when attempting to reuse a TCP session. +
+
+
PAN-243786
+
+
+ Fixed an issue on Panorama where custom GlobalProtect reports + displayed inaccurate values. +
+
+
PAN-242991
+
+
+ Fixed an issue where the web interface stopped responding when you + searched for members in an address group that contained more than 500 + members. +
+
+
PAN-242957
+
+
+ Fixed an issue where the + Rule usage columns of overridden + default policy rules on the Security policy page stopped responding. +
+
+
PAN-242602
+
+
+ Fixed an issue where GlobalProtect clients experienced slow SMB-V3 + download throughput when passing through a Prisma IPSec tunnel and the + firewall and the SMB-V3 session owner dataplane was the same as the + IPSec-ESP tunnel on the multi-dataplane firewall. +
+
+
PAN-238793
+
+
+ (Panorama virtual appliances in Microsoft Azure environments + only) Fixed an issue where a bootstrapped Panorama appliance did not + automatically retrieve the CDL license, which resulted in the firewall + not automatically sending logs to CDL. +
+
+
PAN-238741
+
+
+ Fixed an issue where, after a selective push of the configuration, a + parent device group object with multiple child device groups was not + shown in the device group's push scope. +
+
+
PAN-221096
+
+
+ Fixed an issue where IPSec transport mode failed when the firewall was + the initiator. +
+
+
PAN-216054
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while + it was idle. +
+
+
PAN-214430
+
+
+ Fixed an issue where some commands did not have executable + permissions. +
+
+
PAN-212889
+
+
+ Fixed an issue on Panorama where different threat names were used when + querying a threat under + Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after + clicking a threat name in + Threat Monitor and filtering it in + the global filters. +
+
+
PAN-199141
+
+
+ Fixed an issue where renaming a device group and then performing a + partial commit led to the device group hierarchy being incorrectly + changed. +
+
+
PAN-192176
+
+
+ Fixed an issue where the management server access log file did not + rotate, which caused the root partition to become full and led to + system instability. +
+
+
PAN-76904
+
+
+ (PA-5410 firewalls only) Fixed an issue where + the management interface went down and an error message displayed in + the show interface management CLI + command output. +
+
diff --git a/reference/PAN-OS/addressed/11.2.6.html b/reference/PAN-OS/addressed/11.2.6.html new file mode 100644 index 0000000..9be406e --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.6.html @@ -0,0 +1,1143 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-287812
+
+
+ Fixed an intermittent issue where the dataplane stopped responding + when advanced DNS was enabled. +
+
+
PAN-286255
+
+
+ Fixed an issue where, when the firewall received an unexpected + termination request for SSL sessions, the dataplane experienced a slow + buffer resource leak. +
+
+
PAN-284908
+
+
+ Fixed an issue where retrieving filenames from OneDrive resulted in a + cache miss. +
+
+
PAN-284116
+
+
+ Fixed an issue where mTLS decryption bypass did not work when the + decryption profile was configured with the maximum TLS version as TLS + 1.3. +
+
+
PAN-284036
+
+
+ (PA-450R and PA-450R-5G firewalls only) Fixed + an issue where the maximum temperature threshold and shutdown + threshold were not set correctly. +
+
+
PAN-283467
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall unexpectedly rebooted and entered maintenance mode + due to a ctd-agent out-of-memory (OOM) condition. This occurred during + advanced services load testing and a high volume of IoT EAL log + forwarding. +
+
+
PAN-282968
+
+
+ Fixed an issue where the firewall did not identify the test threat + file when the content was installed via a traditional bootstrap. +
+
+
PAN-282236
+
+
+ Fixed an issue where large IPv6 packets were reassembled incorrectly + on the firewall when the packets arrived fragmented over an IPv4 + tunnel. +
+
+
PAN-282206
+
+
+ Fixed an issue where configuring Secure Web Gateway (SWG) in + no-auth mode led to latency when no + decryption policy rules or + No-decrypt policy rules were + present. +
+
+
PAN-282069
+
+
+ Fixed an issue on Panorama where Security policy rules were removed + from device groups when you cloned or edited Security policy rules + that used more than 63 characters. +
+
+
PAN-282022
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700 + appliances. +
+
+
PAN-280700
+
+
+ Fixed an Issue where commits failed with the error + invalid IPv6 x:x - must be global/link-local unicast + when the management IPv6 address had a specific value. +
+
+
PAN-280471
+
+
+ Fixed an issue where navigating + Panorama > Monitor > Logs was + slower than expected. +
+
+
PAN-279983
+
+
+ (PA-1400 Series firewalls only) Fixed an issue + on the web interface where + Enable Bonjour Reflector was not + displayed (Network > Interfaces > Ethernet Interface). +
+
+
PAN-279746
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client + Hello arrived at the firewall in multiple out-of-order segments and + the traffic was not subject to SSL decryption. +
+
+
PAN-279621
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward + traffic was run. +
+
+
PAN-279197
+
+
+ (PA-450R-5G firewalls only) Fixed an issue + where the firewall stopped responding and displayed the error message + Thermal temperature exceeds system threshold! Shutting down + NOW + even when the firewall was within the threshold. +
+
+
PAN-279191
+
+
+ Fixed an issue where a GlobalProtect gateway stopped responding when + handling HTTP/1.1 traffic with web inspection enabled. +
+
+
PAN-278684
+
+
+ (PA-445 firewalls only) Fixed an issue where + the firewall did not properly power cycle during a reboot. +
+
+
PAN-278322
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) Gateway Load + Balancer (GWLB) deployments only) Fixed an issue where the firewall did not display the correct + source user in traffic logs and session details. +
+
+
PAN-278296
+
+
+ Fixed an issue where the system MAC address of the aggregate interface + was the same on the active firewall and the passive firewall after an + upgrade. +
+
+
PAN-277762
+
+
+ (VM-Series firewalls only) Fixed an issue where + unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2. +
+
+
PAN-277751
+
+
+ Fixed an issue where a policy-based forwarding (PBF) rule with an + action of no-pbf and a service of + TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a + result, traffic was matched by a lower rule with a service of + any and an action of + forward. +
+
+
PAN-277629
+
+
+ Fixed an issue where the firewall did not match the correct policy for + SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS + 10.2.9-h1 to PAN-OS 11.2.3. +
+
+
PAN-277417
+
+
+ Fixed an memory leak issue related to TLS inbound decryption. +
+
+
PAN-277135
+
+
+ Fixed an issue where the firewall stopped responding when a DNS client + closed or reset a TCP connection while the firewall was sending a + response. +
+
+
PAN-276822
+
+
+ Fixed an issue where the packet buffer size increased significantly + when WildFire File Forwarding was continued after a threat detection + and then canceled. +
+
+
PAN-276607
+
+
+ Fixed an issue where GlobalProtect users experienced DNS resolution + timeouts when using Prisma Access. +
+
+
PAN-276546
+
+
+ Fixed an issue where a session lost the PBF rule mapping after a + configuration change or commit. +
+
+
PAN-276177
+
+
+ Fixed an issue where + App Acceleration did not work with + Oracle databases. +
+
+
PAN-276090
+
+
+ Fixed an issue where the DLP feature did not work as expected and + performance issues occurred when uploading files. This was caused by + incomplete error handling when writing CTD WIF messages to shared + memory and incomplete checking of parameters when freeing entries in + the shared memory. +
+
+
PAN-276016
+
+
+ Fixed an issue where Prisma Access cap700 instances did not insert + HTTP headers when accessing certain Google domains if the 32 byte pool + size was low. +
+
+
PAN-275032
+
+
+ (M-600 appliances only) Fixed an issue where + the Elasticsearch cluster certificate (CC) status displayed with a + past expiration date, which caused all shards to be unassigned. +
+
+
PAN-274592
+
+
+ (Firewalls in high availability (HA) configurations only) Fixed an issue where the firewall did not fail over when the active + firewall experienced data plane issues. +
+
+
PAN-274314
+
+
+ (PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400 + Series firewalls only) Fixed an issue where, when the + pan_task + process restarted, control plane packets were dropped, which could + impact LACP and pings to host interfaces. +
+
+
PAN-273949
+
+
+ Fixed an issue where the firewall generated the following error + message in the + snmpd + logs: + pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key + X2F1dGhfa2V5 import from cryptod failed. +
+
+
PAN-273727
+
+
+ Fixed an issue where the firewall skipped the DNS policy rule of a + domain external dynamic list (EDL) during an EDL refresh. +
+
+ To use this fix, run the following CLI command and commit: + set deviceconfig setting ctd custom-edl-domains-continuous-reload + yes/no +
+
+
PAN-273195
+
+
+ Fixed an issue where the firewall did not log the correct NAT IP + address and source zone for HTTP2 traffic with SSL decryption enabled + on RNHP nodes. +
+
+
PAN-273129
+
+
+ Fixed an issue on the web interface where the + negate option was visible when you + clicked on the rule name, but not when you viewed the target options + from the rulebase attribute. +
+
+
PAN-273026
+
+
+ Fixed an issue where traffic logs did not display correctly when + filters were applied. +
+
+
PAN-273021
+
+
+ Fixed an issue where 25G port links did not come up due to a change in + the handling of 25G DAC modules. +
+
+
PAN-272959
+
+
+ Fixed an issue where the firewall generated BGP update packets larger + than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames + were enabled globally. +
+
+
PAN-272849
+
+
+ Fixed an issue where log forwarding to a UDP syslog server stopped + when an unreachable TCP syslog server was configured and applied. +
+
+
PAN-272538
+
+
+ Fixed an issue where the + configd + process stopped responding during a commit-all validation when there + were uncommitted changes and + share-unused-objects-with-devices + was set to off. +
+
+
PAN-272171
+
+
+ Fixed an issue where the firewall dropped the AAAA DNS server response + and caused delays in traffic from Ubuntu or Linux clients when DNS + Security was enabled. +
+
+
PAN-272085
+
+
+ Fixed an issue where the firewall unexpectedly stopped responding and + rebooted when DoH was enabled for DNS Security and multiple DoH + transactions were sent in a single HTTP/1 connection. +
+
+
PAN-271912
+
+
+ Fixed an issue on Panorama where the + configd + process stopped responding when filtering in the configuration audit + window after upgrading to PAN-OS 11.1.3. +
+
+
PAN-271701
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and + Enhanced Application Log stopped working due to incorrect memory usage + accounting, which caused memory usage to remain at 99% after an + extended period of time. +
+
+
PAN-271314
+
+
+ Fixed an issue where pushing changes to a prefix list used for BGP + from Panorama affected OSPF routes. +
+
+
PAN-271273
+
+
+ Fixed an issue where dynamic update downloads failed when + IPv6 firewalling was enabled on the + firewall and both IPv4 and IPv6 were configured on the management + interface. +
+
+
PAN-271181
+
+
+ Fixed an issue where committing changes to Advanced Routing and + redistribution profiles failed while pushing the configuration from + SCM. +
+
+
PAN-271152
+
+
+ (7000-Series firewalls in HA configurations only) Fixed an issue where the firewall failed over into a non-functional + state, and the LFC LED was blinking on the passive firewall. +
+
+
PAN-270607
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where OSPF failed to establish after a failover from + the active firewall to the passive firewall. +
+
+
PAN-270471
+
+
+ Firewalls in active/active configurations only) + Fixed an issue where the firewall did not detect configuration changes + when only the interface of an IKE gateway was changed, which caused + IPSec tunnels to not come up after migrating the IKE gateway IP + address from a subinterface to a physical interface. +
+
+
PAN-269956
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused internal path monitor + failures. +
+
+
PAN-269731
+
+
+ Fixed an issue where Panorama did not display logs from firewalls + after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) + getting restarted continuously. +
+
+
PAN-269291
+
+
+ Fixed an issue where the scheduled report generation script did not + return debug information. +
+
+
PAN-269052
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile + even though the Security policy rule did not have a URL filtering + profile configured. +
+
+
PAN-268705
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP + traffic after upgrading to PAN-OS 10.1.14. +
+
+
PAN-268168
+
+
+ Fixed an issue where uploading files that were 5GB or larger to Google + Drive or YouTube failed when a decryption policy rule for http2 was + enabled. +
+
+
PAN-267662
+
+
+ Fixed an issue where the firewall experienced a memory out-of-bounds + access when the firewall was configured with SD-WAN and the SD-WAN + plugin was loading, which caused the firewall to stop responding and + drop VPN tunnels. +
+
+
PAN-267580
+
+
+ Fixed an issue where an External Dynamic List (EDL) IP address in an + unsupported format was recognized as valid on the firewall. +
+
+
PAN-267489
+
+
+ Fixed an issue where firewalls on PAN-OS 11.2 releases were not able + to successfully onboard to SCM with ZTP due to a commit failure in the + bootstrap process. +
+
+
PAN-267444
+
+
+ Fixed an issue where large file downloads or uploads failed or + remained in an incomplete state when using DLP HTTP2 mirror mode. +
+
+
PAN-265219
+
+
+ (VM-Series firewalls only) Fixed an issue where + GRE traffic did not work properly. +
+
+
PAN-265021
+
+
+ Fixed an issue where the firewall did not inspect NXDomain responses + and follow the regular traffic inspection flow. +
+
+
PAN-261998
+
+
+ Fixed an issue where the firewall configuration process restarted + during an External Dynamic List refresh or a commit and push + operation. +
+
+
PAN-261825
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or + Advanced URL Filtering were enabled. This occurred when the payload + size was greater than 3.5 KB. +
+
+
PAN-261429
+
+
+ Fixed an issue where the + show auth radius-require-msg-authentic + command CLI displayed no output. +
+
+
PAN-260300
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the + all_pktproc + process where DPC slot 3 stopped responding. +
+
+
PAN-260235
+
+
+ Fixed an issue where the firewall sent Threat logs and URL logs to an + external syslog server without Security profile settings when Enhanced + Application Logging was enabled. +
+
+
PAN-260090
+
+
+ Fixed an issue where commit all operations failed when the application + openair-psa was used as a keyword + on a remote network instance that was upgraded to PAN-OS 10.2.4-h20. +
+
+
PAN-260015
+
+
+ Fixed an issue on the firewall where enabling Inline Cloud Analysis + features might cause the firewall to unexpectedly reboot, due to an + issue related to loopback data handling. +
+
+
PAN-259076
+
+
+ Fixed an issue where the firewall displayed an OCSP/CRL check failure + when accessing websites. +
+
+
PAN-257619
+
+
+ Fixed an issue on Panorama where the + Task Manager took longer than + expected to display managed firewall report tasks. +
+
+
PAN-255914
+
+
+ (VM-Series firewalls on AWS environments only) + Fixed an issue where a newly bootstrapped firewall required a + management server restart, relicensing, or license push from Panorama + to invoke the device certificate. +
+
+
PAN-255619
+
+
+ Fixed an intermittent issue where file downloads from websites failed + when decrypting HTTP/2 traffic. +
+
+
PAN-252381
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected when opening interfaces, virtual routers, and zones in a + template or template stack. +
+
+
PAN-245064
+
+
+ (Multi-vsys firewalls only) Fixed an issue + where commits failed on the firewall after selecting + Export or push device config bundle + on Panorama and a force push was required. +
+
+
PAN-233647
+
+
+ Fixed an issue where Panorama management servers generated duplicate + configuration logs. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h1.html b/reference/PAN-OS/addressed/11.2.7-h1.html new file mode 100644 index 0000000..b211603 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h1.html @@ -0,0 +1,349 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-294436
+
+ Fixed an issue where polling failed for ethernet interfaces due to the + physical port counters read from the MAC being 0. +
+
PAN-293842
+
+
+ Fixed an issue where the hybrid-SWG service proxy stopped working + after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to + establish the listening interface. +
+
+
PAN-293673
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM + condition caused by a scheduled log export using FTP to an external + FTP server. +
+
+
PAN-292503
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP + addresses did not display in traffic and threat logs. +
+
+
PAN-291060
+
+
+ Fixed an issue where commits failed due to the configured connected + gateway IPv6 address in the NAT64 policy exceeding the 31 character + limit. +
+
+
PAN-290996
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS + (Connections Per Second) per vsys on firewalls after upgrading to + PAN-OS 11.1.6-h3, even when active connections were present. +
+
+
PAN-290088
+
+
+ Fixed an issue where a memory leak occurred related to the + configd + process when pushing configurations from Panorama to a firewall. This + occurred when the configurations contained shared policy rules. +
+
+
PAN-289714
+
+
+ (Prisma Access only) Fixed an issue where + persistent commit failures occurred due to a missing transformation + script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0. +
+
+
PAN-289268
+
+ Fixed an issue where internet access through Secure Web Gateway (SWG) + proxy nodes did not work when the default internet access policy rule + source user was not known-user. +
+
PAN-288939
+
+
+ Fixed an issue where the + logrcvr + process stopped responding due to an invalid SSL context being used + for socket communication, which caused commits to fail. +
+
+
PAN-284878
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where commits failed due the + useridd + process restarting. +
+
+
PAN-284003
+
+
+ Fixed an issue where clients did not receive a valid response when + when searching a website due to a compression error. +
+
+
PAN-280409
+
+
+ Fixed an issue where the popup window did not appear as expected for + Clientless VPN users. +
+
+
PAN-279901
+
+
+ An issue was fixed where the firewall dropped fragmented TLS + ClientHello packets, which blocked access to certain websites. This + occurred because the packets arrived truncated, in varying sizes and + orders, and the firewall's heuristics failed to handle them correctly. +
+
+ To enable this fix, run: + debug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279690
+
+
+ Fixed an issue where the the + all_pktproc + process stopped responding, which caused the firewall to unexpectedly + restart. +
+
+
PAN-279415
+
+
+ Fixed an issue where service routes configured to use a data plane + interface incorrectly used the management plane interface for traffic + transmission. This issue affected syslog and CRL status traffic when a + custom service route was not configured. +
+
+
PAN-276616
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet + were not visible. +
+
+
PAN-271810
+
+
+ Fixed an issue where auto-negotiation advertised and negotiated 10/100 + half and full duplex. +
+
+
PAN-268787
+
+
+ Fixed an issue where users were unable to log in to Panorama and the + following error message was displayed: + Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of + devices. +
+
+
PAN-255860
+
+
+ (PA-5200 firewalls only) Fixed an issue where + the + all_pktproc + + process stopped responding when the firewall was under a heavy traffic + load. +
+
+
PAN-252706
+
+
+ Fixed an issue where the URL filtering response page for + Continue and + Override did not work with IPv6 + Router Advertisement (RA) or Multicast Listener Query (MLQ) for + IPv6-to-IPv6 and IPv6-to-IPv4 traffic. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h10.html b/reference/PAN-OS/addressed/11.2.7-h10.html new file mode 100644 index 0000000..b511200 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h10.html @@ -0,0 +1,300 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-310868
+
+
+ Fixed an issue where PA Explicit proxy blocked ICMP packets from + flowing towards Envoy for Geneve due to the router not camping MSS + when the MTU was lower in the path. +
+
+
PAN-307901
+
+
+ Fixed an issue where a leak in decryption counters caused resource + exhaustion, which led to a GlobalProtect service outage. +
+
+
PAN-306502
+
+
+ Fixed two issues that impacted TLSv1.2 or earlier sessions when the + traffic matched a decryption policy rule with the no-decrypt action: +
+
    +
  • + Connections failed when both HTTP header insertion (Objects > Security Profiles > URL Filtering > HTTP + Header Insertion) and + Send handshake messages to CTD for inspection + (Device > Setup > Session > Decryption Settings > SSL + Decryption Settings) were enabled. +
  • +
  • + New sessions failed due to software packet buffer resource + depletion, which occurred when + Log Successful SSL Handshake + was disabled in the decryption policy rule and the decryption + profile attached to the rule had both + Block sessions with expired certificates + and + Block sessions with untrusted issuers + disabled. +
  • +
+
+
PAN-306103
+
+
+ (PA-3400 and PA-5400 Series firewalls only) + Fixed an issue where the firewall dataplane frequently restarted when + lockless QoS was enabled +
+
+
PAN-303959
+
+
+ Fixed an issue where traffic was incorrectly identified as + unknown-tcp/unknown-udp due to App-ID resource leak and eventually + dropped. +
+
+
PAN-302767
+
+
+ Fixed an issue where IPv6 IPsec WAN support was not available in + Prisma Access. +
+
+
PAN-301222
+
+
+ Fixed an issue where DNS Security logs incorrectly displayed a + sinkhole action for benign DNS categories due to the firewall saving + the drop or sinkhole action in session flags without discarding the + session. +
+
+
PAN-300638
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall stopped responding due to an out-of-bounds read when + parsing TLS 1.3 clientHello messages with large TLS clientHello + extensions where the + supported_versions extension fell + outside the first TCP segment. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high + packet rates on the synthetic path in DPDK mode. +
+
+
PAN-295803
+
+
+ Addressed a memory leak issue under sc3 and automatic commit recovery + (ACR) code path. +
+
+
PAN-294488
+
+
+ Fixed an issue where certificate data was missing in decryption logs + for No decrypt policy rules and + TLS1.2 traffic after upgrading, and the + Subject Common Name, + Issuer Common Name, + Certificate Start Date, + Certificate End Date, Certificate Serial Number, and + Certificate Fingerprint fields were + blank in the decryption logs. +
+
+
PAN-283563
+
+
+ Fixed an issue where the GlobalProtect gateway firewall intermittently + failed to assign an IP address to GlobalProtect clients from the DHCP + server, even after successfully receiving a DHCP offer. This occurred + when the DHCP retry and timeout settings were overwritten due to + parsing results being stored in the same variable, which caused the + last gateway configuration to take effect. +
+
+
PAN-271438
+
+
+ Fixed an issue where the firewall calculated available memory + incorrectly on CENTOS devices, which caused the firewall to display + high memory usage alerts even when sufficient memory was available. +
+
+
PAN-267328
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused the firewall to stop + processing traffic. +
+
+
PAN-259853
+
+
+ Fixed an issue where, when the DHCP server was enabled for + GlobalProtect, the commit error message was not properly displayed + when Any was selected as the source + interface in the service router configuration (DeviceSetupServiceService Router Configuration). +
+
+
PAN-258039
+
+
+ Fixed an issue where the firewall displayed the incorrect rule name + when a threat log was generated for Inline Cloud Analyzed CMD + Injection Traffic Detection. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h11.html b/reference/PAN-OS/addressed/11.2.7-h11.html new file mode 100644 index 0000000..7e8da3e --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h11.html @@ -0,0 +1,233 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308902
+
+
+ Fixed an issue where, after upgrading to an affected release, the + firewall did not add mTLS websites that required client certificate + authentication via DN list to the ssl-decrypt exclude-cache list. +
+
+
PAN-308654
+
+
+ Fixed an issue where the Elasticsearch Close Indices process closed + more indices than expected and dropped the number of open shards below + the minimum of 800 per Elasticsearch instance. This occurred because + the process did not correctly account for the number of Elasticsearch + instances when calculating the maximum number of allowed open shards. +
+
+
PAN-304718
+
+
+ Fixed an issue where OSPF and BGP outages occurred due to an + all_task + process restart during clientless VPN content rewrite processing. +
+
+
PAN-304576
+
+
+ Fixed an issue where the firewall entered a non-functional state due + to segmentation fault within the + all_pktproc + process that was caused by a session that involved http2 cleartext + traffic +
+
+
PAN-304496
+
+
+ Fixed an issue where, after unregistering an IP tag and registering a + different IP tag for the same IP address via XML API, the dynamic + address group membership was not updated on the dataplane, which + resulted in Security policy rules being enforced incorrectly. +
+
+
PAN-303722
+
+
+ Fixed an issue on the firewall where configuring spyware and + vulnerability profiles in Security policy rules caused a memory leak + in the + devsrvr + process with each configuration commit. +
+
+
PAN-288001
+
+
+ Fixed an issue where devices with 5G cellular modems did not support + the ATT FirstNet auto Access Point Name (APN). +
+
+
PAN-285181
+
+
+ Fixed an issue where the wifclient ran out of memory when Enhanced + Application Logging was enabled and a sudden traffic increase caused a + surge in EAL messages sent through WIF. +
+
+ To use this fix, run the CLI command + debug iot eal memory-gc native +
+
+
PAN-278688
+
+
+ Fixed an issue where DNS Security threat logs were not displayed on + the firewall when packet capture was enabled and the domain name + length was 62 characters. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where an incorrect ASIC configuration caused silent packet drops or + application slowness when receiving a mix of jumbo and non-jumbo + packets. +
+
+
PAN-269228
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused a split brain condition. +
+
+
PAN-267614
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to high CPU utilization on the + mongodb + process. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h12.html b/reference/PAN-OS/addressed/11.2.7-h12.html new file mode 100644 index 0000000..d0dd63a --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h12.html @@ -0,0 +1,525 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-316911
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where a newly bootstrapped firewall required a + management server restart, relicensing, or license push from Panorama + to invoke the device certificate. +
+
+
PAN-315912
+
+
+ Fixed an issue where the Maximum Segment Size (MSS) rewrite + functionality for packets ingressing through SD-WAN interfaces on + firewalls was not optimized. +
+
+
PAN-314147
+
+
+ Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces + with member having different MTU. +
+
+
PAN-313623
+
+
+ Fixed an issue where the + /opt/pancfg/mgmt/ssl/private/ + directory on Palo Alto Networks devices with TPM support became 100% + utilized due to an accumulation of undeleted + .pub_pem files. This occurred + because executing the + show device-certificate status + CLI command initiated a process that generated these files but failed + to remove them, which prevented the fetching of new device + certificates. +
+
+
PAN-313216
+
+
+ Fixed an issue where firewalls with Prisma Access incorrectly + displayed some traffic as unsanctioned in traffic logs for cloud + applications that were tagged as + sanctioned. +
+
+
PAN-312706
+
+
+ Fixed an issue where the firewalls restarted due to a function lacking + a NULL-pointer sanity check. +
+
+
PAN-311512
+
+
+ Fixed an issue where HIP (Host Information Profile) reports were + blocked on GlobalProtect when + Authentication Cookie Usage Restrictions + was enabled and the Prisma Access Agent protocol was in use. This + occurred because the system failed to correctly process HIP messages + that were relayed via IPSec tunnels with a Virtual IP as the source, + leading to their rejection. +
+
+
PAN-309300
+
+
+ Fixed an issue where management plane system resources configuration + size exceeded 28 MB for over 4 hours, and the following error message + was displayed: + Configuration size reaching device capacity limit. +
+
+
PAN-308786
+
+
+ (Panorama appliances only) Fixed an issue where + traffic log queries using the + device_name filter returned no + results, and complex log queries that included negation operators + produced incorrect outputs. +
+
+
PAN-308564
+
+
+ Fixed an issue where packets were dropped on SD-WAN interfaces when a + proxy was enabled due to an MTU inconsistency where the firewall + failed to rewrite the maximum segment size in SYN/ACK packets based on + the SD-WAN virtual interface MTU. +
+
+ Note: This fix does not apply when the traffic + egress interface is SD-WAN Direct Internet Access (DIA) interface + and proxy is enabled. +
+
+
PAN-308507
+
+
+ (Panorama managed firewalls only) Fixed an + issue where the firewall intermittently failed to maintain active log + forwarding streams to Strata Logging Service (SLS) even when duplicate + logging and enhanced application logging were enabled. +
+
+
PAN-308418
+
+
+ Fixed an issue where, when Advanced DNS Security was enabled and + experienced unusually high loads, DNS resolution failures occurred + with the error + resources-unavailable. +
+
+
PAN-306555
+
+
+ Fixed an issue where the firewall stopped responding, which led to + service outages. +
+
+
PAN-304019
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall did not send traffic to SCM or SLS via a configured + explicit proxy IP address when the proxy username was not configured. +
