Revise PAN-OS 11.2 addressed issues
This commit is contained in:
@@ -58,7 +58,7 @@ Fixed an issue where ports went down after an HA failover.
|
||||
|
||||
## PAN-298684
|
||||
|
||||
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and Network > Zones > Pre-NAT Identification enabled.
|
||||
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and **Network** > **Zones** > **Pre-NAT Identification** enabled.
|
||||
|
||||
## PAN-298654
|
||||
|
||||
@@ -92,9 +92,8 @@ Fixed an issue where, during a refresh of a large External Dynamic List (EDL), t
|
||||
|
||||
Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual System field referenced the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. If you're using a multivsys environment, you must upgrade your firewalls to a fixed PAN-OS version. The best practice is to upgrade both the firewalls and Panorama to a fixed PAN-OS version.
|
||||
|
||||
If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama.
|
||||
|
||||
After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
|
||||
- If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama.
|
||||
- After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
|
||||
|
||||
## PAN-297321
|
||||
|
||||
@@ -150,7 +149,7 @@ Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and T
|
||||
|
||||
## PAN-294893
|
||||
|
||||
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
Fixed an issue where firewalls with the **Send handshake messages to CTD for inspection** setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
|
||||
## PAN-294770
|
||||
|
||||
@@ -170,7 +169,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the useridd proce
|
||||
|
||||
## PAN-293985
|
||||
|
||||
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
|
||||
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message **504: Gateway Timeout**.
|
||||
|
||||
## PAN-293877
|
||||
|
||||
@@ -182,7 +181,7 @@ Fixed an issue where, when using the Hub vsys feature to redistribute Host Infor
|
||||
|
||||
## PAN-293848
|
||||
|
||||
Fixed an issue where Panorama failed to push the default value of None for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as None in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
|
||||
Fixed an issue where Panorama failed to push the default value of **None** for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as **None** in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
|
||||
|
||||
## PAN-293511
|
||||
|
||||
@@ -194,7 +193,7 @@ Fixed an issue where setting the logdb-quota for the desum log type to 0 caused
|
||||
|
||||
## PAN-292447
|
||||
|
||||
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
|
||||
## PAN-292393
|
||||
|
||||
@@ -214,7 +213,7 @@ Fixed an issue where, after configuring dual stack GlobalProtect with both IPv4
|
||||
|
||||
## PAN-292019
|
||||
|
||||
Fixed an issue on the Panorama web interface where cloud applications were not displayed under Objects > Applications after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI.
|
||||
Fixed an issue on the Panorama web interface where cloud applications were not displayed under **Objects > Applications** after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI.
|
||||
|
||||
## PAN-291883
|
||||
|
||||
@@ -262,7 +261,7 @@ Fixed an issue with firewalls enabled with Security profiles where certain traff
|
||||
VM-Series firewalls on Microsoft Azure environments in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message Unknown error during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
|
||||
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message **Unknown error** during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
|
||||
|
||||
## PAN-290455
|
||||
|
||||
@@ -286,7 +285,7 @@ Fixed an issue where firewalls configured in vwire mode modified DSCP values fro
|
||||
|
||||
## PAN-287693
|
||||
|
||||
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when Use Proxy Settings for Private Cloud was enabled.
|
||||
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when **Use Proxy Settings for Private Cloud** was enabled.
|
||||
|
||||
## PAN-287622
|
||||
|
||||
|
||||
Reference in New Issue
Block a user