Revise PAN-OS 11.2 addressed issues
This commit is contained in:
@@ -16,9 +16,8 @@ Fixed an issue where a leak in decryption counters caused resource exhaustion, w
|
||||
|
||||
Fixed two issues that impacted TLSv1.2 or earlier sessions when the traffic matched a decryption policy rule with the no-decrypt action:
|
||||
|
||||
Connections failed when both HTTP header insertion (Objects > Security Profiles > URL Filtering > HTTP Header Insertion) and Send handshake messages to CTD for inspection (Device > Setup > Session > Decryption Settings > SSL Decryption Settings) were enabled.
|
||||
|
||||
New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both Block sessions with expired certificates and Block sessions with untrusted issuers disabled.
|
||||
- Connections failed when both HTTP header insertion (**Objects > Security Profiles > URL Filtering > HTTP Header Insertion**) and **Send handshake messages to CTD for inspection** (**Device > Setup > Session > Decryption Settings > SSL Decryption Settings**) were enabled.
|
||||
- New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both **Block sessions with expired certificates** and **Block sessions with untrusted issuers** disabled.
|
||||
|
||||
## PAN-306103
|
||||
|
||||
@@ -66,7 +65,7 @@ Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code
|
||||
Subject Common Name
|
||||
```
|
||||
|
||||
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the , Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
|
||||
Fixed an issue where certificate data was missing in decryption logs for **No decrypt** policy rules and TLS1.2 traffic after upgrading, and the , **Issuer Common Name**, **Certificate Start Date**,**Certificate End Date**, **Certificate Serial Number**, and **Certificate Fingerprint** fields were blank in the decryption logs.
|
||||
|
||||
## PAN-283563
|
||||
|
||||
@@ -82,7 +81,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f
|
||||
|
||||
## PAN-259853
|
||||
|
||||
Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when Any was selected as the source interface in the service router configuration (DeviceSetupServiceService Router Configuration).
|
||||
Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when **Any** was selected as the source interface in the service router configuration (**Device** > **Setup** > **Service** > **Service Router Configuration**).
|
||||
|
||||
## PAN-258039
|
||||
|
||||
|
||||
Reference in New Issue
Block a user