+
+
PAN-303745
+
+
+ Fixed an issue where inter-dataplane forwarding did not work for + sessions ingressing on Slot 2, which resulted in intermittent ping + failures to interfaces on Network Card 2 when traffic was forwarded to + Slot 3. +
+
+ Note: With this fix, after a slot restart, the + global counter will still show dot1q errors for a short period. +
+
+
PAN-302983
+
+
+ Fixed an issue where, after committing changes on Panorama, a shared + post-rule moved to the end of the + post shared rulebase on the + managed device instead of remaining at the top. +
+
+
PAN-302564
+
+
+ Fixed an issue on the firewall where a path monitoring failure + occurred and caused the dataplane to restart. +
+
+
PAN-301653
+
+
+ Fixed an issue where DNS traffic sessions prematurely terminated with + the message + resources-unavailable. This occurred due to IPv4 fragmented DNS responses causing the + Advanced DNS Security module to incorrectly pack the DNS payload + multiple times when forwarding to the cloud for inspection. +
+
+
PAN-300837
+
+
+ Fixed an issue where firewalls experienced multiple reboots due to the + pan_task + process restarting with a SIGSEGV signal. This occurred because the + client-to-firewall side assumed TLS 1.3 for the firewall-server side. +
+
+
PAN-300671
+
+
+ Fixed an issue where traffic reports that were generated with + destination/source and destination/source hostnames were not displayed + in IPv4 format. +
+
+
PAN-300423
+
+
+ Fixed an issue where Data Processing Cards (DPCs) installed in slots 5 + and 6 remained stuck in a starting state with the error + Signal detected for port xeS5-DP0 but Link Down + alerts, which resulted in device instability. +
+
+
PAN-299242
+
+
+ Fixed an issue where the firewall's SSL proxy sent an empty HTTP2 + SETTINGS message to the client before confirming server support, which + caused some clients to incorrectly assume HTTP/2 support and not fall + back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad + Request frames from the server, which prevented the client from + correctly detecting the lack of HTTP/2 support. +
+
+
PAN-298617
+
+
+ Optimized the commit workflow to reduce the size of the effective + configuration, resulting in lower memory consumption. +
+
+
PAN-297708
+
+
+ Fixed an issue where a long-lived session with many Machine Learning + (ML) model triggers caused a memory leak of feature states associated + with the ML model runs. This resulted in Spyware_State failure + increases, allocation max outs, and impaired policy matching. +
+
+
PAN-295802
+
+
+ Fixed an issue where a memory leak related to the + configd + process occurred. +
+
+
PAN-295309
+
+
+ Fixed an issue where OSPF session using MD5 authentication experienced + intermittent flapping due to out-of-order packet processing. +
+
+
PAN-293644
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the + configd + process stopped responding during an External Dynamic List (EDL) + refresh. +
+
+
PAN-290938
+
+
+ Fixed an issue where multiple memory leaks occurred related to the + configd + process. +
+
+
PAN-264762
+
+
+ Fixed an issue where the firewall showed the status of SFP+ interfaces + as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was + connected. +
+
+
PAN-263691
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a + memory leak in the + all_task + process. +
+
+
PAN-248913
+
+
+ Fixed an issue where the Elasticsearch client certificate was not auto + renewed, which caused it to enter a Red state, and logs were not + displayed in Panorama. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h2.html b/reference/PAN-OS/addressed/11.2.7-h2.html new file mode 100644 index 0000000..88c92bb --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h2.html @@ -0,0 +1,135 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-291499
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where newly deployed firewalls were unable to + connect to the Palo Alto Networks Software License Server (SLS) until + after a reboot, license fetch, or management server restart. +
+
+
PAN-290241
+
+
+ Fixed an issue where the + useridd + process became unresponsive, which caused User ID CLI commands to time + out. +
+
+
PAN-287688
+
+
+ Fixed an issue where the firewall failed to connect to the Palo Alto + Networks update server when using a customized service route with the + source interface as MGT. +
+
+
PAN-268680
+
+
+ Fixed an issue where the + configd + process stopped responding when a configuration merge operation + changed. +
+
+
PAN-268522
+
+
+ Fixed an issue where the firewall failed to connect to the update + server with a customized service route when the source interface was + set to MGT and the source address + was set as IPv4. +
+
+
PAN-241230
+
+
+ Fixed an issue where the SNMP get request status value for Panorama + connections was incorrect. +
+
+
PAN-216770
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud + Manager and configured to use a proxy server for external connections, + the management server did not use the configured settings to connect + to the Cloud Management service. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h3.html b/reference/PAN-OS/addressed/11.2.7-h3.html new file mode 100644 index 0000000..b8434aa --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h3.html @@ -0,0 +1,349 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-297458
+
+
+ Fixed an issue where the + all_task_1 + process crashed on the firewall when the wif service wasn't available + because the wif detection ID was not in the current service table. +
+
+
PAN-297261
+
+
+ Fixed an issue where the proxy-protocol debug level was set to + verbose on Prisma Access + instances, even when it was not explicitly configured, which caused + excessive logging by the + pan_task + process. +
+
+
PAN-296519
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an + associated error in + Wifclient + caused the entire pool to close, which resulted in a complete + disconnection. +
+
+
PAN-296478
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10, + GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute + JavaScript links, resulting in an authorization error. This occurred + because the firewall was incorrectly injecting text into URLs when + JavaScript buttons or dropdown menus were clicked within the + Clientless VPN portal. +
+
+
PAN-295812
+
+
+ Fixed an issue where the throughput data on the Switch Card Module + (SCM) was not accurately reported. This issue affected Standard SC + USABN and USABN-2 when using Direct-IO deployment. +
+
+
PAN-294179
+
+
+ Fixed an issue on Panorama where commit versions did not display + correct data in the config audit page even after a refresh. +
+
+
PAN-292202
+
+
+ Fixed an issue where the system logs repeatedly displayed the alert + Clearing snmpd.log due to log overflow + due to the SNMP counters rolling over. +
+
+
PAN-291631
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall frequently rebooted. +
+
+
PAN-291288
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a + pan_task + process restart related to page allocation failures. +
+
+
PAN-290449
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports + were sent in the same email, only the first attached report was + displayed. +
+
+
PAN-288726
+
+
+ Fixed an issue where the + useridd + process stopped responding due to a Security policy rule ID being set + to 0, which caused the last configuration retrieval to fail. +
+
+
PAN-287423
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites + due to the firewall incorrectly setting the IPv6 header flow label to + 0. +
+
+
PAN-286299
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 releases where, after + being offboarded from Panorama, the firewall XML configuration file + retained template information from the previous Panorama + configuration. As a result, when the firewall and its configuration + were imported to another Panorama appliance, all configurations in the + Network and + Device tabs became read-only. +
+
+
PAN-286231
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to + multiple firewalls with different base configurations resulted in + configuration corruption, which caused the firewall to go down. +
+
+
PAN-285285
+
+
+ Fixed an issue where commits remained at 98% completion when static + route configuration cleanup was in progress. +
+
+
PAN-284073
+
+
+ Fixed an issue on the firewall that caused commits to fail and the web + interface to become inaccessible. +
+
+
PAN-279706
+
+
+ (M-600 appliances only) Fixed an issue where + Panorama did not update all + panreplay database entries after + performing a commit and full push to all devices. +
+
+
PAN-277034
+
+
+ Fixed an issue where WildFire reports were not fully displayed and + were not downloadable due to static resources not being found. +
+
+
PAN-276484
+
+
+ Fixed an issue where Panorama did not display license information for + Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes. +
+
+
PAN-259741
+
+
+ Fixed an issue where the firewall dropped GRE keepalive packets that + were encapsulated under another GRE tunnel. +
+
+
PAN-251442
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode if + the authentication process restarted repeatedly. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h4.html b/reference/PAN-OS/addressed/11.2.7-h4.html new file mode 100644 index 0000000..35a3da5 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h4.html @@ -0,0 +1,708 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304088
+
+
+ Fixed an issue where TCP traffic stopped working from Prisma Access + clients to TCP services behind the Service Connection (SC) after a + dataplane upgrade to an affected release. +
+
+
PAN-303559
+
+
+ Fixed an issue where, after manually creating a device telemetry + bundle, the hour_cli_output.txt file within the bundle had a file size + of 0 bytes. This occurred when checking the bundle content after + enabling device telemetry and setting the device telemetry upload + endpoint. +
+
+
PAN-301828
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud + Manager and configured to use a proxy server for external connections, + the management server did not use the configured settings to connect + to the Cloud Management service. +
+
+
PAN-300906
+
+
+ Fixed an issue where XML API commands failed with a + Method not found (policy_xml) + error in dagger.log. The issue was due to missing XML-related + functions for inline-cloud-proxy. +
+
+
PAN-298505
+
+
+ Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, + the vsys ID changed in sequence, causing autocommit failures with + validation errors. This occurred when the multi-vsys firewall had + virtual systems created and pushed from Panorama, and the vsys ID was + not in a correct sequence because the unused vsys was deleted from + Panorama and pushed to devices. +
+
+
PAN-298387
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP + addresses did not display in traffic and threat logs. +
+
+
PAN-297972
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched + Inline Cloud Analysis prefiltering signatures, even when Inline Cloud + Analysis features were not enabled. +
+
+
PAN-297775
+
+
+ Fixed an issue where, after upgrading, the + Visible Virtual Systems field + started to reference the vsys name instead of the vsys ID, which + caused inter-vsys routing to fail. This occurred when a vsys display + name matched one of the vsys IDs. +
+
+
PAN-297240
+
+
+ Fixed an issue where attempting to generate reports in a WildFire FIPS + Private Cloud or WF-500 deployment returned 401 errors. +
+
+
PAN-295560
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors, + tunnel logs were not visible in Panorama or Splunk even though traffic + and threat logs were received. +
+
+
PAN-295385
+
+
+ Fixed an issue where syslog forwarding dropped due to FQDN resolution + failures. +
+
+
PAN-295257
+
+
+ Fixed an issue where, after onboarding a firewall to Panorama, IPsec + tunnels displayed IKEv2 in Panorama, even though the tunnels were + configured with IKEv1 locally on the firewall. +
+
+
PAN-295221
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors, + Traffic and Threat logs were not forwarded to a Splunk server over + UDP. +
+
+
PAN-294893
+
+
+ Fixed an issue where firewalls with the + Send handshake messages to CTD for inspection + setting enabled caused incorrect security policy rules to be matched. + Specifically, traffic not identified as openai-base or openai-chatgpt + applications was incorrectly matched by the + ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected + response page for blocked URLs was not displayed. +
+
+
PAN-294524
+
+
+ Fixed an issue where firewalls and Panorama management servers were + unable to view or download WildFire reports from a WF-500 appliance, + resulting in a 401 error in the report tab. +
+
+
PAN-294320
+
+
+ Fixed an issue where the + mprelay + process repeatedly restarted. +
+
+
PAN-294161
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to the + useridd + process restarting and causing an HA failover. This occurred due to + the + configd + process timing out when running the CLI command + show user user-id-agent config all. +
+
+
PAN-292447
+
+
+ Fixed an issue where Panorama did not display data in the + Feature Adoption tab in Strata Cloud + Manager due to the system creating and deleting a CLI user for each + interval instead of reusing a permanent CLI user for telemetry. +
+
+
PAN-291940
+
+
+ Fixed an issue where the firewall established multiple TCP connections + to a syslog server, which caused logs to be dropped. This occurred + because the firewall established a new TCP session for each transfer + and the sessions were not closed, which resulted in a continuous + increase in connections over time. +
+
+
PAN-291716
+
+
+ Fixed an issue where during a commit, the firewall experienced an + out-of-memory (OOM) condition due to a memory leak and displayed an + error message. This issue caused the device to crash and reboot + unexpectedly. +
+
+
PAN-291653
+
+
+ Fixed an issue where the GlobalProtect host ID field was + intermittently blank in traffic logs on Prisma Access, even when the + user was connected and had the correct host ID information. This + occurred when the IP address to host ID entry expired and the entry + was re-insterted without the dataplane flag being set. +
+
+
PAN-291635
+
+
+ Fixed an issue where cookie surrogate cache entries remained + unresolved after an + idmgr + process reset due to the request not being retransmitted. This + occurred because the timestamp in the cache entry was refreshed even + when the UID was 0, which prevented the retransmission of the request + if the initial response was not received. +
+
+
PAN-291283
+
+
+ Fixed an issue on Panorama where a memory leak associated with the + configd + process occurred during commits, which caused the + configd + process to restart and the commit to fail. +
+
+
PAN-291067
+
+
+ Fixed an issue where the + devsrvr + process periodically exceeded its virtual memory limit and restarted, + which led to intermittent outages. +
+
+
PAN-289859
+
+
+ (Panorama virtual appliances only) Fixed an + issue where Panorama failed to mount logging disks larger than 2TB due + to a partitioning error. +
+
+
PAN-289405
+
+
+ (VM-Series firewalls only) Added the CLI + command + no-refresh-discard-session to + address an issue where the discarded session time to live (TTL) did + not refresh at the default value. +
+
+
PAN-289383
+
+
+ Fixed an issue where the MPLS interface eth1/6 went down and remained + down, even after replacing the SFP with a supported one and adjusting + duplex and speed settings. +
+
+
PAN-289249
+
+
+ Fixed an issue where a memory leak occurred on the + reportd + process when a WildFire update was initiated while device telemetry + data collection was in progress. This resulted in an OOM condition. +
+
+
PAN-289109
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected during configuration operations and a configuration lock time + out occurred during a commit. +
+
+
PAN-288097
+
+
+ Fixed an issue where on the firewall where the + routed + process stopped responding after changing the MTU or any link state + parameters when OSPF and PIM were enabled on the same interface. +
+
+
PAN-287803
+
+
+ Fixed an issue where, after upgrading, certain websites weren't + accessible when the accumulation proxy was enabled. The proxy did not + use the same DF bit state as the original traffic, causing it to be + fragmented and dropped elsewhere in the network. +
+
+
PAN-287782
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP + values from AF11 to CS0 on traffic passing through the firewall, even + when QoS policy rules and DSCP rewrite settings were not configured. +
+
+
PAN-287622
+
+
+ Fixed an issue where IPv6 traffic was affected after upgrading the + firewall. With SSL decryption enabled and a decryption policy + configured for the traffic, the firewall dropped packets due to + receiving a Packet Too Big ICMP + message. This occurred because the PathMTU information update was + incorrect for the TCB (pan-server) when the firewall was acting as a + server. Additionally, the flow label under the IPv6 header was set to + zero while the packet was being transmitted out of the firewall. +
+
+
PAN-287601
+
+
+ Fixed an issue on Panorama where commits took longer than expected. +
+
+
PAN-287387
+
+
+ Fixed an issue on Panorama where API jobs failed with the error + message + Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a + large number of address objects in a single set call. +
+
+
PAN-283053
+
+
+ Fixed an issue where the firewall experienced high disk space + utilization, which caused the firewall to become non-functional. +
+
+
PAN-282277
+
+
+ Fixed an issue where an OOM condition on the + logrcvr + process caused interface flapping, and the interface unexpectedly went + down and then recovered without intervention. +
+
+
PAN-281776
+
+
+ Fixed an issue on the Panorama web interface where the error message + PPPoEv6 Client Interface cannot be enabled with DHCPv6 client + was generated when overriding aggregate interfaces even when no DHCPv6 + or PPPoE was configured. +
+
+
PAN-278836
+
+
+ Fixed an issue where, after an upgrade, GlobalProtect attempted to use + the embedded browser instead of the default browser for gateway + authentication even when it was configured to use the default browser. +
+
+
PAN-272245
+
+
+ Fixed an issue where the + dnsproxy + process stopped responding due to memory corruption caused by a race + condition when the allow list downloading was impacted by a + configuration change. +
+
+
PAN-267450
+
+
+ Fixed an issue where the + reportd + process stopped responding with a SIGSEGV at + schedule_report_es_response. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h7.html b/reference/PAN-OS/addressed/11.2.7-h7.html new file mode 100644 index 0000000..38aaf0b --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h7.html @@ -0,0 +1,96 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-306534
+
+
+ Fixed an issue were the + all_task + process repeatedly restarted due to memory pool corruption when + processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred + due to incorrect buffer length calculations during memory deallocation + when the query name field spanned multiple packets. +
+
+
PAN-305480
+
+
+ Fixed an issue where the + pan_task + process stopped responding while processing DoH JSON format traffic + with DoH Security enabled, which caused missing cross-packet bytes in + the decoded DNS query type field, and the dataplane went down. +
+
+
PAN-305301
+
+
+ Fixed an issue where GlobalProtect notifications in tunnels caused + processes to stop responding and the dataplane to restart due to the + session lookup returning an incorrect session, which resulted in the + data being sent through the wrong tunnel. +
+
+
PAN-292344
+
+
+ Fixed an issue where the firewall rebooted multiple times after an + upgrade if the config contained an EDL (External Dynamic List) that + didn't have an associated certificate profile. +
+
diff --git a/reference/PAN-OS/addressed/11.2.7-h8.html b/reference/PAN-OS/addressed/11.2.7-h8.html new file mode 100644 index 0000000..b5b5399 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7-h8.html @@ -0,0 +1,578 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308727
+
+
+ Fixed an issue where traffic logs for + Remote Networks displayed the source + zone as trust instead of the remote + network name. +
+
+
PAN-308468
+
+
+ Fixed an issue where the firewall rebooted due to the + all_task + process restarting. +
+
+
PAN-303051
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the + reportd + process due to retaining memory that was temporarily used for report + generation instead of releasing the memory for reuse, which resulted + in continuous accumulation and memory exhaustion. +
+
+
PAN-302927
+
+
+ Fixed an issue where, after upgrading Panorama, the + Push to Devices option did not + display selected devices, and the + OK and + Cancel + buttons did not function as expected. Selecting + OK did not close the window, and + selecting Cancel returned to the + main push screen with the push selected devices displaying as empty. + Despite this, selecting Push or + Validate Device Group Push still + pushed to the previously canceled, non-displayed devices. +
+
+
PAN-301801
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process + fluctuated intermittently between green and red states, which led to + interruptions in log collection. This issue occurred when the number + of shards exceeded the cluster's maximum supported threshold of + greater than 1000 shards per Elasticsearch instance. +
+
+
PAN-301691
+
+
+ Fixed an issue where BGP stopped responding with the error message + Too many open files when pushing + 1000 eBGP (External BGP) neighbor configurations. With this fix, the + number of file descriptors for the BGP process is increased from 1024 + to 8192. +
+
+
PAN-301456
+
+
+ Fixed an issue on Panorama where the + debug system reset-ztp CLI + command was unavailable. +
+
+
PAN-300216
+
+
+ Fixed an issue where, when SD-WAN Direct Internet Access was + configured and traffic traversed the cellular interface without a NAT + policy rule, intermittent cellular modem connectivity issues occurred, + which caused the firewall to disconnect and reconnect to the cellular + network. +
+
+ To use this fix, run the CLI command + set session teardown-upon-fwd-zonechange yes. +
+
+
PAN-300138
+
+
+ Fixed an issue where DNS queries stalled or repeatedly time out due to + multiple DNS responses with different CNAME values causing evasion + false positive alerts. +
+
+
PAN-299772
+
+
+ (VM-Series firewalls in active/passive configurations only) Fixed an issue where, after an HA failover event, the newly active + firewall DHCP client interfaces failed to obtain IP addresses + automatically. This occurred because the DHCP client processes did not + initiate the necessary DHCP discover or renew requests +
+
+
PAN-297976
+
+
+ Fixed an issue where the firewall experienced extended boot times + after a reboot due to the + configd + process needing to rebuild the ACE catalog after detecting + discrepancies that were caused by duplicate application checking + between the ACE catalog and content. +
+
+
PAN-297610
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade + due to the + fsck + command scanning drive partitions in parallel with the root partition, + which caused the process to take an extended amount of time. +
+
+
PAN-297005
+
+
+ Fixed an issue where exporting custom reports resulted in empty CSV + files. +
+
+
PAN-296977
+
+
+ Fixed an issue where the web interface became unresponsive when + attempting to view + Ethernet interface details after + applying a filter in + NetworkInterfaces +
+
+
PAN-296752
+
+
+ (PA-1410 Firewalls only) Fixed an issue where + the firewall experienced high management CPU usage and repeatedly + rebooted when attempting to retrieve SMART data. +
+
+
PAN-296694
+
+
+ Fixed an issue where the firewall rebooted due to the + useridd + process repeatedly restarting during an IP-port data type writes to + the redis from multiple sources such as TSA or XML in a scale + environment. +
+
+
PAN-296535
+
+
+ Fixed an issue on the firewall where BGP peers disconnected when more + than 500 BGP neighbors were configured in a single Logical Router +
+
+
PAN-295899
+
+
+ Fixed an issue where DNS resolution failed on Linux machines running + GlobalProtect client version 6.2.6 when connected with DNS Security + enabled. This occurred because the firewall incorrectly discarded DNS + packets when processing multiple DNS requests or responses over the + same session, even when no malicious verdict was received. +
+
+
PAN-295342
+
+
+ Fixed an issue where the + pan_comm + process stopped responding due to insufficient time allocated to read + file descriptors when processing long messages. +
+
+
PAN-295049
+
+
+ Fixed an issue where the + logrcvr + process stopped responding due to memory allocation errors during + Redis communication. +
+
+
PAN-293985
+
+
+ Fixed an issue with the Panorama web interface where admin users were + unable to log in and received the error message + 504: Gateway Timeout. +
+
+
PAN-292770
+
+
+ Fixed an issue where, after reinstalling the device certificate, + delayed telemetry data was displayed in AIOPS. +
+
+
PAN-291661
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after + an upgrade, Elasticsearch intermittently entered into a Red state + before automatically recovering. +
+
+
PAN-288388
+
+
+ Fixed an issue where, after an EDL certificate update or repository + migration, authentication failures caused the firewall to not fall + back to the last successfully cached EDL entries, which led to policy + rules that referenced the EDL to not be enforced. +
+
+
PAN-287842
+
+
+ Fixed an issue where the + comm + process stopped responding due to missing heartbeats, which resulted + in a system alert and HA communication loss on slot1. +
+
+
PAN-285169
+
+
+ Fixed an issue on Panorama where Kerberos superusers were unable to + edit policy rules because the target device tab was grayed out. +
+
+
PAN-281797
+
+
+ Fixed an issue where firewalls became unstable and stopped responding, + which resulted in an OOM condition. +
+
+
PAN-280917
+
+
+ Fixed an issue on Panorama where the WildFire cloud URL contained an + extra period character, which prevented the retrieval of WildFire + analysis reports. +
+
+
PAN-279829
+
+
+ Fixed an issue where NAT pool leaks occurred during a test when RTSP + traffic hit NAT rules. +
+
+
PAN-270554
+
+
+ Fixed an issue where the GlobalProtect client (UWP) or metered hotspot + connections triggered TLS resumption fo GlobalProtect portal + authentication, which caused the portal authentication to fail with a + valid cert required error. +
+
+
PAN-264131
+
+
+ Fixed an issue where the + routed + process core failed the automation run. +
+
+
PAN-209516
+
+
+ Fixed an issue where, when creating an interface, an error occurred + when you clicked OK without + providing a value in the Tag field + even though the field was not displayed as mandatory. +
+
+
PAN-185731
+
+
+ Fixed an issue where the firewall was unable to parse the URL path and + host when the host header was located in a different packet, which + resulted in the firewall not logging the URL path in the first packet. +
+
+ The fix is disabled by default. The following CLI commands can be used + to enable/disable the feature: set system setting ctd + url-crosspkt-host-path-caching enable set system setting ctd + url-crosspkt-host-path-caching disable set system setting ctd + url-crosspkt-host-path-caching default +
+
diff --git a/reference/PAN-OS/addressed/11.2.7.html b/reference/PAN-OS/addressed/11.2.7.html new file mode 100644 index 0000000..a5bd4a3 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.7.html @@ -0,0 +1,2129 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-290803
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom + image, and VM-Series plugin information was not displayed in the + system information. +
+
+
PAN-290542
+
+
+ Fixed an issue where the + all_task + process stopped responding when an additional header logging HTTP + header was split across 2 packets. +
+
+
PAN-290239
+
+
+ (PA-455 firewalls in active/passive high availability (HA) + configurations only) Fixed an issue where, after an upgrade, the TCP session for syslog + forwarding did not resume after the syslog server service was disabled + and then re-enabled, which caused logs to be dropped. This occurred + when the syslog server was down for more than 16 minutes. +
+
+
PAN-289102
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, + PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and + CN-Series firewalls only) Fixed a race condition issue related to predict processing, which + resulted in a dataplane restart and traffic loss. +
+
+
PAN-288930
+
+
+ Fixed an issue where traffic from cloud applications intermittently + matched an incorrect + cloud-apps policy rule when ACE + (App-ID Cloud Engine) was enabled. +
+
+
PAN-287818
+
+
+ Fixed an issue where sessions timed out sooner than expected due to + the + pan_proxy_accumulation_restore_timeout + not initiating when the accumulation + session_init failed. +
+
+
PAN-286897
+
+
+ Fixed an issue where the + pan_task + process stopped responding when the firewall attempted to forward + files to the WildFire public cloud, which caused the dataplane to + experience heartbeat failures. +
+
+
PAN-286857
+
+
+ Fixed an issue where only failed Kerberos authentication events were + logged in auth.log, and + successful authentication events were not logged. +
+
+
PAN-286848
+
+
+ Fixed an issue where ECMP incorrectly balanced sessions across links + based on the configured metric, which led to an imbalance in traffic + distribution and resulted in traffic assignment shifting + disproportionately to routes with lower metrics. +
+
+
PAN-286825
+
+
+ Fixed an issue where GlobalProtect User-ID mappings were lost after 5 + minutes, which caused users to not match User-ID source-based policy + rules. This occurred due to a mismatch between the GlobalProtect + gateway connection settings and the device behavior and when the + inactivity-logout setting was + deleted and set to a different value. +
+
+
PAN-285894
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused the firewall to reboot + unexpectedly, and traffic failures occurred. +
+
+
PAN-285651
+
+
+ (Panorama appliances in active/passive HA configurations on + Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect + unexpectedly. +
+
+
PAN-285597
+
+
+ Fixed an issue where a + routed + process memory leak occurred when advanced routing was enabled. +
+
+
PAN-285590
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments + only) Fixed an issue where the firewall CPU usage reached 100% after + upgrading to PAN-OS 11.1.6-h1. +
+
+
PAN-284117
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where the + vm_agent + process restarted after an upgrade. +
+
+
PAN-284066
+
+
+ Fixed an issue where, after an upgrade, the SNMP polled values for + IF-MIB::ifInErrors displayed a + high number of errors that did not match the values in the CLI show + interface command. +
+
+
PAN-283813
+
+
+ Fixed an issue on Panorama where the web interface performance was + slower than usual when retrieving read-only configurations from + Panorama. +
+
+
PAN-283789
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where, after an upgrade, the + mac receive error counter in + receive incoming errors increased, + which resulted in SNMP alerts. +
+
+
PAN-283644
+
+
+ (Prisma Access only) Fixed an issue where URL + log ingestion decreased after an upgrade, and secondary connections + were lost. +
+
+
PAN-283331
+
+
+ Fixed an issue where selective pushes to managed devices failed when + the User ID Master Device was + configured. +
+
+
PAN-282697
+
+
+ Fixed an issue where traffic was delayed significantly when it used + No Authentication Explicit Proxy and + matched a decryption policy rule. +
+
+
PAN-282640
+
+
+ Fixed an issue where custom reports showed incomplete data when + exported in CSV format from Panorama. +
+
+
PAN-282394
+
+
+ Fixed an issue where a firewall was only able to display a maximum of + 14 permitted IP addresses from a Panorama Template Variable. +
+
+
PAN-282391
+
+
+ (Panorama appliances and Log Collectors only) + Fixed an issue where a VLD memory leak caused increased memory use, + which resulted in OOM errors. +
+
+
PAN-282359
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected. +
+
+
PAN-282240
+
+
+ Fixed an issue where, when attempting to modify an Anti-Spyware + profile via the web interface under a shared location, clicking the + OK button displayed a console + exception error. +
+
+
PAN-281885
+
+
+ Fixed an issue where, when exporting and importing CSV files, the hash + values of pre-shared key variables set at template and template stack + levels changed inconsistently, which resulted in both variables + displaying the same hash value. +
+
+
PAN-281882
+
+
+ Fixed an issue where OSPF redistributed connected routes beyond the + intended loopback IP address. +
+
+
PAN-281649
+
+
+ Fixed an issue where the index size limit was incorrectly calculated + and indices rolled over earlier than expected, which resulted in high + memory and OOM errors. +
+
+
PAN-281540
+
+
+ Fixed an issue where the + logd + process repeatedly restarted when the SD-WAN site name was over 31 + characters and contained certain XML escape characters. +
+
+
PAN-281509
+
+
+ (Panorama appliances only) Fixed an issue where + log exports were slower than expected or failed when filtering logs + after an upgrade, which resulted in timeouts or delays in displaying + logs on the web interface. +
+
+
PAN-281269
+
+
+ (PA-5420 firewalls) Fixed an issue where the + firewall management server memory usage continuously increased. +
+
+
PAN-281264
+
+
+ Fixed an issue where the + routed + process memory usage continuously increased when Advanced Routing was + enabled. +
+
+
PAN-280942
+
+
+ Fixed an issue where the + logrcvr + process stopped responding. +
+
+
PAN-280698
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from + client hello messages that did not fit in a single packet, which + resulted in connection issues. +
+
+
PAN-280532
+
+
+ Fixed an issue where, after disabling and re-enabling the external + syslog server, the TCP session was not resumed, which caused all logs + that were forwarded to the syslog server to be dropped. +
+
+
PAN-280505
+
+
+ Fixed an issue where the web interface did not display a message to + commit prior changes before attempting a partial configuration load. +
+
+
PAN-280477
+
+
+ Fixed an issue on the web interface were you were unable to scroll up + or down to view source zones in a NAT policy rule. +
+
+
PAN-280335
+
+
+ Fixed an issue with an SNMPv3 EngineBoots value discrepancy that + prevented to SNMP server from logging. +
+
+
PAN-280243
+
+
+ Fixed an issue where the firewall lost the pre-shared key + configuration assigned from a PSK variable when an unrelated device + group configuration was loaded. +
+
+
PAN-279691
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs + (security associations) to the passive firewall if the tunnel was not + initially established by the active firewall. +
+
+
PAN-279500
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric + routing environments if the firewall did not see server-to-client + (s2c) packets of the TLS handshake. +
+
+ To use this fix, run the following CLI command: + debug dataplane set ssl-decrypt accumulate-client-hello + asym-disable yes. +
+
+
PAN-279495
+
+
+ Fixed an issue where accessing a URL from the browser returned the + error message + ERR_RESPONSE_HEADERS_TRUNCATED + when the firewall was configured with TLS 1.3. +
+
+
PAN-279400
+
+
+ Fixed an issue where, when + Restrict Certificate Extensions was + enabled on decryption profiles, the basic constraints extension was + overwritten incorrectly. +
+
+
PAN-279336
+
+
+ Fixed an issue where the CLI did not display a message to commit prior + changes before loading a partial configuration. +
+
+
PAN-279176
+
+
+ Fixed an issue where the configuration audit displayed inaccurate + information after partially loading the configuration via the CLI, + which caused the audit to flag the configuration as deleted or + changed. +
+
+
PAN-279065
+
+
+ Fixed an issue where the firewall sent logs with + connection succeeded to the syslog + server every time a connection was established, which resulted in + excessive logs. +
+
+
PAN-278981
+
+
+ Fixed an issue where DNS domain resolutions experienced intermittent + delays due to the firewall not connecting to the DNS Security cloud. +
+
+ To use this fix, enable DNS monitoring on the dataplane via the CLI + command + debug dnsproxyd enable-rtsig-health-monitor yes. +
+
+ To show the current setting, run the CLI command + debug dnsproxyd enable-rtsig-health-monitor show. If the + cfg.general.dns-rtsig-monitor-interval + shows a non-zero value, DNS monitoring is enabled. +
+
+
PAN-278812
+
+
+ Fixed an issue where authentication to GlobalProtect failed with the + error message + User not in allowed list. +
+
+
PAN-278461
+
+
+ (Firewalls deployed in Amazon Web Services (AWS) environments + only) Fixed an issue where DNS Security retransmit packets were not + re-encapsulated into Geneve, which caused DNS requests that were + initiated from the firewall to be returned to AWS GWLB. +
+
+
PAN-278190
+
+
+ Fixed an issue on Panorama where a scheduled report with SLS data had + an invalid translated-query. +
+
+
PAN-278150
+
+
+ Fixed an issue where the firewall removed the Authentication Key + Identifier (AKID) from the certificate during SSL decryption, which + caused Python 3.13 to fail with a certificate verification error. +
+
+
PAN-277808
+
+
+ Fixed an issue where the + eproxy. process stopped responding when running a long duration test using + IXload with hybrid SWG SAML authentication bypass for HTTPS payloads, + which caused the proxy to become unreachable. +
+
+
PAN-277631
+
+
+ Fixed an issue where the + logrcvr + process discarded logs due to a full queue. +
+
+
PAN-277464
+
+
+ Fixed an issue with intermittent access and slower than expected + loading times when accessing websites. This occurred when Anti-Spyware + inline cloud analysis was enabled and the + SSL Command and Control action was + not either allow or + alert and server hello packets were + out of order. +
+
+
PAN-277234
+
+
+ Fixed an issue where a device group import resulted in a Security + policy rule being created with + Application set to + none. +
+
+
PAN-277147
+
+
+ Fixed an issue where daily scheduled reports were not generated and + emailed. +
+
+
PAN-276920
+
+
+ Fixed an issue where web-advertisement traffic was not immediately + blocked which resulted in pages loading indefinitely. +
+
+
PAN-276678
+
+
+ Fixed an issue where Panorama became unresponsive while performing a + dynamic address update without a lock. +
+
+
PAN-276276
+
+
+ (PA-450 firewalls only) Fixed an issue where, + after an upgrade, data that was excluded using the query builder in a + custom report was still visible in the report, and the logs displayed + errors related to invalid threat names being queried. +
+
+
PAN-276062
+
+
+ Fixed an issue where importing a firewall with a large number of + address objects into Panorama did not work and remained at 99% + completion. +
+
+
PAN-275754
+
+
+ Added support for bootstrapping Panorama virtual appliances on ESXi. +
+
+
PAN-275718
+
+
+ Fixed an issue where Panorama stopped forwarding logs to a syslog + server after upgrading to PAN-OS 11.1.5-h1. +
+
+
PAN-275713
+
+
+ Fixed an issue where the + dscd + process stopped responding when + Endpoint Serial Number was enabled, + which resulted in the **Active Directory* returning a list of serial + numbers for a specific firewall from the Cloud Identity Engine. +
+
+
PAN-275133
+
+
+ Fixed an issue where HTTP 503 server errors occurred while browsing + websites due to slow Secure Web Gateway (SWG) bypass rule lookup. +
+
+
PAN-275077
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain + URLs as Alert instead of taking a Sinkhole action, even when + configured to Sinkhole malicious DNS domains. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) Fixed an issue + where, after an upgrade, the firewall was unable to send logs to the + Strata Logging Service (SLS) when using a specific proxy server, and + the SSL connection status displayed as failed when attempting to + forward logs through the web proxy. +
+
+
PAN-274806
+
+
+ (PA-5250 firewalls only) Fixed an issue where + IPv6 pings experienced a high number of dropped packets when forwarded + to another dataplane, which resulted in ping failures. This occurred + when initiating a ping to the link local address of the firewall and + the packet drop percentage depended on the number of dataplanes. +
+
+
PAN-274797
+
+
+ Fixed an issue where a DPC on slot 3 failed intermittently due to the + pktlog_forwarding process + restarting, which resulted in an unexpected HA failover. +
+
+
PAN-274750
+
+
+ Fixed an issue where the detailed log view in Panorama did not display + all packet details for traffic logs received from the cloud. +
+
+
PAN-274726
+
+
+ Fixed an issue where Wildfire signature generation was enabled on all + nodes in a cluster instead of only the active node. +
+
+
PAN-274697
+
+
+ Fixed an issue where push operations from Panorama failed on passive + firewalls when an application was removed from a Security policy rule + and the policy rule was referenced in a device group. +
+
+
PAN-274671
+
+
+ Fixed an issue where empty traffic + logdb folders were generated for + each day even when trafcfic logs were not received by the + logrcvr + process. +
+
+
PAN-274569
+
+
+ Fixed an issue where the QSPF transceiver interface displayed an + incorrect range figure on the temperature alarm. +
+
+
PAN-274496
+
+
+ Fixed an issue where the root partition reached 100% which caused the + system to become non-functional and failover even when aggressive + cleaning was enabled. +
+
+
PAN-274146
+
+
+ Fixed an issue where the firewall rebooted continuously after + upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in + a Gateway Load Balancing (GWLB) scenario and no data packet was + associated with the packet. +
+
+
PAN-273964
+
+
+ Fixed an issue where SNMP scans to a firewall timed out after + upgrading to a PAN-OS 10.2 release. +
+
+
PAN-273694
+
+
+ Fixed an issue where the firewall rebooted due to an out-of-bounds + memory access that occurred as a result of the SIP content length + value being split across packets. +
+
+
PAN-273614
+
+
+ Fixed an issue where packets were dropped initially when a SYN cookie + with activation threshold 0 was enabled. +
+
+
PAN-273597
+
+
+ Fixed an issue where logs in the cloud database displayed in the + Not-Resolved category but not in the + local database. +
+
+
PAN-273453
+
+
+ Fixed an issue where restarting the firewall did not initiate an + autocommit job, which caused the firewall to stop responding and the + HA interface to go down. +
+
+
PAN-273277
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices were + prompted to enter their username and password for Kerberos SSO + authentication. +
+
+
PAN-273153
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to excessive polling of the + MonitorDirect.getTasks API by the + Task Manager. +
+
+
PAN-273141
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file + transfer download throughput when passing through an IPSec tunnel. +
+
+
PAN-272812
+
+
+ Fixed an issue where SNMP monitoring of tunnel interfaces displayed + zero values for received bytes and packets. +
+
+
PAN-272746
+
+
+ (PA-440 firewalls only) Fixed an issue where + the firewall entered an unstable state after committing changes or + onboarding to Panorama. +
+
+
PAN-272605
+
+
+ Fixed an issue where the firewall did not display VPC endpoints when + there was a large amount of VPC endpoints to interface mappings. +
+
+
PAN-272539
+
+
+ (Panorama appliances on Microsoft Azure environments only) Fixed an issue where user to IP address mapping was missing for + some users connected to specific Prisma Access gateways, which caused + the collection layer Azure firewall to not form the mapping. +
+
+
PAN-272395
+
+
+ Fixed an issue where informational logs caused the + distributord + process log file to be frequently overwritten. +
+
+
PAN-272175
+
+
+ Fixed an issue where session rematch caused ACE cloud application + traffic to match the wrong policy. +
+
+
PAN-271700
+
+
+ Fixed an issue where User-ID connections were lost after an HA + failover. +
+
+
PAN-271560
+
+
+ Fixed an issue where DNS requests to malware sites were not blocked as + expected, and the + dns-security-categories log-level + and action displayed default values instead of + unavailable. +
+
+
PAN-271498
+
+
+ (PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls + in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and + frequent reboots were required. +
+
+
PAN-271425
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue with SSL inbound decryption on firewalls on a vwire + setup with asymmetric routing. +
+
+ To use this fix, enter the CLI command + set system setting ssl-decrypt ha-vwire-mac-learn global yes + on both firewalls in an HA pair. +
+
+
PAN-271184
+
+
+ Fixed an issue where Device Telemetry failed due to an issue with the + encoding of characters in the log file path. +
+
+
PAN-271175
+
+
+ Fixed an issue where the + all_task + process stopped responding with a SIGABRT. +
+
+
PAN-271151
+
+
+ Fixed an issue where the GlobalProtect client did not automatically + initiate a Kerberos SSO connection after logging in to Windows. +
+
+
PAN-270849
+
+
+ Fixed a memory leak issue related to the + configd + process that occurred when running consecutive commits for multiple + days. +
+
+
PAN-270744
+
+
+ Fixed an issue where API calls to Panorama failed with the error + Server error : Timed out while getting config lock. Please try + again. +
+
+
PAN-270379
+
+
+ Fixed an issue where socket files created in the /tmp directory were + not cleared. +
+
+
PAN-270193
+
+
+ Fixed an issue where the Panorama management server changed its + certificate authority (CA) unexpectedly, which caused managed + firewalls to disconnect. +
+
+
PAN-270192
+
+
+ Fixed an issue where Panorama did not display the management IP + address of devices onboarded via ZTP. +
+
+
PAN-269700
+
+
+ Fixed an issue where commits to service connection firewalls from + Panorama failed. +
+
+
PAN-269677
+
+
+ Fixed an issue where Panorama did not check for a NULL pointer when + querying logs, which caused logs to not display on the web interface. +
+
+
PAN-269624
+
+
+ Fixed an issue where GlobalProtect clients failed to connect with the + error message + The device or feature requires a GlobalProtect subscription + license. +
+
+
PAN-269193
+
+
+ Fixed an issue where the firewall redirected the user to the first + application instead of the portal page with a list of applications + when multiple applications were configured for GlobalProtect + clientless VPN along with any user match. +
+
+
PAN-269139
+
+
+ (Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM + environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the + mac receive error counter increased + without an error even though traffic was not impacted. +
+
+
PAN-268708
+
+
+ Fixed an issue where PDF summary and email reports displayed IPv6 + addresses instead of IPv4 addresses. +
+
+
PAN-268614
+
+
+ Fixed an issue on the web interface where, when all rules were + highlighted when a read-only admin user clicked the + Highlight Unused Rules checkbox. +
+
+
PAN-268489
+
+
Fixed a Threat log PCAP ID overwrapping issue.
+
+
PAN-268465
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where the total user count in the registered users was different + between the active and passive firewall. +
+
+
PAN-268279
+
+
+ Fixed an issue where autocommits failed if the management IPv6 gateway + was the same as the dataplane interface IP address. +
+
+
PAN-267759
+
+
+ Fixed an issue where Prisma Access gateway downloads were slower than + expected. +
+
+
PAN-267518
+
+
+ Fixed an issue where WildFire submission logs incorrectly reported + allowed malicious samples even when they were blocked by threat + prevention profiles. +
+
+
PAN-266427
+
+
+ Fixed an issue on the firewall where, when a high number of SD-WAN + branch sites or interfaces were not connected, SD-WAN processes and + tund + processes stopped responding due to a high probing rate. +
+
+
PAN-266116
+
+
+ Fixed an issue where URLs did not work due to certificate revocation + list (CRL) requests failing. +
+
+
PAN-265900
+
+
+ Fixed an issue where the firewall stopped responding due to a + tund + process or SD-WAN process restart. +
+
+
PAN-265791
+
+
+ Fixed an issue where the + all_task process stopped + responding, which caused the dataplane to go down. +
+
+
PAN-264982
+
+
+ (VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the firewall entered maintenance mode after an + auto-commit when sending an ARP packet through the loopback interface + using an IPv6 address. +
+
+
PAN-264708
+
+
+ Fixed an issue where a selective push was blocked when a configuration + load was done. +
+
+
PAN-262729
+
+
+ (Panorama appliances only) Fixed an issue where + the + configd + process experienced continuous high CPU utilization and repeatedly + restarted. +
+
+
PAN-262373
+
+
+ Fixed an issue where the error message + Failed to reload config files + displayed in the system logs even when device telemetry was not + enabled. +
+
+
PAN-262372
+
+
+ Fixed an issue where the firewall generated the error message + Successfully generating a new set of config files + in the system logs even when device telemetry was not enabled. +
+
+
PAN-262063
+
+
+ Fixed an issue where the firewall did not display the converted + configurations before a commit and reboot, and the commit failed when + attempting to migrate from MS to FRR mode. +
+
+
PAN-261597
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused the firewall to become + unavailable. +
+
+
PAN-261312
+
+
+ Fixed an issue where a commit for a policy and configuration dump + overlapped, which resulted in a null pointer exception. +
+
+
PAN-261074
+
+
+ Fixed an issue where the firewall delayed video file transfers over + SMB when Exclude Video Traffic from + the Tunnel feature was enabled and no applications were added to the + list. +
+
+
PAN-260229
+
+
+ Fixed an issue where HA path monitoring using VWire did not work as + expected after a reboot. +
+
+
PAN-259727
+
+
+ (Panorama appliances in HA configurations only) + Fixed an issue where Panorama became unresponsive and displayed a 504 + gateway timeout error when accessing the web interface or the CLI. +
+
+
PAN-259610
+
+
+ Fixed an issue where Wildfire content installation failed for WF-500B + clusters when deployed from Panorama using the deployment schedule. +
+
+
PAN-258743
+
+
+ Fixed an issue where, when you attempted to select a redistribution + profile when creating a BGP Redistribute policy rule, the firewall + displayed an empty dropdown. +
+
+
PAN-258166
+
+
+ (PA-220 firewalls only) Fixed an issue where + the root partition frequently reached 100%. +
+
+
PAN-258162
+
+
+ (Panorama appliances on AWS environments only + Fixed an issue where IP addresses were not retrieved in Dynamic + Address Groups when multiple AND operators were configured. +
+
+
PAN-257183
+
+
+ Fixed an issue where the firewall dropped DNS traffic when using DNS + Security. +
+
+
PAN-256904
+
+
+ Fixed an issue where the firewall inconsistently blocked URLs due to + intermittent URL category misidentification. +
+
+
PAN-256867
+
+
+ Fixed an issue where the + logrcvr + process stopped responding while processing session logs for + forwarding to the LFC. +
+
+
PAN-255759
+
+
+ Fixed an issue where the firewall was unable to match HIP data with + the correct anti-malware object for Windows Defender. +
+
+
PAN-254904
+
+
+ Fixed an issue on Panorama where a core file was generated by + /usr/local/bin/logd during a restart. +
+
+
PAN-254524
+
+
+ Fixed an issue on Panorama where, when the + Commit and Push button was clicked + during a selective + Commit and Push operation, the + window stopped responding, which caused the operation to be delayed. +
+
+
PAN-253127
+
+
+ Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the + hardware pool DFLT became highly utilized, and the packet buffer + gradually increased. +
+
+
PAN-251715
+
+
+ Fixed an issue where the firewall closed the SSL connection to the + user ID agent. +
+
+
PAN-243235
+
+
+ Fixed an issue where Panorama stopped responding and rebooted + repeatedly after an upgrade. +
+
+
PAN-193285
+
+
+ Fixed an issue where the policy optimizer feature did not add entries + back to the mongodb database + after removing them during an upgrade or downgrade. +
+
diff --git a/reference/PAN-OS/addressed/11.2.8.html b/reference/PAN-OS/addressed/11.2.8.html new file mode 100644 index 0000000..0783ae1 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.8.html @@ -0,0 +1,5860 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-297240
+
+
+ Fixed an issue where attempting to generate reports in a WildFire FIPS + Private Cloud or WF-500 deployment returned 401 errors. +
+
+
PAN-296592
+
+
+ Fixed an issue where a 404 error occurred when attempting to download + a sample file. +
+
+
PAN-295049
+
+
+ Fixed an issue where the + logrcvr + process stopped responding due to memory allocation errors during + Redis communication. +
+
+
PAN-294488
+
+
+ Fixed an issue where certificate data was missing in decryption logs + for No decrypt policy rules and + TLS1.2 traffic after upgrading, and the + Subject Common Name, + Issuer Common Name, + Certificate Start Date, + Certificate End Date, + Certificate Serial Number, and + Certificate Fingerprint fields were + blank in the decryption logs. +
+
+
PAN-294436
+
+
+ Fixed an issue where polling failed for ethernet interfaces due to the + physical port counters read from the MAC being 0. +
+
+
PAN-294320
+
+
+ Fixed an issue where the + mprelay + process repeatedly restarted. +
+
+
PAN-293842
+
+
+ Fixed an issue where the hybrid-SWG service proxy stopped working + after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to + establish the listening interface. +
+
+
PAN-293673
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM + condition caused by a scheduled log export using FTP to an external + FTP server. +
+
+
PAN-293484
+
+
+ Fixed an issue where, after upgrading the firewall having an IKE + gateway that uses an aggregate ethernet interface in DHCP client mode, + the IPSec tunnels went down with the error + failed to find a socket for retransmission. +
+
+
PAN-293287
+
+
+ (Panorama virtual appliances in FIPS mode only) + Fixed an issue where plugin installs failed with the error + invalid image after manually + uploading the plugin package from the Customer Support Portal (CSP). +
+
+
PAN-292503
+
+
+ Fixed an issue on the firewall where the source and destination NAT IP + addresses did not display in traffic and threat logs. +
+
+
PAN-292344
+
+
+ Fixed an issue where the firewall rebooted multiple times after an + upgrade if the config contained an EDL (External Dynamic List) that + didn't have an associated certificate profile. +
+
+
PAN-292202
+
+
+ Fixed an issue where the system logs repeatedly displayed the alert + Clearing snmpd.log due to log overflow + due to the SNMP counters rolling over. +
+
+
PAN-291973
+
+
+ Fixed an issue where the Advanced Routing Engine stopped responding + when a route-map was configured to match on a metric with a value of + 0. +
+
+
PAN-291631
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) only) Fixed an issue where the firewall frequently rebooted. +
+
+
PAN-291593
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where, when the passive firewall was down and the + idmr + process was reset, the firewall generated the system log + User-ID manager was reset. Commit is not required to reinitialize + User-ID, even though the + idmr + process restart was not successful. +
+
+
PAN-291499
+
+
+ ( + VM-Series firewalls on Amazon Web Services (AWS) envirobments + only) Fixed an issue where newly deployed firewalls were unable to + connect to the Palo Alto Networks Software License Server (SLS) until + after a reboot, license fetch, or management server restart. +
+
+
PAN-291456
+
+
+ Fixed an issue where the custom completer for device groups and + templates received the device group name and template name from the + running configuration instead of the candidate configuration. +
+
+
PAN-291306
+
+
+ Fixed an issue on the Panorama web interface where you were unable to + override the primary or secondary DNS server address in the template + stack. +
+
+
PAN-291288
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a + pan_task + process restart related to page allocation failures. +
+
+
PAN-291283
+
+
+ Fixed an issue on Panorama where a memory leak associated with the + configd + process occurred during commits, which caused the + configd + process to restart and the commit to fail. +
+
+
PAN-291273
+
+
+ Fixed an issue where a PA-VM-Flex firewall in an air-gapped + environment failed to install the license when bootstrapping after a + factory reset when the ISO image contained a PAN-OS image. +
+
+
PAN-291124
+
+
+ (Firewalls with multi-vsys enabled only) Fixed + an issue where an XML API call to get the running Security policy + rules returned only the first Security policy rules. +
+
+
PAN-291094
+
+
+ Fixed an issue the firewall experienced packet descriptor on chip and + buffer spikes, which led to dropped traffic due to an unidentified + traffic pattern. +
+
+
PAN-291060
+
+
+ Fixed an issue where commits failed due to the configured connected + gateway IPv6 address in the NAT64 policy exceeding the 31 character + limit. +
+
+
PAN-290998
+
+
+ (Firewalls on Microsoft Azure environments only) Fixed an issue where management plane CPU usage was unexpectedly + high for netsec firewall. +
+
+
PAN-290996
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS + (Connections Per Second) per vsys on firewalls after upgrading to + PAN-OS 11.1.6-h3, even when active connections were present. +
+
+
PAN-290923
+
+
+ (Panorama virtual appliances only) Fixed an + issue on the web interface where you were unable to export the + Threat Map. +
+
+
PAN-290900
+
+
+ Fixed an issue where Panorama in FIPS-CC mode failed to push IKEv2 + Post-Quantum Pre-Shared Key (PQ PPK) configurations to firewalls that + were not in FIPS-CC mode. +
+
+
PAN-290702
+
+
+ Fixed an issue where + Log Quotas incorrectly displayed a + value that was higher than possible. +
+
+
PAN-290694
+
+
+ Fixed an issue on the Panorama web interface where you were unable to + push shared objects to devices if an + HA failover occurred during a configuration push. +
+
+
PAN-290691
+
+
+ Added the CLI command + set system setting ctd h323_rtp_predict timeout + to increase the maximum timeout limit from 3600 seconds to 65535 + seconds. +
+
+
PAN-290449
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports + were were sent in the same email, only the first attached report was + displayed. +
+
+
PAN-290241
+
+
+ Fixed an issue where the + useridd process became unresponsive, + which caused User ID CLI commands to time out. +
+
+
PAN-290191
+
+
+ Fixed an issue where BGP learned routes were not advertised when + Legacy Routing was used and an + export policy rule was configured to match the next hop of the learned + route. +
+
+
PAN-290157
+
+
+ Fixed an issue on Panorama where the + configd + process stopped responding when filtering in the + Config Audit window, which caused + Panorama to restart unexpectedly. +
+
+
PAN-290088
+
+
+ Fixed an issue where a memory leak occurred related to the + configd + process when pushing configurations from Panorama to a firewall. This + occurred when the configurations contained shared policy rules. +
+
+
PAN-290074
+
+
+ Fixed an issue where IPv6 URLs were incorrectly categorized as + private-ip-addresses even if the + URL had a valid category. This occurred because the firewall did not + check for IPv6 addresses when determining if an IP address was + private. +
+
+
PAN-289895
+
+
+ Fixed an issue where, when SSL decryption was enabled, traffic + matching a deny rule was incorrectly allowed until the SSL handshake + was complete. +
+
+
PAN-289859
+
+
+ (Panorama virtual appliances only) Fixed an + issue where Panorama failed to mount logging disks larger than 2TB due + to a partitioning error. +
+
+
PAN-289826
+
+
+ Fixed an issue on Panorama where a selective push of policy rule + changes to a firewall caused the firewall to lose its Security policy + rules. +
+
+
PAN-289803
+
+
+ Fixed an issue on the firewall where AIPOs and ADEM licenses failed + when SD-WAN or GlobalProtect licenses were not present. +
+
+
PAN-289763
+
+
+ (PA-5400f firewalls only) Fixed an issue where + SD-WAN SaaS monitoring did not work with URL monitoring. +
+
+
PAN-289714
+
+
+ (Prisma Access only) Fixed an issue where + persistent commit failures occurred due to a missing transformation + script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0. +
+
+
PAN-289652
+
+
+ Fixed an issue related to external URL lists where pushing + configuration changes from Panorama failed. +
+
+
PAN-289573
+
+
+ Fixed an issue on Panorama where the web interface became unresponsive + when attempting to edit the + Allow traffic to specified FQDN when Enforce GlobalProtect + Connection for Network Access + setting in a GlobalProtect portal configuration after adding 40 or + more FQDN entries. +
+
+
PAN-289532
+
+
+ Fixed an issue where, when the Advanced Routing Engine was enabled, + PIM (Protocol Independent Multicast) neighborship was not established + concurrently on multiple interfaces. +
+
+
PAN-289406
+
+
+ Fixed an issue where, when redistributing User-ID information between + firewalls, the receiving firewall incorrectly received and stored + duplicate Host Information Profile (HIP) profiles. This occurred when + a GlobalProtect gateway redistributed User-ID and HIP information + through an intermediate firewall. +
+
+
PAN-289405
+
+
+ (VM-Series firewalls only) Added the CLI + command + no-refresh-discard-session to + address an issue where the discarded session time to live (TTL) did + not refresh at the default value. +
+
+
PAN-289383
+
+
+ Fixed an issue where the MPLS interface eth1/6 went down and remained + down, even after replacing the SFP with a supported one and adjusting + duplex and speed settings. +
+
+
PAN-289320
+
+
+ Fixed an issue where External Dynamic List (EDL) entries for + predefined lists were not visible in Panorama when logged in with a + SuperUser Read-Only role. +
+
+
PAN-289304
+
+
+ (PA-7500 firewalls only) Fixed an issue where + SNMP polling failed due to the + snmpd + process becoming unresponsive to incoming requests, which resulted in + high CPU usage. +
+
+
PAN-289301
+
+
+ Fixed an issue on the Panorama web interface where a template name or + device group name displayed invalid text. +
+
+
PAN-289268
+
+
+ Fixed an issue where internet access through Secure Web Gateway (SWG) + proxy nodes did not work when the default internet access policy rule + source user was not known-user. +
+
+
PAN-289239
+
+
+ Fixed an issue on Panorama where a new virtual system (vsys) was + automatically created with the name of a device group. +
+
+
PAN-289226
+
+
+ (Firewalls in HA active/passive configurations only) Fixed an issue where the firewalls experienced high dataplane CPU + use when NAT64 was enabled. This occurred due to NAT64 traffic not + being offloaded and unnecessary HA session updates being sent for + every NAT64 packet. +
+
+
PAN-289109
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected during configuration operations and a configuration lock time + out occurred during a commit. +
+
+
PAN-288988
+
+
+ Fixed an issue on Panorama where, after logging in to the web + interface as the ZTP installer administrator, the web interface was + blank. +
+
+
PAN-288939
+
+
+ Fixed an issue where the + logrcvr + process stopped responding due to an invalid SSL context being used + for socket communication, which caused commits to fail. +
+
+
PAN-288893
+
+
+ (Firewalls in multi-vsys configurations only) + Fixed an issue where HTTP/2 traffic failed due when one virtual system + (vsys) had a decryption policy rule enabled and another vsys had a + no-decrypt policy rule for the same session. +
+
+
PAN-288731
+
+
+ Fixed an issue where the firewall incorrectly allowed traffic for + certain applications when no decryption policy rule was configured. +
+
+
PAN-288726
+
+
+ Fixed an issue where the + useridd + process stopped responding due to a Security policy rule ID being set + to 0, which caused the last configuration retrieval to fail. +
+
+
PAN-288693
+
+
+ Fixed an issue where importing a device configuration into Panorama + failed with a validation error if the configuration included a shared + gateway with shared address objects. +
+
+
PAN-288617
+
+
+ Fixed an issue where the firewall attempted to connect to + wildfire.paloaltonetworks.com when a user downloaded a WildFire PDF + report from the CSP/WF portal even if the user was not behind the + firewall. +
+
+
PAN-288529
+
+
+ Fixed an issue where the firewall failed to forward critical system + logs to Strata Logging Service due to a reboot. +
+
+
PAN-288432
+
+
+ Fixed an issue where, when Advanced Routing Engine was enabled + firewalls configured with multiple logical routers, static routes were + preferred over eBGP routes even though the static routes had a higher + administrative distance. +
+
+
PAN-288427
+
+
+ Fixed an issue on Panorama where commit jobs were not queued and the + system reported that the + useridd + was not connected. +
+
+
PAN-288426
+
+
+ (M-600 Panorama appliances in Log Collector mode in a Log Collector + group only) Fixed an issue where the + reportd + and + logd + processes stopped responding, which resulted in the Panorama server + not receiving logs from firewalls configured under the Log Collector + group. +
+
+
PAN-288158
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall became inaccessible via the web interface and SSH and + remained in an initializing state. +
+
+
PAN-288140
+
+
+ Fixed an issue where the + debug dataplane sync ippool CLI + command output incorrectly included reserved ports. +
+
+
PAN-288097
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where on the firewall where the + routed + process stopped responding after changing the MTU or any link state + parameters when OSPF and PIM were enabled on the same interface. +
+
+
PAN-287978
+
+
+ Fixed an issue where a directly connected interface or aggregate + interface did not appear in the routing table, which caused ping + failures to the directly connected interface. +
+
+
PAN-287921
+
+
+ (VM-Series firewalls only) Fixed an issue where + the maximum registered IP address for was incorrectly set to 100,000 + instead of the expected 500,000. +
+
+
PAN-287842
+
+
+ Fixed an issue where the + comm process stopped responding due + to missing heartbeats, which resulted in a system alert and HA + communication loss on slot1. +
+
+
PAN-287838
+
+
+ (Panorama appliances only) Fixed an issue on + the web interface where resetting the rule hit counter for multiple + policy rules failed with the error message + Failed to reset rule-hit job. +
+
+
PAN-287765
+
+
+ Fixed an issue where SAML authentication failed, which caused the + GlobalProtect client to repeatedly attempted to reconnect. +
+
+
PAN-287734
+
+
+ Fixed an issue where the error message + Scan ERR: Internal Err 1002 was + generated unexpectedly when WIF shared memory use was high. +
+
+
PAN-287688
+
+
+ Fixed an issue where the firewall failed to connect to the Palo Alto + Networks update server when using a customized service route with the + source interface as MGT. +
+
+
PAN-287621
+
+
+ Added debug logs for an issue where a slow IP address pool NAT leak + occurred when persistent NAT was enabled, which led to NAT IP pool + exhaustion. +
+
+
PAN-287611
+
+
+ Fixed an issue where, after upgrading, the firewall incorrectly + calculated the UDP checksum for RTP traffic after NAT and Security + policy application, which led to dropped packets and silent calls in + applications. +
+
+
PAN-287601
+
+
+ Fixed an issue on Panorama where commits took longer than expected. +
+
+
PAN-287584
+
+
+ Fixed an issue on the web interface where the address object pop up + window only displayed a maximum of four address objects in the policy + rule even after expanding the window. +
+
+
PAN-287558
+
+
+ Fixed an issue on the firewall where the QSFP-40G-SR-BD transceiver + was incorrectly flagged as an unsupported SFP. +
+
+
PAN-287548
+
+
+ Fixed an issue where Security policy rules that had the same + parameters were not detected as shadow rules on commit. +
+
+
PAN-287423
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites + due to the firewall incorrectly setting the IPv6 header flow label to + 0. +
+
+
PAN-287394
+
+
+ (CN-Series firewalls only) Fixed an issue where + the firewall generated critical system log alerts every 3 minutes. +
+
+
PAN-287314
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where an OOM condition occurred and caused a failover due to a memory + leak associated with the + logrcvr + process. +
+
+
PAN-287272
+
+
+ Fixed an issue on the firewall were fan alarms were incorrectly + generated constantly. +
+
+
PAN-287154
+
+
+ Fixed an issue on the firewall where the + show advanced-routing bgp loc-rib-detail + CLI command incorrectly displayed + no BGP route when multiple BGP + peers were enabled. With this fix, the CLI command requires a peer + name to be specified to display local RIB details. +
+
+
PAN-287133
+
+
+ Fixed an issue on the Panorama web interface where assigning a policy + rule to a group at the top or bottom of the list changed the order of + other policy rules. +
+
+
PAN-287056
+
+
+ Fixed an issue where BGP export policy rules with next-hop matching + failed to block the advertisement of static routes, and the firewall + incorrectly matched the egress interface IP address instead of the + original next-hop IP address of the static route, which caused the + deny rule to fail. +
+
+
PAN-287035
+
+
+ Fixed an issue where, when an application stopped responding, a large + file was created in the /opt/panlogs directory, which caused the + partition to fill up. +
+
+
PAN-287023
+
+
+ Fixed an issue where a large number of logs caused the + logrcvr + process to stop responding. +
+
+
PAN-286931
+
+
+ Fixed an issue where syslog forwarding in PAN-OS 11.1 and later + releases did not support service routes when performing certificate + validation over TLS. +
+
+
PAN-286922
+
+
+ Fixed an issue where user-to-IP address mappings were not available on + the dataplane for User-ID, which prevented the enforcement of + user-based Security policy rules. This was due to the firewall not + validating the timestamp of mappings received from certain User + Identification Agent (UIA) agents before adding them to the dataplane. +
+
+
PAN-286899
+
+
+ Fixed an issue where the + device-group-tags CLI command + used an unnecessary configuration read lock. +
+
+
PAN-286832
+
+
+ (VM-Series firewalls only AWS environments only) Fixed an issue where the firewall did not send + ICMP unreachable - Fragmentation Needed + message when it received packets larger than the MTU. +
+
+
PAN-286818
+
+
+ Fixed an issue where closing an SSH session to a Panorama using Ctrl+D + did not generate a log message in the system logs, and the session + remained in an idle state for 60 minutes before being automatically + terminated. +
+
+
PAN-286789
+
+
+ (Panorama virtual appliances in HA configurations on Microsoft Azure + environments only) Fixed an issue where plugin versions displayed when hovering over + the Green Match icon were + inconsistent even though the web interface reported the versions as + matching. +
+
+
PAN-286734
+
+
+ (PA-5450 firewalls only) Added uplink counters + to enhance debug capability for traffic drops. +
+
+
PAN-286673
+
+
+ (Panorama appliances only) Fixed an issue where + the + Require SSL/TLS secured connection + in the LDAP profile within the template stack did not take effect + after overriding the configuration. This occurred even when the + setting was enabled multiple times. +
+
+
PAN-286669
+
+
+ (PA-5410 and PA-5430 firewalls only) Fixed an + issue where SFP28 25G ports using S28-25G-LR transceivers did not come + up after an upgrade when Forward Error Connection (FEC) was disabled + on the ports. +
+
+
PAN-286576
+
+
+ Fixed an issue where the + all_pktproc + process restarted, which caused heartbeat failures to occur and a slot + to go down due to path monitor failure. +
+
+
PAN-286534
+
+
+ Fixed an issue where a multi-vsys firewall was unable to retrieve + address groups and address objects pushed from Panorama as shared + objects when using the REST API. +
+
+
PAN-286492
+
+
+ Fixed an issue on Panorama where logs were not forwarded to syslog + servers due to missing CLI options to configure the syslog queue size + and threads. +
+
+
PAN-286475
+
+
+ Fixed an issue where the option to sort sequence numbers was missing + from Filters prefix list in the + advanced routing filters. +
+
+
PAN-286443
+
+
+ Fixed an issue where, after an upgrade, the firewall was unable to be + managed via HTTPS or SSH. +
+
+
PAN-286306
+
+
+ Fixed an issue where, when getting transceiver information from ESCC + for SFP 25G modules, the transceiver code was incorrectly updated with + Unknown instead of + 25GBase-SR. +
+
+
PAN-286299
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 releases where, after + being offboarded from Panorama, the firewall XML configuration file + retained template information from the previous Panorama + configuration. As a result, when the firewall and its configuration + were imported to another Panorama appliance, all configurations in the + Network and + Device tab became read-only. +
+
+
PAN-286231
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to + multiple firewalls with different base configurations resulted in + configuration corruption, which caused the firewall to go down. +
+
+
PAN-286180
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where, after a failover, an SSH decryption caused a mismatch in + the host key, which resulted in a warning message. This issue occurred + because the SSH tunnel keys were not synchronized between the active + and passive firewalls. +
+
+
PAN-286037
+
+
+ Fixed an issue where the firewall stopped processing traffic. +
+
+
PAN-286034
+
+
+ Fixed an issue where the XML API returned an error when attempting to + view debug log receiver statistics. +
+
+
PAN-285834
+
+
+ Fixed an issue on Panorama where + Policy recommendation displayed + Unable to read data for certain + profiles due to a large response size. +
+
+
PAN-285818
+
+
+ Fixed an issue where a tool was needed to display leaked NAT port + numbers without requiring a forced synchronization. +
+
+
PAN-285759
+
+
+ Fixed an issue where the + configd + process stopped responding during a selective push after a move and + rename operation when the configuration was performed via the CLI. +
+
+
PAN-285680
+
+
+ Fixed an issue where firewalls entered a boot loop after receiving a + HSM configuration template push from Panorama. +
+
+
PAN-285623
+
+
+ Fixed an issue where the + configd + process restarted and generated a core file during an HA sync commit + job. This occurred when the firewall was in the HA passive state. +
+
+
PAN-285615
+
+
+ Fixed an issue where, when the firewall acted as an IKEv2 responder + with fragmentation enabled, the firewall did not send the Notify + message type 16430 “IKEV2_FRAGMENTATION_SUPPORTED” in the IKE_SA_INIT + exchange. This prevented the remote peer from fragmenting subsequent + IKEv2 messages. +
+
+
PAN-285591
+
+
+ Fixed an issue where the Panorama web interface did not display a + warning message when a collector group was configured with a 2 node + cluster. +
+
+
PAN-285436
+
+
+ Fixed an issue where a selective push from Panorama caused the + firewall Security policy rules to be removed on firewalls associated + with the device group. This occurred when the base configuration + version chosen for the selective push preceded the device config + import operation, which caused the imported configuration to not be + included in the pushed configuration. +
+
+
PAN-285325
+
+
+ Fixed an issue on Panorama where tags were not automatically populated + in the Security policy rule when searching by name in the tag field. +
+
+
PAN-285298
+
+
+ Fixed an issue where the firewall became unresponsive when the + show user user-ids user all CLI + command was executed repeatedly on large scale LDAP group mappings, + and you were unable to connect to the gateways with the error message + The network connection is unreachable or the gateway is + unresponsive. Check the network connection and reconnect. +
+
+
PAN-285285
+
+
+ Fixed an issue where commits remained at 98% completion when static + route configuration cleanup was in progress. +
+
+
PAN-284907
+
+
+ Fixed an issue where the Panorama web interface displayed + No Data when viewing configuration + logs to see changes before and after a configuration change. +
+
+
PAN-284878
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where commits failed due the + useridd + process restarting. +
+
+
PAN-284866
+
+
+ Fixed an issue where the LFC failed to validate Certificate Revocation + Lists (CRL) for SSL syslog connections, which caused a failure to + forward logs to external syslog servers. +
+
+
PAN-284840
+
+
+ (PA-5220 firewalls only) Fixed an issue where + custom reports were delayed when sent via email instead of being sent + at the scheduled time. +
+
+
PAN-284717
+
+
+ Fixed an issue where a PBF (Policy Based Forwarding) policy rule using + an AE (Aggregate Ethernet) interface configured with DHCP as the + egress interface incorrectly transitioned to an active state after a + commit operation, even when the DHCP lease had expired and the + interface had no assigned IP address. +
+
+
PAN-284527
+
+
+ Fixed an issue where, when a firewall had more than 4,400 logical + interfaces, commits failed with the error message + Error pre-installing config failed to handle CONFIG_COMMIT. +
+
+
PAN-284441
+
+
+ Fixed an issue where, after upgrading the firewall, GlobalProtect + connections failed with the error message + Network Connection is unreachable. +
+
+
PAN-284380
+
+
+ Fixed an issue where committing a custom report in Panorama + incorrectly generated a pending push to devices. +
+
+
PAN-284283
+
+
+ Fixed an issue on Palo Alto Networks firewalls running PAN-OS 11.1.6 + where the CLI command + traceroute ipv4 yes host <host> + failed with a + missing argument error message. +
+
+
PAN-284184
+
+
+ (VM-Series firewalls with Advanced Routing Engine enabled only) Fixed an issue where the + frr_ns2_bgpd + process repeatedly restarted after committing a configuration that + included the same route-map in both the exist and non-exist clauses of + a conditional advertisement or when the same route-map was used in + both the Advertise-out and conditional exist out map configurations. +
+
+
PAN-284176
+
+
+ Fixed an issue where QoS throughput limits were not enforced correctly + on aggregate ethernet interfaces. As a result, when QoS was enabled on + aggregate interfaces, the subnet index was not handled correctly, + which caused traffic shaping to be misdirected. +
+
+
PAN-284090
+
+
+ Fixed an issue where GlobalProtect (GP) portal authentication for + satellites using RADIUS authentication failed due to the + authentication timeout value being set to 0. +
+
+
PAN-284069
+
+
+ Fixed an issue where, after an upgrade, the total number of logout + records in the HIP database incorrectly displayed as zero. +
+
+
PAN-284067
+
+
+ Fixed a cumulative memory leak in the + devsrvr + process that occurred whenever the CLI command + show running application statistics + was issued. This memory leak would gradually consume system memory and + produce an out-of-memory (OOM) condition, causing the firewall to + reboot. +
+
+
PAN-284003
+
+
+ Fixed an issue where clients did not receive a valid response when + searching a website due to a compression error. +
+
+
PAN-283979
+
+
+ Fixed an issue where the firewall became non-functional due to high + root partition use. +
+
+
PAN-283954
+
+
+ Fixed an issue where the + configd + process stopped responding due to a circular reference between address + groups. +
+
+
PAN-283936
+
+
+ (Panorama appliances only) Fixed an issue where + the + configd + process intermittently restarted, which caused Panorama to be + temporarily unavailable. +
+
+
PAN-283864
+
+
+ Fixed an issue where DNS Security Category exceptions created with DNS + category UTID were not ignored. +
+
+
PAN-283741
+
+
+ Fixed an issue where HTTP/2 child streams were blocked by + strict-ip-check zone protection + when traffic passed through a transparent proxy. +
+
+
PAN-283613
+
+
+ Fixed an issue on the web interface where the + IP Tag + Quota(%) value displayed as 2 even + when changed. +
+
+
PAN-283575
+
+
+ Fixed an issue where iPerf file transfers between a client and server + were slower than expected when the firewall was involved in the + traffic flow due to + cfg.uplink-buffer-resize not + being enabled by default. +
+
+
PAN-283563
+
+
+ Fixed an issue where the GlobalProtect gateway firewall intermittently + failed to assign an IP address to GlobalProtect clients from the DHCP + server, even after successfully receiving a DHCP offer. This occurred + when the DHCP retry and timeout settings were overwritten due to + parsing results being stored in the same variable, which caused the + last gateway configuration to take effect. +
+
+
PAN-283544
+
+
+ Fixed an issue where a failover event caused packet loss due to a + delay in the child error indication. +
+
+
PAN-283524
+
+
+ Fixed an issue where commits failed when a certificate with a + cryptographic setting of RSA 4096 was used in the Syslog Service + Profile due to the firewall being unable to decrypt the private key + due to an incorrectly hardcoded private key length. +
+
+
PAN-283522
+
+
+ Fixed an issue where the SAML single log out (SLO) URL was not + correctly displayed in the web interface after it was changed in the + SAML profile. +
+
+
PAN-283333
+
+
+ Fixed an issue where threat logs displayed logs from the + N/A threat category when a random + string was used for the + category-of-threatid filter in + threat logs. +
+
+
PAN-283316
+
+
+ Fixed an issue where a software download job reported a completion + timestamp that occurred before the software loading process was + finished. +
+
+
PAN-283304
+
+
+ Fixed an issue where the OSPFv3 area nssa + default-information-originate CLI + command was not applied due to a configuration error in the backend + advanced-routing stack. +
+
+
PAN-283206
+
+
+ Fixed an issue where configuring an HTTP profile to send Webhook + alerts to Microsoft Teams failed with a 400 Bad request error when + clicking Send Test Log. +
+
+
PAN-283168
+
+
+ Fixed an issue related to syslog forwarding that caused the + logrcvr + process stopped responding. +
+
+
PAN-283165
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected after a period of inactivity due to the Panorama management + server unnecessarily reading the + running-config.xml file. +
+
+
PAN-283138
+
+
+ Fixed an issue where the + reportd + process stopped responding when exporting CSV files when decryption + logs were included in the unified logs. +
+
+
PAN-283004
+
+
+ Fixed an issue where the firewall bypassed Content Threat Detection + (CTD) for sessions with STARTTLS large client hello out-of-order with + No Decrypt. +
+
+
PAN-282607
+
+
+ Fixed an issue where the DHCP process stopped responding when the + firewall was configured as a DHCP relay agent. +
+
+
PAN-282578
+
+
+ Fixed an issue where ping commands from both the management plane and + dataplane interfaces incorrectly prioritized IPv6 addresses over IPv4 + addresses, even when IPv6 was disabled. This caused connectivity + issues when pinging FQDNs that resolved to IPv6 addresses. +
+
+
PAN-282571
+
+
+ Fixed an issue where the Border Gateway Protocol (BGP) established + time was displayed inaccurately due to a 32-bit counter wrapping + issue. +
+
+
PAN-282533
+
+
+ Fixed an issue where firewalls in air-gapped environments attempted to + connect to a Google IP address for Machine Learning AV (MLAV) + functionality, even when MLAV was not licensed or configured. +
+
+
PAN-282454
+
+
+ Fixed an issue where, when you added the + Virtual System Name column under + Unified Logs, the column did not + remain visible in the table if you closed and re-opened the tab. +
+
+
PAN-282277
+
+
+ Fixed an issue where an OOM condition on the + logrcvr + process caused interface flapping, and the interface unexpectedly went + down and then recovered without intervention. +
+
+
PAN-281797
+
+
+ Fixed an issue where firewalls became unstable and stopped responding, + which resulted in an OOM condition. +
+
+
PAN-281776
+
+
+ Fixed an issue on the Panorama web interface where the error message + PPPoEv6 Client Interface cannot be enabled with DHCPv6 client + was generated when overriding aggregate interfaces even when no DHCPv6 + or PPPoE was configured. +
+
+
PAN-281596
+
+
+ Fixed an issue where, when the firewall was configured as an explicit + proxy, connections were intermittently dropped. +
+
+
PAN-281576
+
+
+ Fixed an issue where SNMP traps messages were not sent after system + startup. +
+
+
PAN-281488
+
+
+ Fixed an issue where searching configuration logs for an + audit_uuid did not return a + result if the rule was created with a clone operation. +
+
+
PAN-281294
+
+
+ Fixed an issue where, after an + authd + process restart, the username, password, and source IP address + displayed in plain text on the console when attempting to log in via + the web interface. +
+
+
PAN-281198
+
+
+ Fixed an issue on Panorama managed firewalls where, when the service + route configuration was set to VLAN as the source, attempting to + import the variable CSV into the template resulted in the validation + error + Failed to parse variable configuration file. This issue occurred because the system incorrectly validated the + VLAN interface name in the service route configuration within the + template. +
+
+
PAN-281096
+
+
+ Fixed an issue on HA clusters where, when link and path monitoring was + configured and the failover condition was set to + all, disconnecting and reconnecting + monitored ethernet ports caused the firewall to switch to a + nonfunctional role, which resulted in all interfaces except the HA + interface going down. +
+
+
PAN-281017
+
+
+ Fixed an issue where shared objects were displayed in the + Push Scope after pushing the + configuration from Panorama to managed firewalls. +
+
+
PAN-280910
+
+
+ Fixed an issue on firewalls with Advanced Routing Engine enabled where + BGP route maps were not correctly configured for IPv6 next-hop + selection. The firewall rejected the IPv6 configuration provided as + the next hop due to an incorrect command sent to FRR (Free Range + Routing). +
+
+
PAN-280901
+
+
+ Fixed an issue where DHCP Based IP Address Assignment for Global + protect failed when the management interface was configured to receive + its own IP address from DHCP. +
+
+
PAN-280695
+
+
+ Fixed an issue where all data interfaces went down due to a Forward + Error Correction (FEC) mode mismatch. The firewall defaulted to FEC + Auto mode, while the peer Cisco switch was configured for FC-FEC. +
+
+
PAN-280409
+
+
+ Fixed an issue where the popup window did not appear as expected for + Clientless VPN users. +
+
+
PAN-280302
+
+
+ Fixed an issue where the + show session cache CLI command + was unavailable on VM-Series firewalls with VM license types smaller + than VM-200 when session resiliency was enabled. +
+
+
PAN-280101
+
+
+ Fixed an issue where set and edit commands took longer than expected + when adding address objects with a large number of dynamic groups due + to the completion cache being enabled. With this fix, the completion + cache is disabled by default. +
+
+
PAN-280099
+
+
+ Fixed an issue in the URL filtering logs where the columns and the + displayed contents did not match. +
+
+
PAN-280013
+
+
+ Fixed an issue where User-ID custom reports were unable to exclude IP + address 0.0.0.0 when using the filter + ip notin 0.0.0.0. +
+
+
PAN-279829
+
+
+ Fixed an issue where NAT pool leaks occurred during a test when RTSP + traffic hit NAT rules. +
+
+
PAN-279706
+
+
+ (M-600 appliances only)) Fixed an issue where + Panorama did not update all + panreplay database entries after + performing a commit and full push to all devices. +
+
+
PAN-279690
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused the firewall to unexpectedly + restart. +
+
+
PAN-279647
+
+
+ Fixed an issue where threat names were displayed differently on the + web interface and the exported CSV file. +
+
+
PAN-279584
+
+
+ Fixed an issue where, during software deployment from Panorama to + multiple firewalls, some firewalls did not automatically reboot after + the upgrade, even when + Reboot device after install was + selected. This was due to the Panorama timing out before the software + deployment completed on the affected firewalls, which prevented the + reboot request from being sent. +
+
+
PAN-279415
+
+
+ Fixed an issue where service routes configured to use a data plane + interface incorrectly used the management plane interface for traffic + transmission. This issue affected syslog and CRL status traffic when a + custom service route was not configured. +
+
+
PAN-279366
+
+
+ Fixed an issue where the firewall used an unnecessary configuration + lock when running operational commands. +
+
+
PAN-279209
+
+
+ Fixed an issue where changes made to the management interface + permitted IP address list in a global template were not pushed to the + template stack or firewalls. +
+
+
PAN-279195
+
+
+ Fixed an issue on Panorama where + Device Health displayed the device + memory as 0%. +
+
+
PAN-278836
+
+
+ Fixed an issue where, after an upgrade, GlobalProtect attempted to use + the embedded browser instead of the default browser for gateway + authentication even when it was configured to use the default browser. +
+
+
PAN-278628
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the + configd + process restarted during a configuration push from Panorama, which + caused the active firewall to lose management access for 20-30 + minutes. +
+
+
PAN-278507
+
+
+ Fixed an issue where the OCSP Signing purpose was not included in the + Extended Key Usage field when a + certificate was generated on the firewall with the OCSP responder + called in the certificate. This caused the GlobalProtect connection to + fail with the error + Missing OCSP signing purpose in the ExtendedKeyUsage. +
+
+
PAN-278364
+
+
+ Fixed an issue where a stack overflow occurred when the DNS domain + name length exceeded 255 characters. +
+
+
PAN-278288
+
+
+ Fixed an issue where IPv6 BGP peering established between virtual + routers even without dataplane connectivity. This occurred because the + firewall used the kernel for lookups instead of the dataplane. +
+
+
PAN-278276
+
+
+ Fixed an issue on Panorama where custom reports displayed an incorrect + log count with critical severity when the report filter was built with + and without explicitly specifying severity as critical. +
+
+
PAN-278126
+
+
+ Fixed an issue where the number of registered IP Tags on Panorama did + not match the number of registered IP Tags on the managed firewalls + due to a change in file format between PAN-OS releases. +
+
+
PAN-277987
+
+
+ (VM-Series firewalls in AWS environments only) + Fixed an issue where HA failover mode incorrectly changed from + interface move to + secondary IP move after a reboot. +
+
+
PAN-277759
+
+
+ Fixed an issue where Panorama failed to upgrade due to duplicate + path-monitor names configured across different static routes within + the same virtual router or logical router. +
+
+
PAN-277755
+
+
+ Fixed an issue that caused the + request system private-data-reset + CLI command to fail. +
+
+
PAN-277682
+
+
+ Fixed an issue where moving an address object from a device group to + shared and renaming it did not + reflect in the address group, which caused commits to fail. +
+
+
PAN-277617
+
+
+ Fixed an issue where deleting the NTP server address caused a commit + validation error. This occurred when the configuration included both + primary and secondary NTP servers and the secondary server was + removed. +
+
+
PAN-277306
+
+
+ Fixed an issue where the XML API and REST API failed to run commands + with an error. +
+
+
PAN-277162
+
+
+ Fixed an issue where random characters were added to the + proxy_authorization in HTTP + messages when the firewall accessed certain services through a + configured proxy server. This caused proxy server authentication to + intermittently fail. +
+
+
PAN-277034
+
+
+ Fixed an issue where WildFire reports were not fully displayed and + were not downloadable due to static resources not being found. +
+
+
PAN-277018
+
+
+ Fixed an issue where FTP data connections did not work for EPRT with + Source IP + Port translation enabled on the firewall. +
+
+
PAN-277000
+
+
+ Fixed an issue where the firewall stopped responding after upgrading + to PAN-OS 11.0.2 with lockless-qos enabled. +
+
+
PAN-276961
+
+
+ Fixed an issue where adding an SD-WAN interface profile to an + overridden interface on a template stack failed with an + sdwan-interface-profile is invalid + error. +
+
+
PAN-276936
+
+
+ Fixed an issue where the CLI command syntax was incorrect when + configuring the + deviceconfig values from the + Template Stack. +
+
+
PAN-276862
+
+
+ Fixed an issue on Panorama where the + logd + process stopped responding unexpectedly. +
+
+
PAN-276795
+
+
+ Fixed an issue where the GlobalProtect client displayed an error + message when you clicked + Check Now and + Preferred Releases and + Base Releases were unchecked (Device > Software). +
+
+
PAN-276694
+
+
+ Fixed an issue where the firewall unexpectedly rebooted when the + show dns-proxy ddns interface name all + CLI command was executed with the error + Server error: op command for client dnsproxyd timed out as client + is not available. +
+
+
PAN-276616
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet + were not visible. +
+
+
PAN-276599
+
+
+ Fixed an issue where the password expiry prompt was not visible when + logging in via the web interface. +
+
+
PAN-276491
+
+
+ (Panorama virtual appliances only) Fixed an + issue where Panorama stopped responding when running reports. +
+
+
PAN-276484
+
+
+ Fixed an issue where Panorama did not display license information for + Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes. +
+
+
PAN-276412
+
+
+ Fixed an issue where you were unable to download XML files from + Panorama > Summary > Backups. +
+
+
PAN-276352
+
+
+ Fixed an issue where multicast flows were dropped due to a missing + sysd + variable for maximum multicast routes. +
+
+
PAN-276321
+
+
+ Fixed an issue where User-ID mappings were not correctly redistributed + from Panorama to firewalls, causing some users to be identified as + unknown, which prevented access to + resources based on AD group membership. +
+
+
PAN-276144
+
+
+ Fixed an issue on the web interface where the + Response Page + action column was not accessible. +
+
+
PAN-276033
+
+
+ Fixed an issue on Panorama managed firewalls where + SAML identity provider and + Clientless Apps objects did not have + override or revert options. +
+
+
PAN-276000
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the + confgid + process and + mgmtsrvr + process restarted daily when processing a + show rule-hit-count CLI command + when retrieving Security policy rules for vsys1. +
+
+
PAN-275653
+
+
+ Fixed an issue where the Log Collector service did not start on a new + Log Collector appliance added to a Log Collector group. As a result, + the new Log Collector appliance did not appear in the cluster and the + number of nodes in the cluster was incorrect. +
+
+
PAN-275601
+
+
+ Fixed an issue where, when Panorama was not internet connected and you + attempted to upload images to managed firewalls using the + Validate option, the upload failed + with the error + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-275451
+
+
+ (Panorama appliances only) Fixed an issue where + sequence numbers were lost when forwarded from Panorama, which + resulted in missing or lost logs. +
+
+
PAN-275272
+
+
+ Fixed an issue where a dataplane restart was not triggered as expected + when internal packet path monitoring failure occurred. +
+
+
PAN-275089
+
+
+ Fixed an issue where a + devsrvr + process restart caused commits to fail due to cloud app validation, + which resulted in WildFire installs failing. +
+
+
PAN-275050
+
+
+ Fixed an issue where the Japanese translation for the URL filtering + option to add a trailing slash to entries and the device license + status error was incorrect. +
+
+
PAN-275026
+
+
+ Fixed an issue where you were unable to to adjust the frequency of the + Advanced Cloud Explorer (ACE) cloud fetch via the CLI. +
+
+
PAN-274907
+
+
+ Fixed an issue on Panorama where + Config Audit Commit Date displayed + the timestamp of the configuration edit instead of the commit time. +
+
+
PAN-274650
+
+
+ Fixed an issue where the firewall did not perform certificate expiry + validation during a commit, which resulted in successful + authentication even when an intermediate certificate had expired. +
+
+
PAN-274622
+
+
+ Fixed an issue on the Panorama web interface where GlobalProtect + client images were not exported via SCP. +
+
+
PAN-274333
+
+
+ Fixed an issue where the Logging Service License Status displayed as + red even though a valid license was installed on the firewall. +
+
+
PAN-274292
+
+
+ (M-600 Appliances only) Fixed an issue where + the web interface was slow when logging in and filtering for policies + due to deep search operations taking longer than expected. +
+
+
PAN-274213
+
+
+ Fixed an issue where the firewall did not properly update incremental + update data maintained at the management plane when an IP address was + part of both a Dynamic Address Group and an External Dynamic List + (EDL). This resulted in the firewall not matching the expected + Security policy rule and threat signature. +
+
+
PAN-274207
+
+
+ Fixed an issue where Global Search did not redirect correctly to + routing profiles when searching for their names. +
+
+
PAN-274086
+
+
+ Fixed an issue where the firewall incorrectly assembled SIP NOTIFY and + REFER messages when processing SIP TCP packets that contained a + partial content-body from a previous SIP message and a complete header + and content-body from the next SIP message. +
+
+
PAN-274064
+
+
+ Fixed an issue on Panorama where the + request batch license info CLI + command displayed entries for devices that were no longer attached to + Panorama. +
+
+
PAN-274038
+
+
+ Fixed an issue where you were unable to use the + s_encrypted field in custom reports + for the Panorama threat log database. +
+
+
PAN-273991
+
+
+ Fixed an issue where the transmit power for a cable that was used on + port 44 displayed as N/A. +
+
+
PAN-273969
+
+
+ Fixed an issue where the Panorama interface template did not include + the Forward Error Correction (FEC) setting. +
+
+
PAN-273963
+
+
+ Fixed an issue where GlobalProtect health information (HIP) did not + display the certificate key usage. +
+
+
PAN-273947
+
+
+ Fixed an issue where the displayed group name differed depending on + whether the group was configured locally on the firewall or through + Panorama. +
+
+
PAN-273805
+
+
+ Fixed an issue where SAML authentication for GlobalProtect failed when + the GlobalProtect portal was accessed externally on a non-standard + port. +
+
+
PAN-273589
+
+
+ Fixed an issue where firewalls configured with a VPN tunnel stopped + responding when a configuration update was applied. +
+
+
PAN-273010
+
+
+ Fixed an issue where the configuration version did not increment in + the Audit Comment Archive after making changes to the Security policy + rule with an audit comment and performing a commit. As a result, all + subsequent changes were grouped under the same configuration version, + which prevented the comparison of changes in the + Rule Changes field of the Security + policy rule. +
+
+
PAN-273008
+
+
+ (PA-5400 firewalls only) Fixed an issue where + frequent BGP/BFD flaps occurred and HA2 keep-alives went down. +
+
+
PAN-272998
+
+
+ Fixed an issue where commits from Panorama to VM-Series firewalls on + Microsoft Azure environments failed. +
+
+
PAN-272796
+
+
+ Fixed an issue where you were unable to export the GlobalProtect + client software version to the SCP server. +
+
+
PAN-272790
+
+
+ Fixed an issue on the Panorama web interface where administrators were + unable to export GlobalProtect client images and received an + scp export failed error. This was + due to the system attempting to retrieve the file from an incorrect + directory. +
+
+
PAN-272743
+
+
+ Fixed an issue where non-captive portal traffic was not visible under + Traffic Logs when the traffic was + denied by an authentication rule and the session was discarded. +
+
+
PAN-272726
+
+
+ Fixed an issue on the web interface where the + URL Filtering change category + feature did not work. +
+
+
PAN-272505
+
+
+ Fixed an issue where GlobalProtect cookie authentication failed with + the error + User is not in allow list. +
+
+
PAN-272469
+
+
+ Fixed an issue where the DNS exception displayed + 0 instead of + no result in the anti-spyware + profile when no threat ID was available for a DNS Security category. +
+
+
PAN-272408
+
+
+ (PA-1420 firewalls only) Fixed an issue where + the firewall reported unsupported SFPs when PAN-SFPPLUS10GBASE-T SFPs + were used on ports Ethernet 1/21 and 1/22. +
+
+
PAN-272178
+
+
+ Fixed an issue where the firewall displayed packet buffers between 18 + and 19 even when there was little or no traffic. +
+
+
PAN-272172
+
+
+ Fixed an issue where + plugin_api_server could + experience a memory leak when using OpenConfig for telemetry. +
+
+
PAN-271810
+
+
+ Fixed an issue where auto-negotiation advertised and negotiated 10/100 + half and full duplex. +
+
+
PAN-271637
+
+
+ Fixed an issue where the firewall did not increase the metric of the + default route when redistributed into OSPF when the firewall was + configured as an NSSA ABR. +
+
+
PAN-271636
+
+
+ (PA-1400 and PA-3400 Series firewalls only) + Fixed an issue where the firewall displayed the error message + Failed to parse pbf policy when + you committed a configuration that included more than 8 Policy Based + Forwarding (PBF) rules with symmetric return enabled. +
+
+
PAN-271490
+
+
+ Fixed an issue on the firewall that caused the following error message + to be displayed: + frr_ns0: failed to stop child frr_ns0_ospf6d. +
+
+
PAN-271440
+
+
+ Fixed an issue where + PublicCloud Server certificate validation failed. Dest Addr: + (null), Reason: self signed certificate in certificate chain + generated as a high alert in the system log every 5 minutes. +
+
+
PAN-271438
+
+
+ Fixed an issue where the firewall calculated available memory + incorrectly on CENTOS devices, which caused the firewall to display + high memory usage alerts even when sufficient memory was available. +
+
+
PAN-271436
+
+
+ A CLI counter was added to indicate a full suppression queue. +
+
+
PAN-271412
+
+
+ Fixed an issue where the character ( + ) in the authentication message + prompt displayed incorrectly as + #43; on the GlobalProtect client + after upgrading to a PAN-OS 10.2 release. +
+
+
PAN-271301
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments with + GWLB integrated only) Fixed an issue where DNS queries timed out when overlay routing was + enabled. +
+
+
PAN-271204
+
+
+ Fixed an issue where performing a factory reset caused the firewall to + enter a continuous boot loop due to a failure in generating the + global.xml configuration file. +
+
+
PAN-271173
+
+
+ Fixed an issue where the firewall displayed an incorrect maximum + translated IP capacity when using DIPP NAT policy rules. +
+
+
PAN-271061
+
+
+ Fixed an issue on the web interface where you were unable to add + Threat IDs to Signature Exceptions. +
+
+
PAN-270747
+
+
+ Fixed an issue where the + show system statistics application + CLI command failed. +
+
+
PAN-270554
+
+
+ Fixed an issue where the GlobalProtect client (UWP) or metered hotspot + connections triggered TLS resumption fo GlobalProtect portal + authentication, which caused the portal authentication to fail with a + valid cert required error. +
+
+
PAN-270493
+
+
+ Fixed an issue where the + Low free buffer limit output was + not available. +
+
+
PAN-270323
+
+
+ Fixed an issue where the firewall allowed cleartext web-browsing + traffic on port 443 when the Security policy rule was configured to + allow application: web-browsing with service: application-default. +
+
+
PAN-269913
+
+
+ Fixed an issue threat reports were empty when generated from Panorama, + but displayed correctly when generated from the firewall. +
+
+
PAN-269843
+
+
+ Fixed an issue where the firewall dropped non-SYN TCP packets even + when the Reject non-SYN TCP option + was set to No when a session rematch + was triggered. +
+
+
PAN-269716
+
+
+ Fixed an issue where half-closed TCP sessions did not refresh the + session timeout when continuously receiving data after setting the + cfg.session.tcp-no-refresh-fin-rst + option toTrue. +
+
+
PAN-269659
+
+
+ Fixed an issue on the firewall where you were unable to configure more + than 500 DHCP relay servers even though the supported limit was 4096. +
+
+
PAN-269535
+
+
+ Fixed an issue where the mib ID returned an incorrect value via SNMP. +
+
+
PAN-269445
+
+
+ Fixed an issue where the + show user ip-user-mapping all option detail + XML API command did not show the complete output. +
+
+
PAN-269342
+
+
+ Fixed an issue where BGP aggregate routes with the AS-SET option + enabled had incorrect AS paths. +
+
+
PAN-269303
+
+
+ Fixed an issue where the CSV export of disabled applications included + duplicate entries, which caused the count of disabled applications to + be higher in the CSV export than on the web interface. +
+
+
PAN-269286
+
+
+ Fixed an issue where the firewall did not query for an AAAA record + when only IPv6 was enabled for the management interface. +
+
+
PAN-269228
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused a split brain condition. +
+
+
PAN-269191
+
+
+ (VM-Series firewalls only) Fixed an issue where + the aggressive clean-up threshold for disk space was set to 95% in + system monitor. +
+
+
PAN-269176
+
+
+ Fixed an issue where the + domain-edl column was empty in the + threat log even when a threat was detected as a DNS alert. +
+
+
PAN-269155
+
+
+ Fixed an issue where an OOM condition occurred, which caused processes + to stop responding. +
+
+
PAN-269057
+
+
+ Fixed an issue where the + routed + process stopped responding due to accessing freed memory from a hash + table when the route vectors were resized. This occurred when a large + number of static routes were configured. +
+
+
PAN-269051
+
+
+ Fixed an issue where, when using WildFire Private Cloud, the system + log displayed the error message + tls-X509-validation. +
+
+
PAN-268922
+
+
+ (PA-3220 firewalls in HA configurations only) + Fixed an intermittent issue where the firewalls went out of sync after + a configuration push from Panorama. +
+
+
PAN-268787
+
+
+ Fixed an issue where users were unable to log in to Panorama and the + following error message was displayed: + Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of + devices. +
+
+
PAN-268680
+
+
+ Fixed an issue where the + configd + process stopped responding when a configuration merge operation + changed. +
+
+
PAN-268606
+
+
+ Fixed an issue where GlobalProtect users with client certificates + received an authentication failure message without entering a password + and clicking connect or + login. +
+
+
PAN-268597
+
+
+ Fixed an issue where the firewall displayed 0 bytes received for + GlobalProtect SSL sessions in the traffic logs. +
+
+
PAN-268569
+
+
+ Fixed an issue where the web interface was slower than expected when + logging in and filtering for policies. +
+
+
PAN-268522
+
+
+ Fixed an issue where the firewall failed to connect to the update + server with a customized service route when the source interface was + set to MGT and the source address + was set as IPv4. +
+
+
PAN-268426
+
+
+ Fixed an issue where the firewall was unable to connect to a syslog + server that used a TLS certificate without a subject key identifier. +
+
+
PAN-268425
+
+
+ Fixed an issue where the + execute show transceiver-detail all + XML API command returned an incorrect value for the low temperature + alarm threshold. +
+
+
PAN-268313
+
+
+ Fixed an issue where the Priority Code Point (PCP) bits in the VLAN + header were not reset to 0 when a packet was received from one Layer 3 + tagged interface and forwarded to another, which resulted in dropped + packets. +
+
+ To use this fix, run the CLI command + set force-vlan-pcp-reset yes and + reboot the firewall. +
+
+
PAN-268032
+
+
+ Fixed an issue where importing a device configuration into Panorama + failed with a validation error if the configuration included a shared + gateways containing NAT/PBF rules. +
+
To use this fix:
+
    +
  1. + Enable the configuration. Commit failures may occur if the device is + not able to support the number of objects. +
  2. +
  3. Export and push the device group only.
  4. +
  5. Push the template.
  6. +
+
+ Note: This fix is supported on PAN-OS 10.2 and later releases. +
+
+
PAN-267936
+
+
+ Fixed an issue where commits failed with a validation error when you + changed the encryption level and re-encryption option on a Panorama + managed firewall. +
+
+
PAN-267912
+
+
+ Fixed an issue on the Panorama web interface where + Application and + Category was not able to be selected + under Test Policy Match. +
+
+
PAN-267830
+
+
+ Fixed an issue where the snmpd.log.old file continuously increased, + which caused the root partition to become full. +
+
+
PAN-267614
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to high CPU utilization on the + mongodb + process. +
+
+
PAN-267426
+
+
+ (Firewalls in HA configuration only) Fixed an + issue where the + Network pre-negotiation enabled page + did not display on the firewall dashboard. +
+
+
PAN-267381
+
+
+ Fixed an issue where the firewall failed to upload a macOSX file if + the file had a MIME boundary. +
+
+
PAN-267330
+
+
+ Fixed an issue where the firewall dropped inbount RTP traffic after + using Webex Screen Sharing due to the firewall removing the NAT cache + when the predict timed out, which caused a new NAT to be established + that conflicted with existing sessions. To use this fix, run the CLI + command + set system setting ctd h323_rtp_predict timeout + <120-3600> + to increase the timeout limit. +
+
+
PAN-267328
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused the firewall to stop + processing traffic. +
+
+
PAN-267117
+
+
+ (VM-Series firewalls only) Fixed an issue where + BGP route refreshes occurred when a commit was performed if + AS Set was enabled for BGP aggregate + routes. +
+
+
PAN-267045
+
+
+ Fixed an issue on the firewall where ICMP ping loss occurred after + installing a Network Processing Card (NPC) in slot 7. +
+
+
PAN-266971
+
+
+ Fixed an issue where the firewall generated AAAA DNS queries when IPv6 + firewalling was disabled. +
+
+
PAN-266905
+
+
+ Fixed an issue where sessions ended with the message + decrypt error in the logs for + traffic that matched a + no-decrypt policy. +
+
+
PAN-266698
+
+
+ Fixed an issue where an email was able to be transferred to the + destination MTA even when the firewall detected a suspicious file with + a reset-bot action when it was encrypted by STARTTLS. +
+
+
PAN-266688
+
+
+ Fixed an issue on the firewall where traffic matched a custom + signature even if the custom signature was removed from the + configuration. +
+
+
PAN-266589
+
+
+ Fixed an issue where the firewall was unable to generate a tech + support file when management server debug was disabled. +
+
+
PAN-266302
+
+
+ Fixed an issue where OSPFv3 Link State (LS) update packets (type 9) + were not fragmented properly, which caused the OSPF header to have an + incorrect checksum when sent from the firewall. This occurred when the + update packet size exceeded 1514 byte, which resulted in the peer + device rejecting the packet and the neighbor relationship going down. +
+
+
PAN-265926
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the + all_task + process stopped responding, which caused the firewall to reboot. +
+
+
PAN-265916
+
+
+ Fixed an issue where double-clicking the login button returned the + error message + Login session expired. +
+
+
PAN-265782
+
+
+ Fixed an issue on Panorama where, after you enabled multihop in a BFD + profile, you were unable to disable it via the web interface. +
+
+
PAN-265686
+
+
+ Fixed an issue where the GlobalProtect portal logged passwords in + cleartext. +
+
+
PAN-264912
+
+
+ Fixed an issue where the firewall did not shut down completely. +
+
+
PAN-264742
+
+
+ Fixed an issue on Panorama where the dynamic address group IP + addresses of the Kubernetes plugin or Prisma Cloud plugin for Secure + Developer Environment were not displayed. +
+
+
PAN-264666
+
+
+ Fixed an issue where the + configd + process restarted when pushing configurations to multiple device + groups via XML API, which caused the push to fail. +
+
+
PAN-264570
+
+
+ Fixed an issue where the maximum session limit for a vsys was + 4,194,290. +
+
+
PAN-264538
+
+
+ (VM-Series firewalls only) Fixed an issue where + the + all_task + process stopped responding and a reboot was required. +
+
+
PAN-264131
+
+
+ Fixed an issue where the + routed + process core failed the automation run. +
+
+
PAN-264040
+
+
+ Fixed an issue where AAAA DNS queries went out even when + IPv6 firewalling was disabled. +
+
+
PAN-263699
+
+
+ PA-440 firewalls only) Fixed an issue where the + firewall was unable to create more than 6 GlobalProtect gateways. +
+
+
PAN-263674
+
+
+ (VM-Series firewalls in HA configurations only) + Fixed an issue where the firewall rebooted due to multiple HA + failovers. +
+
+
PAN-263544
+
+
+ Fixed an issue where management plane CPU usage increased after + upgrading when there was a full-mesh User-ID redistribution + configuration between multiple firewalls. +
+
+
PAN-263504
+
+
+ Fixed an issue where exporting managed device information from + Panorama in CSV format included extraneous characters. +
+
+
PAN-263270
+
+
+ Fixed an issue where, after a commit was performed from Strata Cloud + Manager, the SD-WAN configuration containing BGP routes did not + display on the hub firewall. +
+
+
PAN-263052
+
+
+ Fixed an issue where the + request logdb migrate-to-panorama start end-time <start-time> + <type> + CLI command did not work as expected, and you were unable to resend + logs from a firewall to Panorama or a log collector. +
+
+
PAN-262599
+
+
+ Fixed an issue where the firewall displayed incorrect policy cache + usage and configuration memory usage during a commit, which caused the + configuration commit to fail with a + CONFIG_UPDATE_START error. This + occurred when a large number of External Dynamic Lists (EDLs), shared + addresses, and policy rules were configured. +
+
+
PAN-262521
+
+
+ Fixed an issue where imported certificates were not visible on + firewalls with multi-vsys disabled. +
+
+
PAN-262278
+
+
+ Fixed an issue where the service route setting for HTTP was not + applied when the source interface IP address was set via an address + object, which caused HTTP traffic to be sent from the management + interface. +
+
+
PAN-262043
+
+
+ Fixed an issue where Voice over WiFi (VoWiFi) stopped working after + switching from a PA-5200 Series firewall to a PA-7500 Series firewall + in NGFW clustering mode with NATT IPSec Passthrough and NAT policy + enabled. To use this fix, enter the CLI command + show tunnel-acceleration, disable + tunnel acceleration, and reboot the PA-7500 Series firewall. +
+
+
PAN-261936
+
+
+ Fixed an issue where WildFire submission logs were not displayed when + filtered by Sender Address. +
+
+
PAN-261602
+
+
+ Fixed an issue where GlobalProtect Decryption logs were not forwarded + to Panorama. +
+
+
PAN-260879
+
+
+ Fixed an issue where the Panorama port 28270 did not adhere to the + restricted TLS version and ciphers set in the + Secure Communication Settings. +
+
+
PAN-260790
+
+
+ Fixed an issue where the bytes transmitted and packet transmitted + counters for hardware interfaces incorrectly displayed as 0 after a + restart of slot-1. +
+
+
PAN-260752
+
+
+ Fixed an issue where the firewall did not support TLSv1.3 in the + Clientless VPN, which caused the portal page to not load. +
+
+
PAN-260661
+
+
+ Fixed an issue where daily email reports generated from the custom + report did not display the report details in PDF or CSV files. +
+
+
PAN-260581
+
+
+ Fixed an issue where Panorama template changes to the zone and virtual + router were not pushed to managed firewalls when the template stack + default virtual system was set to + None. +
+
+
PAN-260540
+
+
+ Fixed an issue where task-debug logs remained on the debug level even + after running the + debug dataplane packet-diag set log off + CLI command, which caused high dataplane CPU utilization. +
+
+
PAN-260330
+
+
+ Fixed an issue where Panorama was unable to generate PDF reports when + the footer contained a GIF image. +
+
+
PAN-259998
+
+
+ (M-600 Appliances only) Fixed an issue where + log collectors in a cluster stopped responding when running high load + tests. +
+
+
PAN-259741
+
+
+ Fixed an issue where the firewall dropped GRE keepalive packets that + were encapsulated under another GRE tunnel. +
+
+
PAN-259343
+
+
+ Fixed an issue on the Panorama web interface where the + Configuration tab did not accurately + display changes made to URL filtering profiles. +
+
+
PAN-259284
+
+
+ Fixed an issue where IPv4 BGP routes were not included in the routing + table or FIB of a virtual router when ECMP was configured with more + than two next hops. +
+
+
PAN-259091
+
+
+ Fixed an issue where the CLI command + show user ip-user-mapping-mp all + displayed the total timeout value instead of the current timeout value + when the + set cli op-command-xml-output on + CLI command was used. +
+
+
PAN-258912
+
+
+ (PA-7000b firewalls only) Fixed an issue where + the firewall web interface displayed an incorrect HSM client version + when the client was upgraded to version 7.2.0.220. +
+
+
PAN-258456
+
+
+ Fixed an issue where not all IP-TAG logs were forwarded to Log + Collectors. +
+
+
PAN-258039
+
+
+ Fixed an issue where the firewall displayed the incorrect rule name + when a threat log was generated for Inline Cloud Analyzed CMD + Injection Traffic Detection. +
+
+
PAN-257638
+
+
+ Fixed an issue where the firewall dataplane stopped responding, which + caused BGP flaps between hubs and branches. +
+
+
PAN-257616
+
+
+ Fixed an issue where selective push operations from Panorama to + managed firewalls failed with the error message + Failed to generate selective push configuration. Schema validation + failed. Please try a full push. +
+
+
PAN-257362
+
+
+ Fixed an issue where GlobalProtect traffic destined for the internet + did not follow the path-based forwarding (PBF) rule and was sent out + the wrong interface. +
+
+
PAN-257195
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where the mp-monitor logs did not print disk SMART data. +
+
+
PAN-257074
+
+
+ Fixed an issue on the Panorama web interface where the template sync + status showed Out-of-Sync for + managed devices after a combined commit-all operation. This occurred + due to Panorama sending the default MD5 sum of the template to the + firewall instead of the correct MD5 sum. +
+
+
PAN-256560
+
+
+ Fixed an issue where exporting a + Custom Report to CSV format did not + display the full report if it contained non-ASCII characters. +
+
+
PAN-256552
+
+
+ Fixed an issue where the + logrcvr + stopped responding, which caused the firewall to restart. +
+
+
PAN-256138
+
+
+ (VM-Series firewalls only) Fixed an issue where + firewalls with a DNS server IP address received by DHCP from Amazon + Web Services (AWS) had a delay in resolving FQDNs after a reboot. +
+
+
PAN-255860
+
+
+ (PA-5200 firewalls only) Fixed an issue where + the + all_pktproc + process stopped responding when the firewall was under a heavy traffic + load. +
+
+
PAN-255806
+
+
+ Fixed an issue on Panorama where the ACC report for URL categories + displayed inconsistent results for the same time range when run daily. +
+
+
PAN-255654
+
+
+ Fixed an issue where, when QoS was enabled on aggregate interfaces, + the maximum aggregate interface throughput was capped, which limited + network traffic. This occurred even with default QoS settings and no + configured egress max-bandwidth. +
+
+
PAN-255547
+
+
+ Fixed an issue where commits failed when importing configurations to a + device with a non-default master key. +
+
+
PAN-255282
+
+
+ (PA-450 firewalls in HA configurations only) + Fixed an issue where the firewall remained in an active state and all + traffic stopped until a failover to the passive firewall was + performed. +
+
+
PAN-255253
+
+
+ Fixed an issue where the firewall did not establish a syslog + connection to the probe VM syslog server in ADEM Regressions. +
+
+
PAN-255190
+
+
+ Fixed an issue where the TCP timeout value was reflected incorrectly + when using application override for a custom application in TAP mode. +
+
+
PAN-255025
+
+
+ Fixed an issue where the + show session cache all CLI + command failed with the error message + Server error : An error occured. See dagger.log for + information. +
+
+
PAN-254946
+
+
+ Fixed an issue where the firewall HA2 keep-alive went down multiple + times without a specific reason. +
+
+
PAN-254875
+
+
+ (PA-410 firewalls only) Fixed an issue where + the firewall rebooted unexpectedly due to multiple + all_task + process restarts. +
+
+
PAN-254297
+
+
+ Fixed an issue where the + show pbf rule name <name> + CLI command failed. +
+
+
PAN-253778
+
+
+ (PA-7500 Series firewalls in a cluster configuration only) Fixed an issue where users were able to enable or disable certain + configurations. +
+
+
PAN-253187
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the class of service (CoS) priority bit was not modified, causing + access points to lose connectivity to the wireless controller when + traffic was routed through the firewall. +
+
+
PAN-252706
+
+
+ Fixed an issue where the URL filtering response page for + Continue and + Override did not work with IPv6 + Router Advertisement (RA) or Multicast Listener Query (MLQ) for + IPv6-to-IPv6 and IPv6-to-IPv4 traffic. +
+
+
PAN-252699
+
+
+ Fixed an issue where frequent session failures occurred due to CTD + resource exhaustion. +
+
+
PAN-251442
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode if + the authentication process restarted repeatedly. +
+
+
PAN-250048
+
+
+ Fixed an issue where applications did not load via the Clientless VPN + portal when the portal was hosted on an L3 VLAN interface. +
+
+
PAN-250043
+
+
+ Fixed an issue where, on an NGFW cluster node, operations failed when + QoS interfaces were configured with an egress max that exceeded 68,000 + Mbps. +
+
+
PAN-249574
+
+
+ Fixed an issue where selective pushes failed due to a missing log + collector reference. +
+
+
PAN-249194
+
+
+ Fixed an issue where SaaS quality profile probes were dropped on the + SD-WAN hub. +
+
+
PAN-248148
+
+
Jumbo frame feature support is enabled.
+
+
PAN-247141
+
+
+ Fixed an issue where DNS traffic did not match the intended SD-WAN + policy rule when NAT was enabled. +
+
+
PAN-243335
+
+
+ Fixed an issue on the Panorama web interface where you were unable to + add static IPv6 address entries to a logical router in a cluster + template stack. +
+
+
PAN-242777
+
+
+ Fixed and issue where users previously reported limitations due to + session count caps when utilizing + Web Proxy features on PA-5400 Series Firewalls. To + address these performance complaints and support higher traffic + volumes, we have increased the maximum session capacity on specific + PA-5400F series platforms, leveraging available + system memory. This update ensures greater capacity and stability for + high-volume environments. +
+
+ The supported session limits are: + +
+
+
+
+
+
+
+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
PlatformMax Sessions
PA-541095K
PA-542095K
PA-543095K
PA-5440225K
PA-5445250K
+
+
+
PAN-241953
+
+
+ Fixed an issue where the firewall did not have a heartbeat mechanism + for the + authd + process, which caused the firewall to become unresponsive if the + authd + process stopped responding. +
+
+
PAN-241694
+
+
+ Fixed an issue where memory leaks related to the + devsrvr + process occurred when downloading and pushing updates from the App-ID + Cloud Engine to the dataplane. +
+
+
PAN-241230
+
+
+ Fixed an issue where the SNMP get request status value for Panorama + connections was incorrect. +
+
+
PAN-238208
+
+
+ Fixed an issue where the firewall API returned inconsistent responses + to a failed call using a valid API key. With this fix, the firewall + returns the error + Session is invalid if the session is + not available for the cookie. +
+
+
PAN-234993
+
+
+ Fixed an issue where CPU base gateway auto-scaling failed, which + caused performance issues. +
+
+
PAN-221137
+
+
+ Fixed an issue where the CLI command to set the target virtual system + accepted a non-existent virtual system name, and the CLI prompt + incorrectly changed to the non-existent virtual system. +
+
+
PAN-216770
+
+
+ Fixed an issue where, when a firewall was managed by Strata Cloud + Manager and configured to use a proxy server for external connections, + the management server did not use the configured settings to connect + to the Cloud Management service. +
+
diff --git a/reference/PAN-OS/addressed/11.2.9.html b/reference/PAN-OS/addressed/11.2.9.html new file mode 100644 index 0000000..bbd5635 --- /dev/null +++ b/reference/PAN-OS/addressed/11.2.9.html @@ -0,0 +1,280 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-297972
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched + Inline Cloud Analysis prefiltering signatures, even when Inline Cloud + Analysis features were not enabled. +
+
+
PAN-297458
+
+
+ Fixed an issue where the + all_task_1 + process crashed on the firewall when the wif service wasn't available + because the wif detection ID was not in the current service table. +
+
+
PAN-297261
+
+
+ Fixed an issue where the proxy-protocol debug level was set to + verbose on Prisma Access + instances, even when it was not explicitly configured, which caused + excessive logging by the + pan_task + process. +
+
+
PAN-296519
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an + associated error in + Wifclient + caused the entire pool to close, which resulted in a complete + disconnection. +
+
+
PAN-296478
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10, + GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute + JavaScript links, resulting in an authorization error. This occurred + because the firewall was incorrectly injecting text into URLs when + JavaScript buttons or dropdown menus were clicked within the + Clientless VPN portal. +
+
+
PAN-296283
+
+
+ Fixed an issue where, on hardware platforms with the SaaS inline + license, Additional Header Logging (AHL) hash table creation proceeded + even when the feature was disabled through the CLI, potentially + leading to crashes. +
+
+
PAN-295944
+
+
+ Fixed an issue where static routes remained active in the FIB and RIB + even when the associated physical port interface was down, which + resulted in traffic being incorrectly routed through a non-operational + interface. +
+
+
PAN-295812
+
+
+ Fixed an issue where the throughput data on the Switch Card Module + (SCM) was not accurately reported. This issue affected Standard SC + USABN and USABN-2 when using Direct-IO deployment. +
+
+
PAN-295342
+
+
+ Fixed an issue where the + pan_comm + process stopped responding due to insufficient time allocated to read + file descriptors when processing long messages. +
+
+
PAN-292539
+
+
+ (CN-Series firewalls only) Fixed an issue where + the firewall generated incomplete or corrupted tech support files + (TSF) due to high disk usage on the management plane. +
+
+
PAN-291940
+
+
+ Fixed an issue where the firewall established multiple TCP connections + to a syslog server, which caused logs to be dropped. This occurred + because the firewall established a new TCP session for each transfer + and the sessions were not closed, which resulted in a continuous + increase in connections over time. +
+
+
PAN-289249
+
+
+ Fixed an issue where a memory leak occurred on the + reportd + process when a WildFire update was initiated while device telemetry + data collection was in progress. This resulted in an OOM condition. +
+
+
PAN-281721
+
+
+ Fixed an issue where the firewall generated high-severity system + alerts indicating that the configuration size exceeded the maximum + recommended size, even when the configuration size was within the + expected limits. +
+
+
PAN-277178
+
+
+ Fixed an issue on Panorama where you were unable to delete a shared + object due to the rulebase incorrectly referencing the shared object + instead of the device group-specific object when the name was used. +
+
+ To use this fix, delete the original shared object after cloning it to + a device group with the same name. +
+
+
PAN-272245
+
+
+ Fixed an issue where the dnsproxy process crashed due to memory + corruption caused by a race condition when allow list downloading was + impacted by config change. +
+
diff --git a/web/data/issues/PAN-OS/addressed/11.2.0-h1.md b/web/data/issues/PAN-OS/addressed/11.2.0-h1.md index 5c19512..6169657 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.0-h1.md +++ b/web/data/issues/PAN-OS/addressed/11.2.0-h1.md @@ -6,4 +6,4 @@ version: 11.2.0-h1 ## PAN-272809 -A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474. +A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474). diff --git a/web/data/issues/PAN-OS/addressed/11.2.0.md b/web/data/issues/PAN-OS/addressed/11.2.0.md index 8891bee..cd03b19 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.0.md +++ b/web/data/issues/PAN-OS/addressed/11.2.0.md @@ -26,7 +26,7 @@ Fixed an issue with session caching where the reportd process stopped responding ## PAN-227344 -Fixed an issue on Panorama where PDF Summary Reports (Monitor > PDF Reports > Manage PDF Summary) displayed no data and were blank when predefined widgets were included in the summary report. +Fixed an issue on Panorama where **PDF Summary Reports** (**Monitor > PDF Reports > Manage PDF Summary**) displayed no data and were blank when predefined widgets were included in the summary report. ## PAN-227305 @@ -90,7 +90,7 @@ Fixed an issue where the firewall CPU percentage was miscalculated, and the valu ## PAN-219768 -Fixed an issue where you were unable to filter Data Filtering logs with Threat ID/NAME for custom data patterns created over Panorama. +Fixed an issue where you were unable to filter Data Filtering logs with **Threat ID/NAME** for custom data patterns created over Panorama. ## PAN-219585 diff --git a/web/data/issues/PAN-OS/addressed/11.2.1-h1.md b/web/data/issues/PAN-OS/addressed/11.2.1-h1.md index c16ea0b..d7aefcc 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.1-h1.md +++ b/web/data/issues/PAN-OS/addressed/11.2.1-h1.md @@ -6,4 +6,4 @@ version: 11.2.1-h1 ## PAN-272809 -A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474. +A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474). diff --git a/web/data/issues/PAN-OS/addressed/11.2.1.md b/web/data/issues/PAN-OS/addressed/11.2.1.md index 5addfc3..7db3eee 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.1.md +++ b/web/data/issues/PAN-OS/addressed/11.2.1.md @@ -6,7 +6,7 @@ version: 11.2.1 ## PAN-257919 -Fixed an issue where, when using explicit proxy with SAML authentication, initiating SAML authentication with a non-GET request resulted in a 302 redirect response instead of the expected 200 ok response. +Fixed an issue where, when using explicit proxy with SAML authentication, initiating SAML authentication with a non-GET request resulted in a **302 redirect** response instead of the expected **200 ok** response. ## PAN-256343 @@ -46,4 +46,4 @@ Fixed an issue where, when you committed the first configuration change after bo ## PAN-164885 -Fixed an issue on Panorama where Commit and Push or Push to Devices operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping. +Fixed an issue on Panorama where **Commit and Push** or **Push to Devices** operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping. diff --git a/web/data/issues/PAN-OS/addressed/11.2.10-h2.md b/web/data/issues/PAN-OS/addressed/11.2.10-h2.md index e66f2f1..23aec90 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.10-h2.md +++ b/web/data/issues/PAN-OS/addressed/11.2.10-h2.md @@ -18,7 +18,7 @@ Fixed an issue on Panorama where a memory leak occurred related to the reportd p ## PAN-302927 -Fixed an issue where, after upgrading Panorama, the Push to Devices option did not display selected devices, and the OK and Cancel buttons did not function as expected. Selecting OK did not close the window, and selecting Cancel returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting Push or Validate Device Group Push still pushed to the previously canceled, non-displayed devices. +Fixed an issue where, after upgrading Panorama, the **Push to Devices** option did not display selected devices, and the **OK** and **Cancel** buttons did not function as expected. Selecting **OK** did not close the window, and selecting **Cancel** returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting **Push** or **Validate Device Group Push** still pushed to the previously canceled, non-displayed devices. ## PAN-301801 @@ -60,7 +60,7 @@ Fixed an issue where exporting custom reports resulted in empty CSV files. ## PAN-296977 -Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in NetworkInterfaces +Fixed an issue where the web interface became unresponsive when attempting to view **Ethernet** interface details after applying a filter in **Network** > **Interfaces** ## PAN-296694 @@ -80,7 +80,7 @@ Resolved multiple issues affecting IPSec tunnels using NAT Traversal (NAT-T) whe ## PAN-209516 -Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory. +Fixed an issue where, when creating an interface, an error occurred when you clicked **OK** without providing a value in the **Tag** field even though the field was not displayed as mandatory. ## PAN-185731 diff --git a/web/data/issues/PAN-OS/addressed/11.2.10-h3.md b/web/data/issues/PAN-OS/addressed/11.2.10-h3.md index 596662e..f5f2582 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.10-h3.md +++ b/web/data/issues/PAN-OS/addressed/11.2.10-h3.md @@ -58,4 +58,4 @@ Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code ## PAN-289723 -Fixed an issue where the firewall web interface continuously loaded and not display any output when viewing the Route Table or FIB table (More Runtime Stats). This issue occurred when L3 configurations were added to ethernet and AE interfaces. +Fixed an issue where the firewall web interface continuously loaded and not display any output when viewing the Route Table or FIB table (**More Runtime Stats**). This issue occurred when L3 configurations were added to ethernet and AE interfaces. diff --git a/web/data/issues/PAN-OS/addressed/11.2.10-h4.md b/web/data/issues/PAN-OS/addressed/11.2.10-h4.md index b868b7d..2b6ab51 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.10-h4.md +++ b/web/data/issues/PAN-OS/addressed/11.2.10-h4.md @@ -38,7 +38,9 @@ Fixed an issue where devices with 5G cellular modems did not support the ATT Fir ## PAN-285181 -Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature. +Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF. + +To use this fix, run the CLI command debug iot eal memory-gc native ## PAN-278688 @@ -55,7 +57,3 @@ Fixed an issue where an incorrect ASIC configuration caused silent packet drops ## PAN-269228 Fixed an issue where the all_task process stopped responding, which caused a split brain condition. - -## PAN-267614 - -Fixed an issue where the Panorama web interface was slower than expected due to high CPU utilization on the mongodb process. diff --git a/web/data/issues/PAN-OS/addressed/11.2.10.md b/web/data/issues/PAN-OS/addressed/11.2.10.md index 42a69ee..2b6e0ed 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.10.md +++ b/web/data/issues/PAN-OS/addressed/11.2.10.md @@ -58,7 +58,7 @@ Fixed an issue where ports went down after an HA failover. ## PAN-298684 -Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and Network > Zones > Pre-NAT Identification enabled. +Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and **Network** > **Zones** > **Pre-NAT Identification** enabled. ## PAN-298654 @@ -92,9 +92,8 @@ Fixed an issue where, during a refresh of a large External Dynamic List (EDL), t Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual System field referenced the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. If you're using a multivsys environment, you must upgrade your firewalls to a fixed PAN-OS version. The best practice is to upgrade both the firewalls and Panorama to a fixed PAN-OS version. -If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama. - -After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations. +- If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama. +- After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations. ## PAN-297321 @@ -150,7 +149,7 @@ Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and T ## PAN-294893 -Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed. +Fixed an issue where firewalls with the **Send handshake messages to CTD for inspection** setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed. ## PAN-294770 @@ -170,7 +169,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the useridd proce ## PAN-293985 -Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout. +Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message **504: Gateway Timeout**. ## PAN-293877 @@ -182,7 +181,7 @@ Fixed an issue where, when using the Hub vsys feature to redistribute Host Infor ## PAN-293848 -Fixed an issue where Panorama failed to push the default value of None for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as None in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading. +Fixed an issue where Panorama failed to push the default value of **None** for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as **None** in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading. ## PAN-293511 @@ -194,7 +193,7 @@ Fixed an issue where setting the logdb-quota for the desum log type to 0 caused ## PAN-292447 -Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry. +Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry. ## PAN-292393 @@ -214,7 +213,7 @@ Fixed an issue where, after configuring dual stack GlobalProtect with both IPv4 ## PAN-292019 -Fixed an issue on the Panorama web interface where cloud applications were not displayed under Objects > Applications after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI. +Fixed an issue on the Panorama web interface where cloud applications were not displayed under **Objects > Applications** after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI. ## PAN-291883 @@ -262,7 +261,7 @@ Fixed an issue with firewalls enabled with Security profiles where certain traff VM-Series firewalls on Microsoft Azure environments in HA configurations only ``` -Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message Unknown error during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur. +Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message **Unknown error** during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur. ## PAN-290455 @@ -286,7 +285,7 @@ Fixed an issue where firewalls configured in vwire mode modified DSCP values fro ## PAN-287693 -Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when Use Proxy Settings for Private Cloud was enabled. +Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when **Use Proxy Settings for Private Cloud** was enabled. ## PAN-287622 diff --git a/web/data/issues/PAN-OS/addressed/11.2.11.md b/web/data/issues/PAN-OS/addressed/11.2.11.md index b94cd92..be6df5b 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.11.md +++ b/web/data/issues/PAN-OS/addressed/11.2.11.md @@ -1743,7 +1743,9 @@ Fixed an issue where the firewall did not automatically recover after a machine ## PAN-285181 -Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature. +Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF. + +To use this fix, run the CLI command debug iot eal memory-gc native ## PAN-285169 diff --git a/web/data/issues/PAN-OS/addressed/11.2.2-h2.md b/web/data/issues/PAN-OS/addressed/11.2.2-h2.md index 0bcb5f8..760bf7f 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.2-h2.md +++ b/web/data/issues/PAN-OS/addressed/11.2.2-h2.md @@ -6,4 +6,4 @@ version: 11.2.2-h2 ## PAN-272809 -A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474. +A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474). diff --git a/web/data/issues/PAN-OS/addressed/11.2.2.md b/web/data/issues/PAN-OS/addressed/11.2.2.md index 9fa5c8d..cf33b06 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.2.md +++ b/web/data/issues/PAN-OS/addressed/11.2.2.md @@ -14,7 +14,7 @@ Fixed an issue where the varrcvr process stopped responding when files were bein ## PAN-255773 -Fixed an issue where errors related to applications in Content-preview caused commit failures. +Fixed an issue where errors related to applications in **Content-preview** caused commit failures. ## PAN-248508 diff --git a/web/data/issues/PAN-OS/addressed/11.2.3-h3.md b/web/data/issues/PAN-OS/addressed/11.2.3-h3.md index 962493a..e917457 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.3-h3.md +++ b/web/data/issues/PAN-OS/addressed/11.2.3-h3.md @@ -6,7 +6,7 @@ version: 11.2.3-h3 ## PAN-272809 -A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474. +A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474). ## PAN-247230 diff --git a/web/data/issues/PAN-OS/addressed/11.2.3-h5.md b/web/data/issues/PAN-OS/addressed/11.2.3-h5.md index 1530740..6c80932 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.3-h5.md +++ b/web/data/issues/PAN-OS/addressed/11.2.3-h5.md @@ -18,7 +18,7 @@ Fixed an issue where the firewall did not reset the maximum latency timer for ho ## PAN-268823 -Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter. +Fixed an issue where **Monitor > Log Display** did not display all logs when you applied a filter. ## PAN-264549 @@ -26,4 +26,4 @@ Fixed an issue where, after modifying a policy rule on Panorama, pushes to the C ## PAN-259078 -Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error. +Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**. diff --git a/web/data/issues/PAN-OS/addressed/11.2.3.md b/web/data/issues/PAN-OS/addressed/11.2.3.md index 72c43dc..670d2f5 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.3.md +++ b/web/data/issues/PAN-OS/addressed/11.2.3.md @@ -22,7 +22,7 @@ Fixed an issue where dereferencing a NULL pointer that occurred when App-ID stop ## PAN-262013 -Fixed an issue where Prisma Access mobile users did not receive no such name DNS responses from the firewall and were timed out. +Fixed an issue where Prisma Access mobile users did not receive **no such name** DNS responses from the firewall and were timed out. ## PAN-261991 @@ -42,7 +42,7 @@ Fixed an issue where the firewall decremented the TTL/Hop limit for BGPv6 packet ## PAN-260059 -Fixed an issue where Device Telemetry Regions did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off. +Fixed an issue where **Device Telemetry Regions** did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off. ## PAN-259964 @@ -150,7 +150,7 @@ Fixed an issue where BGP routes from the active firewall were lost when the pass ## PAN-256666 -Fixed an issue where the configd process stopped responding when Commit and Push operations were performed on multiple device groups. +Fixed an issue where the configd process stopped responding when **Commit and Push** operations were performed on multiple device groups. ## PAN-256385 @@ -170,7 +170,7 @@ Fixed an issue where the logd process repeatedly restarted due to a buffer overf ## PAN-256249 -Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (Network > Network Profiles > IKE Gateways). +Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (**Network > Network Profiles > IKE Gateways**). ## PAN-256223 @@ -182,7 +182,7 @@ Fixed an issue where the management interface and front panel port interface sta ## PAN-255895 -Fixed an issue where Panorama administrators with the Panorama Administrator dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles. +Fixed an issue where Panorama administrators with the **Panorama Administrator** dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles. ## PAN-255820 @@ -190,7 +190,7 @@ Fixed an issue where the WildFire signature generation check box in Panorama did ## PAN-255711 -Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking OK on the configuration window due to the log type Correlation incorrectly being displayed (Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation). +Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking **OK** on the configuration window due to the log type **Correlation** incorrectly being displayed (**Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation**). ## PAN-255611 @@ -254,7 +254,7 @@ Fixed an issue where the firewall required a restart when an SD-WAN policy rule ## PAN-254411 -Fixed an issue where the configd process stopped responding, which caused ERR_CONNECTION_REFUSED error messages to be displayed in admin sessions. +Fixed an issue where the configd process stopped responding, which caused **ERR_CONNECTION_REFUSED** error messages to be displayed in admin sessions. ## PAN-254373 @@ -278,7 +278,7 @@ Fixed an issue where the CLI command show running security-policy timed out when ## PAN-253819 -Fixed an issue where a User Activity Report was not generated by Run Now or not emailed through the Email Schedule when the locale setting was not English. +Fixed an issue where a **User Activity Report** was not generated by **Run Now** or not emailed through the **Email Schedule** when the locale setting was not English. ## PAN-253452 @@ -350,7 +350,7 @@ Fixed an issue where network issues between the firewall and the log collector c ## PAN-250597 -Fixed an issue where Global Find for a Panorama pushed shared address object displayed Others in the results. +Fixed an issue where Global Find for a Panorama pushed shared address object displayed **Others** in the results. ## PAN-250462 @@ -378,7 +378,7 @@ Fixed an issue on the firewall where the Certificate Name character limit was 31 ## PAN-250127 -Fixed an issue where commits failed with the error message set is not allowed when default originate was enabled with a route map that included a set action. +Fixed an issue where commits failed with the error message set is not allowed when **default originate** was enabled with a route map that included a set action. ## PAN-250024 @@ -386,7 +386,7 @@ Fixed an issue related to the reportd process where you were unable to log in to ## PAN-250021 -Fixed an issue where Change Summary and Preview Changes displayed inconsistent information when changing an admin user password. +Fixed an issue where **Change Summary** and **Preview Changes** displayed inconsistent information when changing an admin user password. ## PAN-250005 @@ -422,7 +422,7 @@ Fixed an issue on Panorama where commits failed when Advanced Routing was enable ## PAN-248130 -Fixed an issue where the AND operation under a Dynamic Address Group comparison did not work after upgrading the AWS plugin to 3.0.1. +Fixed an issue where the **AND** operation under a Dynamic Address Group comparison did not work after upgrading the AWS plugin to 3.0.1. ## PAN-247857 @@ -434,7 +434,7 @@ Fixed an issue on the firewall where a dataplane process restarted when updating ## PAN-247754 -Fixed an issue where successful Commit and Push operations performed by SAML authenticated users were not reflected on the firewall. +Fixed an issue where successful **Commit and Push** operations performed by SAML authenticated users were not reflected on the firewall. ## PAN-247575 @@ -470,7 +470,7 @@ Fixed an issue where single TLS session packets were sent to multiple firewalls ## PAN-245892 -Fixed an issue where Log Filtering (Monitor > Logs) was slower than expected. +Fixed an issue where Log Filtering (**Monitor > Logs**) was slower than expected. ## PAN-245556 @@ -486,7 +486,7 @@ Fixed an issue where the firewall TLS/SSL service profile exclusion settings wer ## PAN-243387 -Fixed an issue where sessions ended with the message resources-unavailable when traffic hit a Security profile. +Fixed an issue where sessions ended with the message **resources-unavailable** when traffic hit a Security profile. ## PAN-243240 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h1.md b/web/data/issues/PAN-OS/addressed/11.2.4-h1.md index e5e7f19..db14b95 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h1.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h1.md @@ -6,4 +6,4 @@ version: 11.2.4-h1 ## PAN-272809 -A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474. +A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474). diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h10.md b/web/data/issues/PAN-OS/addressed/11.2.4-h10.md index 31b6d63..d6a3e16 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h10.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h10.md @@ -204,7 +204,7 @@ Fixed an issue where the firewall displayed inaccurate throughput utilization st ## PAN-259881 -Fixed an issue on Panorama where traffic log details were not displayed under detailed log view. +Fixed an issue on Panorama where traffic log details were not displayed under **detailed log view**. ## PAN-258757 @@ -224,7 +224,7 @@ Fixed an issue on Panorama where configuration locks were observed during a part ## PAN-246699 -Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy rules stopped incrementing. +Fixed an issue on Panorama where **Rule Usage** and **Apps Seen** under Security policy rules stopped incrementing. ## PAN-245064 @@ -232,4 +232,4 @@ Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy Multi-vsys firewalls only ``` -Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required. +Fixed an issue where commits failed on the firewall after selecting **Export or push device config bundle** on Panorama and a force push was required. diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h11.md b/web/data/issues/PAN-OS/addressed/11.2.4-h11.md index e11b313..00bea96 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h11.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h11.md @@ -30,11 +30,13 @@ Fixed an issue where the logrcvr process stopped responding due to an invalid SS ## PAN-287688 -Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT. +Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**. ## PAN-279901 -Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP. +An issue was fixed where the firewall dropped fragmented TLS ClientHello packets, which blocked access to certain websites. This occurred because the packets arrived truncated, in varying sizes and orders, and the firewall's heuristics failed to handle them correctly. + +To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes ## PAN-268680 @@ -42,7 +44,7 @@ Fixed an issue where the configd process stopped responding when a configuration ## PAN-268522 -Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4. +Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4. ## PAN-255914 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h12.md b/web/data/issues/PAN-OS/addressed/11.2.4-h12.md index 635c144..1da4fcd 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h12.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h12.md @@ -82,7 +82,7 @@ Fixed an issue where content loading issues occurred on IPv6 websites due to the ## PAN-286299 -Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only. +Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tabs became read-only. ## PAN-285285 @@ -106,7 +106,7 @@ Fixed an issue where Panorama did not update all panreplay database entries afte ## PAN-276484 -Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes. +Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes. ## PAN-273453 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h14.md b/web/data/issues/PAN-OS/addressed/11.2.4-h14.md index 5ebd3d7..ea538d4 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h14.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h14.md @@ -62,7 +62,7 @@ Fixed an issue where, after upgrading to PAN-OS 11.1.6-h6 the Eth1/2, Eth1/3, Et ## PAN-292447 -Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry. +Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry. ## PAN-291940 @@ -86,7 +86,7 @@ Fixed an issue on Panorama where API jobs failed with the error message Server e ## PAN-284279 -Fixed an issue where the policy destination always defaulted to any, even when specific IP addresses and FQDNs were specified during policy import. +Fixed an issue where the policy destination always defaulted to **any**, even when specific IP addresses and FQDNs were specified during policy import. ## PAN-284067 @@ -94,7 +94,7 @@ Fixed a cumulative memory leak in the devsrvr process that occurred whenever the ## PAN-281776 -Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured. +Fixed an issue on the Panorama web interface where the error message **PPPoEv6 Client Interface cannot be enabled with DHCPv6 client** was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured. ## PAN-279829 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h15.md b/web/data/issues/PAN-OS/addressed/11.2.4-h15.md index b316eb3..0d9ff02 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h15.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h15.md @@ -4,6 +4,6 @@ product: PAN-OS version: 11.2.4-h15 --- -## PAN-000000 +## BLANK-000000 -A fix was made to address CVE-2026-0227. +A fix was made to address [CVE-2026-0227](https://security.paloaltonetworks.com/CVE-2026-0227). diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h2.md b/web/data/issues/PAN-OS/addressed/11.2.4-h2.md index d7d6eea..85e0b0c 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h2.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h2.md @@ -18,4 +18,4 @@ Fixed an issue where the firewall did not reset the maximum latency timer for ho ## PAN-259078 -Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error. +Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**. diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h4.md b/web/data/issues/PAN-OS/addressed/11.2.4-h4.md index 43e8aae..d06b5f8 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h4.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h4.md @@ -14,15 +14,15 @@ Fixed an issue where upgrading Panorama and pushing configurations to the firewa ## PAN-273994 -A fix was made to address CVE-2025-0111. +A fix was made to address [CVE-2025-0111](https://security.paloaltonetworks.com/CVE-2025-0111). ## PAN-273971 -A fix was made to address CVE-2025-0108. +A fix was made to address [CVE-2025-0108](https://security.paloaltonetworks.com/CVE-2025-0108). ## PAN-273278 -A fix was made to address CVE-2025-0109. +A fix was made to address [CVE-2025-0109](https://security.paloaltonetworks.com/CVE-2025-0109). ## PAN-273197 @@ -94,7 +94,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the all_task proc ## PAN-265742 -Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable. +Fixed an issue on the Panorama web interface where the **OK** button on the GlobalProtect gateway configuration dialog box was not clickable. ## PAN-263987 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h5.md b/web/data/issues/PAN-OS/addressed/11.2.4-h5.md index 18f14d5..f0c6d85 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h5.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h5.md @@ -10,7 +10,7 @@ Fixed an issue where scheduled SaaS application usage reports were generated inc ## PAN-276177 -Fixed an issue where App Acceleration did not work with Oracle databases. +Fixed an issue where **App Acceleration** did not work with Oracle databases. ## PAN-274791 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h6.md b/web/data/issues/PAN-OS/addressed/11.2.4-h6.md index f26e8c1..b17d3a9 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h6.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h6.md @@ -18,7 +18,7 @@ Fixed an issue where large IPv6 packets were reassembled incorrectly on the fire ## PAN-282206 -Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present. +Fixed an issue where configuring Secure Web Gateway (SWG) in **no-auth** mode led to latency when no decryption policy rules or **No-decrypt** policy rules were present. ## PAN-282022 @@ -26,7 +26,7 @@ Fixed the support limitation for the Panorama M-600 and M-700 appliances. ## PAN-280471 -Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected. +Fixed an issue where navigating **Panorama > Monitor > Logs** was slower than expected. ## PAN-279746 @@ -90,7 +90,7 @@ Fixed an issue on Panorama where the configd process stopped responding when fil ## PAN-271351 -A fix was made to address CVE-2025-0116. +A fix was made to address [CVE-2025-0116](https://security.paloaltonetworks.com/CVE-2025-0116). ## PAN-270224 @@ -158,7 +158,7 @@ Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr p ## PAN-257619 -Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks. +Fixed an issue on Panorama where the **Task Manager** took longer than expected to display managed firewall report tasks. ## PAN-257028 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h7.md b/web/data/issues/PAN-OS/addressed/11.2.4-h7.md index bf6687a..05ae056 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h7.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h7.md @@ -26,7 +26,7 @@ Fixed an issue where the firewall did not match the correct policy for SSL forwa ## PAN-268474 -Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop. +Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as **Valid** even when the firewall did not have the license, which caused traffic to drop. ## PAN-261999 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4-h9.md b/web/data/issues/PAN-OS/addressed/11.2.4-h9.md index f07ba6c..abfaefc 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4-h9.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4-h9.md @@ -22,7 +22,7 @@ Fixed a race condition issue related to predict processing, which resulted in a ## PAN-287002 -A fix was made to address CVE-2025-0133. +A fix was made to address [CVE-2025-0133](https://security.paloaltonetworks.com/CVE-2025-0133). ## PAN-285894 @@ -54,7 +54,7 @@ Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInE Firewalls in HA configurations only ``` -Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts. +Fixed an issue where, after an upgrade, the **mac receive error** counter in **receive incoming errors** increased, which resulted in SNMP alerts. ## PAN-283467 @@ -66,7 +66,7 @@ Fixed an issue where the firewall unexpectedly rebooted and entered maintenance ## PAN-283331 -Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured. +Fixed an issue where selective pushes to managed devices failed when the **User ID Master Device** was configured. ## PAN-282069 @@ -106,7 +106,7 @@ Fixed an issue on firewalls in HA configurations where, when using the Cloud Ide ## PAN-271273 -Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface. +Fixed an issue where dynamic update downloads failed when **IPv6 firewalling** was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface. ## PAN-270379 @@ -138,7 +138,7 @@ Fixed an issue where large file downloads or uploads failed or remained in an in ## PAN-266900 -Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall. +Fixed an issue on the Panorama web interface where you were unable to click **OK** after selecting an install package type and file from the dropdown and selecting a firewall. ## PAN-265745 diff --git a/web/data/issues/PAN-OS/addressed/11.2.4.md b/web/data/issues/PAN-OS/addressed/11.2.4.md index 44a34bc..a7c5872 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.4.md +++ b/web/data/issues/PAN-OS/addressed/11.2.4.md @@ -10,7 +10,7 @@ Fixed an issue where, after modifying a policy rule on Panorama, pushes to the C ## PAN-268823 -Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter. +Fixed an issue where **Monitor > Log Display** did not display all logs when you applied a filter. ## PAN-267386 @@ -82,7 +82,7 @@ Fixed an issue where the firewall reported the same value over consecutive SNMP ## PAN-259767 -Fixed an issue where GlobalProtect users were unable to connect when the option Block sessions if the certificate was not issued to the authenticating device was enabled in the certificate profile. +Fixed an issue where GlobalProtect users were unable to connect when the option **Block sessions if the certificate was not issued to the authenticating device** was enabled in the certificate profile. ## PAN-259002 @@ -158,7 +158,7 @@ Fixed an issue where link flaps occurred on Panorama appliances in HA configurat ## PAN-225213 -Fixed an issue where Push All Changes displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group. +Fixed an issue where **Push All Changes** displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group. ## PAN-222542 diff --git a/web/data/issues/PAN-OS/addressed/11.2.5.md b/web/data/issues/PAN-OS/addressed/11.2.5.md index b61db1e..84547a6 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.5.md +++ b/web/data/issues/PAN-OS/addressed/11.2.5.md @@ -98,11 +98,11 @@ Fixed an issue where the firewall was unable to generate a TSF file due to a ful ## PAN-268474 -Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop. +Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as **Valid** even when the firewall did not have the license, which caused traffic to drop. ## PAN-268419 -Fixed an issue where Managed Devices > Summary displayed incorrect subcolumns. +Fixed an issue where **Managed Devices > Summary** displayed incorrect subcolumns. ## PAN-268229 @@ -110,7 +110,7 @@ Fixed an issue where the firewall stopped responding during session setup for EC ## PAN-268228 -Fixed an issue where Panorama administrators were unable to select Edit Selection when pushing changes to devices if they logged in using TACACS authentication. +Fixed an issue where Panorama administrators were unable to select **Edit Selection** when pushing changes to devices if they logged in using TACACS authentication. ## PAN-268127 @@ -154,7 +154,7 @@ Fixed an issue where multicast streams were unstable with ECMP and dropped every ## PAN-266900 -Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall. +Fixed an issue on the Panorama web interface where you were unable to click **OK** after selecting an install package type and file from the dropdown and selecting a firewall. ## PAN-266704 @@ -190,7 +190,7 @@ Fixed an issue where BFD sessions took longer than expected to establish after a ## PAN-266167 -Fixed an issue where the restart option for IPSec tunnels was greyed out (Network > IPSec Tunnels > IKE Info). +Fixed an issue where the **restart** option for IPSec tunnels was greyed out (**Network > IPSec Tunnels > IKE Info**). ## PAN-266003 @@ -210,11 +210,11 @@ Added debug functionality in the packet-diag log to address an issue regarding p ## PAN-265742 -Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable. +Fixed an issue on the Panorama web interface where the **OK** button on the GlobalProtect gateway configuration dialog box was not clickable. ## PAN-265621 -Fixed an issue where the restart option for IPSec tunnels was greyed out when you attempted to restart the tunnel from Network > IPSec Tunnels > IKE Info. +Fixed an issue where the **restart** option for IPSec tunnels was greyed out when you attempted to restart the tunnel from **Network > IPSec Tunnels > IKE Info**. ## PAN-265462 @@ -234,7 +234,7 @@ Fixed an issue where multiple segments of HTTP proxy connect messages were not h ## PAN-265344 -Fixed an issue where Import GlobalProtect Client Package did not work after clicking OK after selecting a valid package under Device > GlobalProtect Client > Upload). +Fixed an issue where **Import GlobalProtect Client Package** did not work after clicking **OK** after selecting a valid package under **Device > GlobalProtect Client > Upload**). ## PAN-265179 @@ -270,15 +270,15 @@ Fixed an issue where OSPF adjacencies failed to come up when using a subinterfac PA-220 firewalls only ``` -Fixed an issue where Device > Setup was not displayed on the web interface. +Fixed an issue where **Device > Setup** was not displayed on the web interface. ## PAN-264678 -Fixed an issue where Preview Changes did not display configuration changes in Commit and push > Push Scope. +Fixed an issue where **Preview Changes** did not display configuration changes in **Commit and push** > **Push Scope**. ## PAN-264662 -Fixed an issue where HTTP POST requests were blocked for URLs that had the block-continue category configured. +Fixed an issue where HTTP POST requests were blocked for URLs that had the **block-continue** category configured. ## PAN-264289 @@ -306,7 +306,7 @@ Fixed an issue where log collectors had a low incoming log rate. PA-440 firewalls only ``` -Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the Auto option for the interface duplex setting. +Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the **Auto** option for the interface duplex setting. ## PAN-263843 @@ -378,7 +378,7 @@ Fixed an issue on firewalls in HA configurations where OSPF neighbors were not e ## PAN-262415 -Fixed an issue where a partial configuration load failed for configuration files that contained regenerate-hostkeys. +Fixed an issue where a partial configuration load failed for configuration files that contained **regenerate-hostkeys**. ## PAN-261997 @@ -514,7 +514,7 @@ Fixed an issue where BGP Aggregate Advertise filters did not work as expected wh ## PAN-260193 -Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to Use System Default. +Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to **Use System Default**. ## PAN-260149 @@ -538,7 +538,7 @@ Fixed an issue where the firewalls behind an Amazon Web Services (AWS) Gateway L ## PAN-259881 -Fixed an issue on Panorama where traffic log details were not displayed under detailed log view. +Fixed an issue on Panorama where traffic log details were not displayed under **detailed log view**. ## PAN-259870 @@ -562,11 +562,11 @@ Fixed an issue on Panorama where the web interface was slower than expected or u ## PAN-259200 -Fixed an issue where the firewall displayed truncated zone names in the Block IP List log when a zone name contained more than 14 characters. +Fixed an issue where the firewall displayed truncated zone names in the **Block IP List** log when a zone name contained more than 14 characters. ## PAN-259078 -Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error. +Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**. ## PAN-258996 @@ -610,7 +610,7 @@ Fixed an issue on the Panorama web interface where Security policy rules loaded ## PAN-258188 -Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the OK button did not work. +Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the **OK** button did not work. ## PAN-258149 @@ -618,7 +618,7 @@ Fixed an issue where the firewall dropped the SYN-ACK when using the TCP Fast Op ## PAN-257961 -Fixed an issue on Panorama where Test Security Policy Match failed when the From or To zone fields were populated. +Fixed an issue on Panorama where **Test Security Policy Match** failed when the **From** or **To** zone fields were populated. ## PAN-257912 @@ -654,7 +654,7 @@ Fixed an issue where firewalls entered a non-functional state and displayed the ## PAN-257021 -"Fixed an issue on the web interface where Match Evidence log details for Monitor > Correlated events did not populate." +"Fixed an issue on the web interface where **Match Evidence** log details for **Monitor > Correlated events** did not populate." ## PAN-256960 @@ -662,7 +662,7 @@ Fixed an issue where a custom portal login page was not displayed correctly in t ## PAN-256725 -Fixed an issue on the Panorama interface where Traffic and Unified event details loaded more slowly than expected. +Fixed an issue on the Panorama interface where **Traffic** and **Unified** event details loaded more slowly than expected. ## PAN-256669 @@ -690,7 +690,7 @@ Fixed an issue where GTP sessions remained as allocated sessions on the passive ## PAN-256115 -Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a disconnected status for the inter-log collector connection. +Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a **disconnected** status for the inter-log collector connection. ## PAN-255930 @@ -762,7 +762,7 @@ Fixed an issue where multiple SSHD process restarts triggered a firewall reboot ## PAN-252801 -Fixed an issue where the LSVPN tunnel monitoring status displayed as No data available after re-key events. +Fixed an issue where the LSVPN tunnel monitoring status displayed as **No data available** after re-key events. ## PAN-252604 @@ -770,7 +770,7 @@ Fixed an issue where the clientless VPN did not carry authentication to other ta ## PAN-252370 -Fixed an issue where services with the reserved keyword application-default were allowed. +Fixed an issue where services with the reserved keyword **application-default** were allowed. ## PAN-252300 @@ -822,7 +822,7 @@ Fixed an issue where stale BGP routes were advertised to peers even when they we ## PAN-249533 -Fixed an issue where an internal error message was displayed when you selected Exclude video traffic from the tunnel (Windows and macOS only). +Fixed an issue where an internal error message was displayed when you selected **Exclude video traffic from the tunnel (Windows and macOS only)**. ## PAN-249384 @@ -878,7 +878,7 @@ Fixed an issue where the web interface stopped responding when you searched for ## PAN-242957 -Fixed an issue where the Rule usage columns of overridden default policy rules on the Security policy page stopped responding. +Fixed an issue where the **Rule usage** columns of overridden default policy rules on the Security policy page stopped responding. ## PAN-242602 @@ -910,7 +910,7 @@ Fixed an issue where some commands did not have executable permissions. ## PAN-212889 -Fixed an issue on Panorama where different threat names were used when querying a threat under Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in Threat Monitor and filtering it in the global filters. +Fixed an issue on Panorama where different threat names were used when querying a threat under **Threat Monitor** (**Monitor > App Scope**) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in **Threat Monitor** and filtering it in the global filters. ## PAN-199141 diff --git a/web/data/issues/PAN-OS/addressed/11.2.6.md b/web/data/issues/PAN-OS/addressed/11.2.6.md index 7357a11..6c734ea 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.6.md +++ b/web/data/issues/PAN-OS/addressed/11.2.6.md @@ -46,7 +46,7 @@ Fixed an issue where large IPv6 packets were reassembled incorrectly on the fire ## PAN-282206 -Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present. +Fixed an issue where configuring Secure Web Gateway (SWG) in **no-auth** mode led to latency when no decryption policy rules or **No-decrypt** policy rules were present. ## PAN-282069 @@ -62,7 +62,7 @@ Fixed an Issue where commits failed with the error invalid IPv6 x:x - must be gl ## PAN-280471 -Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected. +Fixed an issue where navigating **Panorama > Monitor > Logs** was slower than expected. ## PAN-279983 @@ -70,7 +70,7 @@ Fixed an issue where navigating Panorama > Monitor > Logs was slower than expect PA-1400 Series firewalls only ``` -Fixed an issue on the web interface where Enable Bonjour Reflector was not displayed (Network > Interfaces > Ethernet Interface). +Fixed an issue on the web interface where **Enable Bonjour Reflector** was not displayed (**Network > Interfaces > Ethernet Interface**). ## PAN-279746 @@ -122,7 +122,7 @@ Fixed an issue where unexpected failovers occurred on firewalls running PAN-OS 1 ## PAN-277751 -Fixed an issue where a policy-based forwarding (PBF) rule with an action of no-pbf and a service of TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a result, traffic was matched by a lower rule with a service of any and an action of forward. +Fixed an issue where a policy-based forwarding (PBF) rule with an action of **no-pbf** and a service of TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a result, traffic was matched by a lower rule with a service of **any** and an action of **forward**. ## PAN-277629 @@ -150,7 +150,7 @@ Fixed an issue where a session lost the PBF rule mapping after a configuration c ## PAN-276177 -Fixed an issue where App Acceleration did not work with Oracle databases. +Fixed an issue where **App Acceleration** did not work with Oracle databases. ## PAN-276090 @@ -200,7 +200,7 @@ Fixed an issue where the firewall did not log the correct NAT IP address and sou ## PAN-273129 -Fixed an issue on the web interface where the negate option was visible when you clicked on the rule name, but not when you viewed the target options from the rulebase attribute. +Fixed an issue on the web interface where the **negate** option was visible when you clicked on the rule name, but not when you viewed the target options from the **rulebase** attribute. ## PAN-273026 @@ -220,7 +220,7 @@ Fixed an issue where log forwarding to a UDP syslog server stopped when an unrea ## PAN-272538 -Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and share-unused-objects-with-devices was set to off. +Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and **share-unused-objects-with-devices** was set to off. ## PAN-272171 @@ -244,7 +244,7 @@ Fixed an issue where pushing changes to a prefix list used for BGP from Panorama ## PAN-271273 -Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface. +Fixed an issue where dynamic update downloads failed when **IPv6 firewalling** was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface. ## PAN-271181 @@ -364,7 +364,7 @@ Fixed an issue where the firewall displayed an OCSP/CRL check failure when acces ## PAN-257619 -Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks. +Fixed an issue on Panorama where the **Task Manager** took longer than expected to display managed firewall report tasks. ## PAN-255914 @@ -388,7 +388,7 @@ Fixed an issue where the Panorama web interface was slower than expected when op Multi-vsys firewalls only ``` -Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required. +Fixed an issue where commits failed on the firewall after selecting **Export or push device config bundle** on Panorama and a force push was required. ## PAN-233647 diff --git a/web/data/issues/PAN-OS/addressed/11.2.7-h1.md b/web/data/issues/PAN-OS/addressed/11.2.7-h1.md index c12b2fd..b08aee5 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.7-h1.md +++ b/web/data/issues/PAN-OS/addressed/11.2.7-h1.md @@ -42,7 +42,7 @@ Fixed an issue where persistent commit failures occurred due to a missing transf ## PAN-289268 -Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user . +Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not **known-user**. ## PAN-288939 @@ -66,7 +66,9 @@ Fixed an issue where the popup window did not appear as expected for Clientless ## PAN-279901 -Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP. +An issue was fixed where the firewall dropped fragmented TLS ClientHello packets, which blocked access to certain websites. This occurred because the packets arrived truncated, in varying sizes and orders, and the firewall's heuristics failed to handle them correctly. + +To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes ## PAN-279690 @@ -98,4 +100,4 @@ Fixed an issue where the all_pktproc process stopped responding when the firewal ## PAN-252706 -Fixed an issue where the URL filtering response page for Continue and Override did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic. +Fixed an issue where the URL filtering response page for **Continue** and **Override** did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic. diff --git a/web/data/issues/PAN-OS/addressed/11.2.7-h10.md b/web/data/issues/PAN-OS/addressed/11.2.7-h10.md index e3fb4f2..101fd10 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.7-h10.md +++ b/web/data/issues/PAN-OS/addressed/11.2.7-h10.md @@ -16,9 +16,8 @@ Fixed an issue where a leak in decryption counters caused resource exhaustion, w Fixed two issues that impacted TLSv1.2 or earlier sessions when the traffic matched a decryption policy rule with the no-decrypt action: -Connections failed when both HTTP header insertion (Objects > Security Profiles > URL Filtering > HTTP Header Insertion) and Send handshake messages to CTD for inspection (Device > Setup > Session > Decryption Settings > SSL Decryption Settings) were enabled. - -New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both Block sessions with expired certificates and Block sessions with untrusted issuers disabled. +- Connections failed when both HTTP header insertion (**Objects > Security Profiles > URL Filtering > HTTP Header Insertion**) and **Send handshake messages to CTD for inspection** (**Device > Setup > Session > Decryption Settings > SSL Decryption Settings**) were enabled. +- New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both **Block sessions with expired certificates** and **Block sessions with untrusted issuers** disabled. ## PAN-306103 @@ -66,7 +65,7 @@ Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code Subject Common Name ``` -Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the , Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs. +Fixed an issue where certificate data was missing in decryption logs for **No decrypt** policy rules and TLS1.2 traffic after upgrading, and the , **Issuer Common Name**, **Certificate Start Date**,**Certificate End Date**, **Certificate Serial Number**, and **Certificate Fingerprint** fields were blank in the decryption logs. ## PAN-283563 @@ -82,7 +81,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f ## PAN-259853 -Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when Any was selected as the source interface in the service router configuration (DeviceSetupServiceService Router Configuration). +Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when **Any** was selected as the source interface in the service router configuration (**Device** > **Setup** > **Service** > **Service Router Configuration**). ## PAN-258039 diff --git a/web/data/issues/PAN-OS/addressed/11.2.7-h11.md b/web/data/issues/PAN-OS/addressed/11.2.7-h11.md index ca2a2b9..003c860 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.7-h11.md +++ b/web/data/issues/PAN-OS/addressed/11.2.7-h11.md @@ -34,7 +34,9 @@ Fixed an issue where devices with 5G cellular modems did not support the ATT Fir ## PAN-285181 -Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature. +Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF. + +To use this fix, run the CLI command debug iot eal memory-gc native ## PAN-278688 diff --git a/web/data/issues/PAN-OS/addressed/11.2.7-h2.md b/web/data/issues/PAN-OS/addressed/11.2.7-h2.md index 6fd182e..bbcac28 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.7-h2.md +++ b/web/data/issues/PAN-OS/addressed/11.2.7-h2.md @@ -18,7 +18,7 @@ Fixed an issue where the useridd process became unresponsive, which caused User ## PAN-287688 -Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT. +Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**. ## PAN-268680 @@ -26,7 +26,7 @@ Fixed an issue where the configd process stopped responding when a configuration ## PAN-268522 -Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4. +Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4. ## PAN-241230 diff --git a/web/data/issues/PAN-OS/addressed/11.2.7-h3.md b/web/data/issues/PAN-OS/addressed/11.2.7-h3.md index bb8fffc..61de5fb 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.7-h3.md +++ b/web/data/issues/PAN-OS/addressed/11.2.7-h3.md @@ -58,7 +58,7 @@ Fixed an issue where content loading issues occurred on IPv6 websites due to the ## PAN-286299 -Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only. +Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tabs became read-only. ## PAN-286231 @@ -86,7 +86,7 @@ Fixed an issue where WildFire reports were not fully displayed and were not down ## PAN-276484 -Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes. +Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes. ## PAN-259741 diff --git a/web/data/issues/PAN-OS/addressed/11.2.7-h4.md b/web/data/issues/PAN-OS/addressed/11.2.7-h4.md index b885f6c..d5ddec9 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.7-h4.md +++ b/web/data/issues/PAN-OS/addressed/11.2.7-h4.md @@ -34,7 +34,7 @@ Fixed an issue where a dataplane crash occurred when traffic matched Inline Clou ## PAN-297775 -Fixed an issue where, after upgrading, the Visible Virtual Systems field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. +Fixed an issue where, after upgrading, the **Visible Virtual Systems** field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. ## PAN-297240 @@ -58,7 +58,7 @@ Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and T ## PAN-294893 -Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed. +Fixed an issue where firewalls with the **Send handshake messages to CTD for inspection** setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed. ## PAN-294524 @@ -74,7 +74,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the useridd proce ## PAN-292447 -Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry. +Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry. ## PAN-291940 diff --git a/web/data/issues/PAN-OS/addressed/11.2.7-h8.md b/web/data/issues/PAN-OS/addressed/11.2.7-h8.md index 2342e04..e2500af 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.7-h8.md +++ b/web/data/issues/PAN-OS/addressed/11.2.7-h8.md @@ -6,7 +6,7 @@ version: 11.2.7-h8 ## PAN-308727 -Fixed an issue where traffic logs for Remote Networks displayed the source zone as trust instead of the remote network name. +Fixed an issue where traffic logs for **Remote Networks** displayed the source zone as **trust** instead of the remote network name. ## PAN-308468 @@ -18,7 +18,7 @@ Fixed an issue on Panorama where a memory leak occurred related to the reportd p ## PAN-302927 -Fixed an issue where, after upgrading Panorama, the Push to Devices option did not display selected devices, and the OK and Cancel buttons did not function as expected. Selecting OK did not close the window, and selecting Cancel returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting Push or Validate Device Group Push still pushed to the previously canceled, non-displayed devices. +Fixed an issue where, after upgrading Panorama, the **Push to Devices** option did not display selected devices, and the **OK** and **Cancel** buttons did not function as expected. Selecting **OK** did not close the window, and selecting **Cancel** returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting **Push** or **Validate Device Group Push** still pushed to the previously canceled, non-displayed devices. ## PAN-301801 @@ -64,7 +64,7 @@ Fixed an issue where exporting custom reports resulted in empty CSV files. ## PAN-296977 -Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in NetworkInterfaces +Fixed an issue where the web interface became unresponsive when attempting to view **Ethernet** interface details after applying a filter in **Network** > **Interfaces** ## PAN-296752 @@ -96,7 +96,7 @@ Fixed an issue where the logrcvr process stopped responding due to memory alloca ## PAN-293985 -Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout. +Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message **504: Gateway Timeout**. ## PAN-292770 @@ -140,7 +140,7 @@ Fixed an issue where the routed process core failed the automation run. ## PAN-209516 -Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory. +Fixed an issue where, when creating an interface, an error occurred when you clicked **OK** without providing a value in the **Tag** field even though the field was not displayed as mandatory. ## PAN-185731 diff --git a/web/data/issues/PAN-OS/addressed/11.2.7.md b/web/data/issues/PAN-OS/addressed/11.2.7.md index 06c68ab..46a913e 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.7.md +++ b/web/data/issues/PAN-OS/addressed/11.2.7.md @@ -34,7 +34,7 @@ Fixed a race condition issue related to predict processing, which resulted in a ## PAN-288930 -Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled. +Fixed an issue where traffic from cloud applications intermittently matched an incorrect **cloud-apps** policy rule when ACE (App-ID Cloud Engine) was enabled. ## PAN-287818 @@ -54,7 +54,7 @@ Fixed an issue where ECMP incorrectly balanced sessions across links based on th ## PAN-286825 -Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the inactivity-logout setting was deleted and set to a different value. +Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the **inactivity-logout** setting was deleted and set to a different value. ## PAN-285894 @@ -102,7 +102,7 @@ Fixed an issue on Panorama where the web interface performance was slower than u Firewalls in HA configurations only ``` -Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts. +Fixed an issue where, after an upgrade, the **mac receive error** counter in **receive incoming errors** increased, which resulted in SNMP alerts. ## PAN-283644 @@ -114,11 +114,11 @@ Fixed an issue where URL log ingestion decreased after an upgrade, and secondary ## PAN-283331 -Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured. +Fixed an issue where selective pushes to managed devices failed when the **User ID Master Device** was configured. ## PAN-282697 -Fixed an issue where traffic was delayed significantly when it used No Authentication Explicit Proxy and matched a decryption policy rule. +Fixed an issue where traffic was delayed significantly when it used **No Authentication Explicit Proxy** and matched a decryption policy rule. ## PAN-282640 @@ -142,7 +142,7 @@ Fixed an issue where the Panorama web interface was slower than expected. ## PAN-282240 -Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the OK button displayed a console exception error. +Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the **OK** button displayed a console exception error. ## PAN-281885 @@ -228,7 +228,7 @@ Fixed an issue where accessing a URL from the browser returned the error message ## PAN-279400 -Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly. +Fixed an issue where, when **Restrict Certificate Extensions** was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly. ## PAN-279336 @@ -240,7 +240,7 @@ Fixed an issue where the configuration audit displayed inaccurate information af ## PAN-279065 -Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs. +Fixed an issue where the firewall sent logs with **connection succeeded** to the syslog server every time a connection was established, which resulted in excessive logs. ## PAN-278981 @@ -280,11 +280,11 @@ Fixed an issue where the logrcvr process discarded logs due to a full queue. ## PAN-277464 -Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the SSL Command and Control action was not either allow or alert and server hello packets were out of order. +Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the **SSL Command and Control** action was not either **allow** or **alert** and server hello packets were out of order. ## PAN-277234 -Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none. +Fixed an issue where a device group import resulted in a Security policy rule being created with **Application** set to **none**. ## PAN-277147 @@ -320,7 +320,7 @@ Fixed an issue where Panorama stopped forwarding logs to a syslog server after u ## PAN-275713 -Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine. +Fixed an issue where the dscd process stopped responding when **Endpoint Serial Number** was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine. ## PAN-275133 @@ -392,7 +392,7 @@ Fixed an issue where packets were dropped initially when a SYN cookie with activ ## PAN-273597 -Fixed an issue where logs in the cloud database displayed in the Not-Resolved category but not in the local database. +Fixed an issue where logs in the cloud database displayed in the **Not-Resolved** category but not in the local database. ## PAN-273453 @@ -522,7 +522,7 @@ Fixed an issue where the firewall redirected the user to the first application i Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only ``` -Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted. +Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the **mac receive error** counter increased without an error even though traffic was not impacted. ## PAN-268708 @@ -530,7 +530,7 @@ Fixed an issue where PDF summary and email reports displayed IPv6 addresses inst ## PAN-268614 -Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox. +Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the **Highlight Unused Rules** checkbox. ## PAN-268489 @@ -610,7 +610,7 @@ Fixed an issue where a commit for a policy and configuration dump overlapped, wh ## PAN-261074 -Fixed an issue where the firewall delayed video file transfers over SMB when Exclude Video Traffic from the Tunnel feature was enabled and no applications were added to the list. +Fixed an issue where the firewall delayed video file transfers over SMB when **Exclude Video Traffic** from the Tunnel feature was enabled and no applications were added to the list. ## PAN-260229 @@ -670,7 +670,7 @@ Fixed an issue on Panorama where a core file was generated by /usr/local/bin/log ## PAN-254524 -Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed. +Fixed an issue on Panorama where, when the **Commit and Push** button was clicked during a selective **Commit and Push** operation, the window stopped responding, which caused the operation to be delayed. ## PAN-253127 diff --git a/web/data/issues/PAN-OS/addressed/11.2.8.md b/web/data/issues/PAN-OS/addressed/11.2.8.md index 43feff9..7b300d0 100644 --- a/web/data/issues/PAN-OS/addressed/11.2.8.md +++ b/web/data/issues/PAN-OS/addressed/11.2.8.md @@ -18,7 +18,7 @@ Fixed an issue where the logrcvr process stopped responding due to memory alloca ## PAN-294488 -Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the Subject Common Name, Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs. +Fixed an issue where certificate data was missing in decryption logs for **No decrypt** policy rules and TLS1.2 traffic after upgrading, and the **Subject Common Name**, **Issuer Common Name**, **Certificate Start Date**, **Certificate End Date**, **Certificate Serial Number**, and **Certificate Fingerprint** fields were blank in the decryption logs. ## PAN-294436 @@ -46,7 +46,7 @@ Fixed an issue where, after upgrading the firewall having an IKE gateway that us Panorama virtual appliances in FIPS mode only ``` -Fixed an issue where plugin installs failed with the error invalid image after manually uploading the plugin package from the Customer Support Portal (CSP). +Fixed an issue where plugin installs failed with the error **invalid image** after manually uploading the plugin package from the Customer Support Portal (CSP). ## PAN-292503 @@ -142,7 +142,7 @@ Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections P Panorama virtual appliances only ``` -Fixed an issue on the web interface where you were unable to export the Threat Map. +Fixed an issue on the web interface where you were unable to export the **Threat Map**. ## PAN-290900 @@ -150,11 +150,11 @@ Fixed an issue where Panorama in FIPS-CC mode failed to push IKEv2 Post-Quantum ## PAN-290702 -Fixed an issue where Log Quotas incorrectly displayed a value that was higher than possible. +Fixed an issue where **Log Quotas** incorrectly displayed a value that was higher than possible. ## PAN-290694 -Fixed an issue on the Panorama web interface where you were unable to push shared objects to devices if an HA failover occurred during a configuration push. +Fixed an issue on the Panorama web interface where you were unable to **push** shared objects to devices if an HA failover occurred during a configuration push. ## PAN-290691 @@ -166,15 +166,15 @@ Fixed an issue where, when multiple scheduled vulnerability reports were were se ## PAN-290241 -Fixed an issue where the useridd process became unresponsive, which caused User ID CLI commands to time out. +Fixed an issue where the **useridd** process became unresponsive, which caused User ID CLI commands to time out. ## PAN-290191 -Fixed an issue where BGP learned routes were not advertised when Legacy Routing was used and an export policy rule was configured to match the next hop of the learned route. +Fixed an issue where BGP learned routes were not advertised when **Legacy Routing** was used and an export policy rule was configured to match the next hop of the learned route. ## PAN-290157 -Fixed an issue on Panorama where the configd process stopped responding when filtering in the Config Audit window, which caused Panorama to restart unexpectedly. +Fixed an issue on Panorama where the configd process stopped responding when filtering in the **Config Audit** window, which caused Panorama to restart unexpectedly. ## PAN-290088 @@ -226,7 +226,7 @@ Fixed an issue related to external URL lists where pushing configuration changes ## PAN-289573 -Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries. +Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the **Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access** setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries. ## PAN-289532 @@ -266,7 +266,7 @@ Fixed an issue on the Panorama web interface where a template name or device gro ## PAN-289268 -Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user. +Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not **known-user**. ## PAN-289239 @@ -370,7 +370,7 @@ Fixed an issue where the maximum registered IP address for was incorrectly set t ## PAN-287842 -Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1. +Fixed an issue where the **comm** process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1. ## PAN-287838 @@ -386,11 +386,11 @@ Fixed an issue where SAML authentication failed, which caused the GlobalProtect ## PAN-287734 -Fixed an issue where the error message Scan ERR: Internal Err 1002 was generated unexpectedly when WIF shared memory use was high. +Fixed an issue where the error message **Scan ERR: Internal Err 1002** was generated unexpectedly when WIF shared memory use was high. ## PAN-287688 -Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT. +Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**. ## PAN-287621 @@ -474,7 +474,7 @@ Fixed an issue where the device-group-tags CLI command used an unnecessary confi VM-Series firewalls only AWS environments only ``` -Fixed an issue where the firewall did not send ICMP unreachable - Fragmentation Needed message when it received packets larger than the MTU. +Fixed an issue where the firewall did not send **ICMP unreachable - Fragmentation Needed** message when it received packets larger than the MTU. ## PAN-286818 @@ -486,7 +486,7 @@ Fixed an issue where closing an SSH session to a Panorama using Ctrl+D did not g Panorama virtual appliances in HA configurations on Microsoft Azure environments only ``` -Fixed an issue where plugin versions displayed when hovering over the Green Match icon were inconsistent even though the web interface reported the versions as matching. +Fixed an issue where plugin versions displayed when hovering over the **Green Match** icon were inconsistent even though the web interface reported the versions as matching. ## PAN-286734 @@ -502,7 +502,7 @@ Added uplink counters to enhance debug capability for traffic drops. Panorama appliances only ``` -Fixed an issue where the Require SSL/TLS secured connection in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times. +Fixed an issue where the **Require SSL/TLS secured connection** in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times. ## PAN-286669 @@ -526,7 +526,7 @@ Fixed an issue on Panorama where logs were not forwarded to syslog servers due t ## PAN-286475 -Fixed an issue where the option to sort sequence numbers was missing from Filters prefix list in the advanced routing filters. +Fixed an issue where the option to sort sequence numbers was missing from **Filters prefix list** in the advanced routing filters. ## PAN-286443 @@ -538,7 +538,7 @@ Fixed an issue where, when getting transceiver information from ESCC for SFP 25G ## PAN-286299 -Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tab became read-only. +Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tab became read-only. ## PAN-286231 @@ -562,7 +562,7 @@ Fixed an issue where the XML API returned an error when attempting to view debug ## PAN-285834 -Fixed an issue on Panorama where Policy recommendation displayed Unable to read data for certain profiles due to a large response size. +Fixed an issue on Panorama where **Policy recommendation** displayed **Unable to read data** for certain profiles due to a large response size. ## PAN-285818 @@ -606,7 +606,7 @@ Fixed an issue where commits remained at 98% completion when static route config ## PAN-284907 -Fixed an issue where the Panorama web interface displayed No Data when viewing configuration logs to see changes before and after a configuration change. +Fixed an issue where the Panorama web interface displayed **No Data** when viewing configuration logs to see changes before and after a configuration change. ## PAN-284878 @@ -638,7 +638,7 @@ Fixed an issue where, when a firewall had more than 4,400 logical interfaces, co ## PAN-284441 -Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message Network Connection is unreachable. +Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message **Network Connection is unreachable**. ## PAN-284380 @@ -702,7 +702,7 @@ Fixed an issue where HTTP/2 child streams were blocked by strict-ip-check zone p ## PAN-283613 -Fixed an issue on the web interface where the IP Tag Quota(%) value displayed as 2 even when changed. +Fixed an issue on the web interface where the **IP Tag** **Quota(%)** value displayed as 2 even when changed. ## PAN-283575 @@ -726,7 +726,7 @@ Fixed an issue where the SAML single log out (SLO) URL was not correctly display ## PAN-283333 -Fixed an issue where threat logs displayed logs from the N/A threat category when a random string was used for the category-of-threatid filter in threat logs. +Fixed an issue where threat logs displayed logs from the **N/A** threat category when a random string was used for the **category-of-threatid** filter in threat logs. ## PAN-283316 @@ -738,7 +738,7 @@ Fixed an issue where the OSPFv3 area nssa default-information-originate CLI comm ## PAN-283206 -Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking Send Test Log. +Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking **Send Test Log**. ## PAN-283168 @@ -774,7 +774,7 @@ Fixed an issue where firewalls in air-gapped environments attempted to connect t ## PAN-282454 -Fixed an issue where, when you added the Virtual System Name column under Unified Logs, the column did not remain visible in the table if you closed and re-opened the tab. +Fixed an issue where, when you added the **Virtual System Name** column under **Unified Logs**, the column did not remain visible in the table if you closed and re-opened the tab. ## PAN-282277 @@ -786,7 +786,7 @@ Fixed an issue where firewalls became unstable and stopped responding, which res ## PAN-281776 -Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured. +Fixed an issue on the Panorama web interface where the error message **PPPoEv6 Client Interface cannot be enabled with DHCPv6 client** was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured. ## PAN-281596 @@ -810,11 +810,11 @@ Fixed an issue on Panorama managed firewalls where, when the service route confi ## PAN-281096 -Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to all, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down. +Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to **all**, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down. ## PAN-281017 -Fixed an issue where shared objects were displayed in the Push Scope after pushing the configuration from Panorama to managed firewalls. +Fixed an issue where shared objects were displayed in the **Push Scope** after pushing the configuration from Panorama to managed firewalls. ## PAN-280910 @@ -846,7 +846,7 @@ Fixed an issue in the URL filtering logs where the columns and the displayed con ## PAN-280013 -Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter ip notin 0.0.0.0. +Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter **ip notin 0.0.0.0**. ## PAN-279829 @@ -870,7 +870,7 @@ Fixed an issue where threat names were displayed differently on the web interfac ## PAN-279584 -Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when Reboot device after install was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent. +Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when **Reboot device after install** was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent. ## PAN-279415 @@ -886,7 +886,7 @@ Fixed an issue where changes made to the management interface permitted IP addre ## PAN-279195 -Fixed an issue on Panorama where Device Health displayed the device memory as 0%. +Fixed an issue on Panorama where **Device Health** displayed the device memory as 0%. ## PAN-278836 @@ -902,7 +902,7 @@ Fixed an issue where the configd process restarted during a configuration push f ## PAN-278507 -Fixed an issue where the OCSP Signing purpose was not included in the Extended Key Usage field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error Missing OCSP signing purpose in the ExtendedKeyUsage. +Fixed an issue where the OCSP Signing purpose was not included in the **Extended Key Usage** field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error **Missing OCSP signing purpose in the ExtendedKeyUsage**. ## PAN-278364 @@ -926,7 +926,7 @@ Fixed an issue where the number of registered IP Tags on Panorama did not match VM-Series firewalls in AWS environments only ``` -Fixed an issue where HA failover mode incorrectly changed from interface move to secondary IP move after a reboot. +Fixed an issue where HA failover mode incorrectly changed from **interface move** to **secondary IP move** after a reboot. ## PAN-277759 @@ -938,7 +938,7 @@ Fixed an issue that caused the request system private-data-reset CLI command to ## PAN-277682 -Fixed an issue where moving an address object from a device group to shared and renaming it did not reflect in the address group, which caused commits to fail. +Fixed an issue where moving an address object from a device group to **shared** and renaming it did not reflect in the address group, which caused commits to fail. ## PAN-277617 @@ -978,7 +978,7 @@ Fixed an issue on Panorama where the logd process stopped responding unexpectedl ## PAN-276795 -Fixed an issue where the GlobalProtect client displayed an error message when you clicked Check Now and Preferred Releases and Base Releases were unchecked (Device > Software). +Fixed an issue where the GlobalProtect client displayed an error message when you clicked **Check Now** and **Preferred Releases** and **Base Releases** were unchecked (**Device > Software**). ## PAN-276694 @@ -1002,11 +1002,11 @@ Fixed an issue where Panorama stopped responding when running reports. ## PAN-276484 -Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes. +Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes. ## PAN-276412 -Fixed an issue where you were unable to download XML files from Panorama > Summary > Backups. +Fixed an issue where you were unable to download XML files from **Panorama > Summary > Backups**. ## PAN-276352 @@ -1014,15 +1014,15 @@ Fixed an issue where multicast flows were dropped due to a missing sysd variable ## PAN-276321 -Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as unknown, which prevented access to resources based on AD group membership. +Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as **unknown**, which prevented access to resources based on AD group membership. ## PAN-276144 -Fixed an issue on the web interface where the Response Page action column was not accessible. +Fixed an issue on the web interface where the **Response Page** **action** column was not accessible. ## PAN-276033 -Fixed an issue on Panorama managed firewalls where SAML identity provider and Clientless Apps objects did not have override or revert options. +Fixed an issue on Panorama managed firewalls where **SAML identity provider** and **Clientless Apps** objects did not have override or revert options. ## PAN-276000 @@ -1038,7 +1038,7 @@ Fixed an issue where the Log Collector service did not start on a new Log Collec ## PAN-275601 -Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the Validate option, the upload failed with the error Failed to create multi-upload job. No valid software deploy targets found. +Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the **Validate** option, the upload failed with the error **Failed to create multi-upload job. No valid software deploy targets found**. ## PAN-275451 @@ -1066,7 +1066,7 @@ Fixed an issue where you were unable to to adjust the frequency of the Advanced ## PAN-274907 -Fixed an issue on Panorama where Config Audit Commit Date displayed the timestamp of the configuration edit instead of the commit time. +Fixed an issue on Panorama where **Config Audit Commit Date** displayed the timestamp of the configuration edit instead of the commit time. ## PAN-274650 @@ -1106,11 +1106,11 @@ Fixed an issue on Panorama where the request batch license info CLI command disp ## PAN-274038 -Fixed an issue where you were unable to use the s_encrypted field in custom reports for the Panorama threat log database. +Fixed an issue where you were unable to use the **s_encrypted** field in custom reports for the Panorama threat log database. ## PAN-273991 -Fixed an issue where the transmit power for a cable that was used on port 44 displayed as N/A. +Fixed an issue where the transmit power for a cable that was used on port 44 displayed as **N/A**. ## PAN-273969 @@ -1134,7 +1134,7 @@ Fixed an issue where firewalls configured with a VPN tunnel stopped responding w ## PAN-273010 -Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the Rule Changes field of the Security policy rule. +Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the **Rule Changes** field of the Security policy rule. ## PAN-273008 @@ -1154,15 +1154,15 @@ Fixed an issue where you were unable to export the GlobalProtect client software ## PAN-272790 -Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an scp export failed error. This was due to the system attempting to retrieve the file from an incorrect directory. +Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an **scp export failed** error. This was due to the system attempting to retrieve the file from an incorrect directory. ## PAN-272743 -Fixed an issue where non-captive portal traffic was not visible under Traffic Logs when the traffic was denied by an authentication rule and the session was discarded. +Fixed an issue where non-captive portal traffic was not visible under **Traffic Logs** when the traffic was denied by an authentication rule and the session was discarded. ## PAN-272726 -Fixed an issue on the web interface where the URL Filtering change category feature did not work. +Fixed an issue on the web interface where the **URL Filtering** change category feature did not work. ## PAN-272505 @@ -1170,7 +1170,7 @@ Fixed an issue where GlobalProtect cookie authentication failed with the error U ## PAN-272469 -Fixed an issue where the DNS exception displayed 0 instead of no result in the anti-spyware profile when no threat ID was available for a DNS Security category. +Fixed an issue where the DNS exception displayed **0** instead of **no result** in the anti-spyware profile when no threat ID was available for a DNS Security category. ## PAN-272408 @@ -1222,7 +1222,7 @@ A CLI counter was added to indicate a full suppression queue. ## PAN-271412 -Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as #43; on the GlobalProtect client after upgrading to a PAN-OS 10.2 release. +Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as **#43;** on the GlobalProtect client after upgrading to a PAN-OS 10.2 release. ## PAN-271301 @@ -1242,7 +1242,7 @@ Fixed an issue where the firewall displayed an incorrect maximum translated IP c ## PAN-271061 -Fixed an issue on the web interface where you were unable to add Threat IDs to Signature Exceptions. +Fixed an issue on the web interface where you were unable to add Threat IDs to **Signature Exceptions**. ## PAN-270747 @@ -1266,11 +1266,11 @@ Fixed an issue threat reports were empty when generated from Panorama, but displ ## PAN-269843 -Fixed an issue where the firewall dropped non-SYN TCP packets even when the Reject non-SYN TCP option was set to No when a session rematch was triggered. +Fixed an issue where the firewall dropped non-SYN TCP packets even when the **Reject non-SYN TCP** option was set to **No** when a session rematch was triggered. ## PAN-269716 -Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option toTrue. +Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option to True. ## PAN-269659 @@ -1310,7 +1310,7 @@ Fixed an issue where the aggressive clean-up threshold for disk space was set to ## PAN-269176 -Fixed an issue where the domain-edl column was empty in the threat log even when a threat was detected as a DNS alert. +Fixed an issue where the **domain-edl** column was empty in the threat log even when a threat was detected as a DNS alert. ## PAN-269155 @@ -1342,7 +1342,7 @@ Fixed an issue where the configd process stopped responding when a configuration ## PAN-268606 -Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking connect or login. +Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking **connect** or **login**. ## PAN-268597 @@ -1354,7 +1354,7 @@ Fixed an issue where the web interface was slower than expected when logging in ## PAN-268522 -Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4. +Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4. ## PAN-268426 @@ -1376,11 +1376,9 @@ Fixed an issue where importing a device configuration into Panorama failed with To use this fix: -Enable the configuration. Commit failures may occur if the device is not able to support the number of objects. - -Export and push the device group only. - -Push the template. +1. Enable the configuration. Commit failures may occur if the device is not able to support the number of objects. +2. Export and push the device group only. +3. Push the template. Note: This fix is supported on PAN-OS 10.2 and later releases. @@ -1390,7 +1388,7 @@ Fixed an issue where commits failed with a validation error when you changed the ## PAN-267912 -Fixed an issue on the Panorama web interface where Application and Category was not able to be selected under Test Policy Match. +Fixed an issue on the Panorama web interface where **Application** and **Category** was not able to be selected under **Test Policy Match**. ## PAN-267830 @@ -1406,7 +1404,7 @@ Fixed an issue where the Panorama web interface was slower than expected due to Firewalls in HA configuration only ``` -Fixed an issue where the Network pre-negotiation enabled page did not display on the firewall dashboard. +Fixed an issue where the **Network pre-negotiation enabled** page did not display on the firewall dashboard. ## PAN-267381 @@ -1426,7 +1424,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f VM-Series firewalls only ``` -Fixed an issue where BGP route refreshes occurred when a commit was performed if AS Set was enabled for BGP aggregate routes. +Fixed an issue where BGP route refreshes occurred when a commit was performed if **AS Set** was enabled for BGP aggregate routes. ## PAN-267045 @@ -1438,7 +1436,7 @@ Fixed an issue where the firewall generated AAAA DNS queries when IPv6 firewalli ## PAN-266905 -Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a no-decrypt policy. +Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a **no-decrypt** policy. ## PAN-266698 @@ -1506,7 +1504,7 @@ Fixed an issue where the routed process core failed the automation run. ## PAN-264040 -Fixed an issue where AAAA DNS queries went out even when IPv6 firewalling was disabled. +Fixed an issue where AAAA DNS queries went out even when **IPv6 firewalling** was disabled. ## PAN-263699 @@ -1558,7 +1556,7 @@ Fixed an issue where Voice over WiFi (VoWiFi) stopped working after switching fr ## PAN-261936 -Fixed an issue where WildFire submission logs were not displayed when filtered by Sender Address. +Fixed an issue where WildFire submission logs were not displayed when filtered by **Sender Address**. ## PAN-261602 @@ -1566,7 +1564,7 @@ Fixed an issue where GlobalProtect Decryption logs were not forwarded to Panoram ## PAN-260879 -Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the Secure Communication Settings. +Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the **Secure Communication Settings**. ## PAN-260790 @@ -1582,7 +1580,7 @@ Fixed an issue where daily email reports generated from the custom report did no ## PAN-260581 -Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to None. +Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to **None**. ## PAN-260540 @@ -1606,7 +1604,7 @@ Fixed an issue where the firewall dropped GRE keepalive packets that were encaps ## PAN-259343 -Fixed an issue on the Panorama web interface where the Configuration tab did not accurately display changes made to URL filtering profiles. +Fixed an issue on the Panorama web interface where the **Configuration** tab did not accurately display changes made to URL filtering profiles. ## PAN-259284 @@ -1638,7 +1636,7 @@ Fixed an issue where the firewall dataplane stopped responding, which caused BGP ## PAN-257616 -Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push. +Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message **Failed to generate selective push configuration. Schema validation failed. Please try a full push**. ## PAN-257362 @@ -1654,11 +1652,11 @@ Fixed an issue where the mp-monitor logs did not print disk SMART data. ## PAN-257074 -Fixed an issue on the Panorama web interface where the template sync status showed Out-of-Sync for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum. +Fixed an issue on the Panorama web interface where the template sync status showed **Out-of-Sync** for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum. ## PAN-256560 -Fixed an issue where exporting a Custom Report to CSV format did not display the full report if it contained non-ASCII characters. +Fixed an issue where exporting a **Custom Report** to CSV format did not display the full report if it contained non-ASCII characters. ## PAN-256552 @@ -1746,7 +1744,7 @@ Fixed an issue where the class of service (CoS) priority bit was not modified, c ## PAN-252706 -Fixed an issue where the URL filtering response page for Continue and Override did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic. +Fixed an issue where the URL filtering response page for **Continue** and **Override** did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic. ## PAN-252699 @@ -1786,17 +1784,17 @@ Fixed an issue on the Panorama web interface where you were unable to add static ## PAN-242777 -Fixed and issue where users previously reported limitations due to session count caps when utilizing Web Proxy features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific PA-5400F series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments. +Fixed and issue where users previously reported limitations due to session count caps when utilizing **Web Proxy** features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific **PA-5400F** series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments. The supported session limits are: | Platform | Max Sessions | -| --- | --- | -| PA-5410 | 95K | -| PA-5420 | 95K | -| PA-5430 | 95K | -| PA-5440 | 225K | -| PA-5445 | 250K | +| -------- | ------------ | +| PA-5410 | 95K | +| PA-5420 | 95K | +| PA-5430 | 95K | +| PA-5440 | 225K | +| PA-5445 | 250K | ## PAN-241953 @@ -1812,7 +1810,7 @@ Fixed an issue where the SNMP get request status value for Panorama connections ## PAN-238208 -Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error Session is invalid if the session is not available for the cookie. +Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error **Session is invalid** if the session is not available for the cookie. ## PAN-234993