Revise PAN-OS 11.2 addressed issues
This commit is contained in:
@@ -18,7 +18,7 @@ Fixed an issue where the logrcvr process stopped responding due to memory alloca
|
||||
|
||||
## PAN-294488
|
||||
|
||||
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the Subject Common Name, Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
|
||||
Fixed an issue where certificate data was missing in decryption logs for **No decrypt** policy rules and TLS1.2 traffic after upgrading, and the **Subject Common Name**, **Issuer Common Name**, **Certificate Start Date**, **Certificate End Date**, **Certificate Serial Number**, and **Certificate Fingerprint** fields were blank in the decryption logs.
|
||||
|
||||
## PAN-294436
|
||||
|
||||
@@ -46,7 +46,7 @@ Fixed an issue where, after upgrading the firewall having an IKE gateway that us
|
||||
Panorama virtual appliances in FIPS mode only
|
||||
```
|
||||
|
||||
Fixed an issue where plugin installs failed with the error invalid image after manually uploading the plugin package from the Customer Support Portal (CSP).
|
||||
Fixed an issue where plugin installs failed with the error **invalid image** after manually uploading the plugin package from the Customer Support Portal (CSP).
|
||||
|
||||
## PAN-292503
|
||||
|
||||
@@ -142,7 +142,7 @@ Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections P
|
||||
Panorama virtual appliances only
|
||||
```
|
||||
|
||||
Fixed an issue on the web interface where you were unable to export the Threat Map.
|
||||
Fixed an issue on the web interface where you were unable to export the **Threat Map**.
|
||||
|
||||
## PAN-290900
|
||||
|
||||
@@ -150,11 +150,11 @@ Fixed an issue where Panorama in FIPS-CC mode failed to push IKEv2 Post-Quantum
|
||||
|
||||
## PAN-290702
|
||||
|
||||
Fixed an issue where Log Quotas incorrectly displayed a value that was higher than possible.
|
||||
Fixed an issue where **Log Quotas** incorrectly displayed a value that was higher than possible.
|
||||
|
||||
## PAN-290694
|
||||
|
||||
Fixed an issue on the Panorama web interface where you were unable to push shared objects to devices if an HA failover occurred during a configuration push.
|
||||
Fixed an issue on the Panorama web interface where you were unable to **push** shared objects to devices if an HA failover occurred during a configuration push.
|
||||
|
||||
## PAN-290691
|
||||
|
||||
@@ -166,15 +166,15 @@ Fixed an issue where, when multiple scheduled vulnerability reports were were se
|
||||
|
||||
## PAN-290241
|
||||
|
||||
Fixed an issue where the useridd process became unresponsive, which caused User ID CLI commands to time out.
|
||||
Fixed an issue where the **useridd** process became unresponsive, which caused User ID CLI commands to time out.
|
||||
|
||||
## PAN-290191
|
||||
|
||||
Fixed an issue where BGP learned routes were not advertised when Legacy Routing was used and an export policy rule was configured to match the next hop of the learned route.
|
||||
Fixed an issue where BGP learned routes were not advertised when **Legacy Routing** was used and an export policy rule was configured to match the next hop of the learned route.
|
||||
|
||||
## PAN-290157
|
||||
|
||||
Fixed an issue on Panorama where the configd process stopped responding when filtering in the Config Audit window, which caused Panorama to restart unexpectedly.
|
||||
Fixed an issue on Panorama where the configd process stopped responding when filtering in the **Config Audit** window, which caused Panorama to restart unexpectedly.
|
||||
|
||||
## PAN-290088
|
||||
|
||||
@@ -226,7 +226,7 @@ Fixed an issue related to external URL lists where pushing configuration changes
|
||||
|
||||
## PAN-289573
|
||||
|
||||
Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.
|
||||
Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the **Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access** setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.
|
||||
|
||||
## PAN-289532
|
||||
|
||||
@@ -266,7 +266,7 @@ Fixed an issue on the Panorama web interface where a template name or device gro
|
||||
|
||||
## PAN-289268
|
||||
|
||||
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user.
|
||||
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not **known-user**.
|
||||
|
||||
## PAN-289239
|
||||
|
||||
@@ -370,7 +370,7 @@ Fixed an issue where the maximum registered IP address for was incorrectly set t
|
||||
|
||||
## PAN-287842
|
||||
|
||||
Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
|
||||
Fixed an issue where the **comm** process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
|
||||
|
||||
## PAN-287838
|
||||
|
||||
@@ -386,11 +386,11 @@ Fixed an issue where SAML authentication failed, which caused the GlobalProtect
|
||||
|
||||
## PAN-287734
|
||||
|
||||
Fixed an issue where the error message Scan ERR: Internal Err 1002 was generated unexpectedly when WIF shared memory use was high.
|
||||
Fixed an issue where the error message **Scan ERR: Internal Err 1002** was generated unexpectedly when WIF shared memory use was high.
|
||||
|
||||
## PAN-287688
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**.
|
||||
|
||||
## PAN-287621
|
||||
|
||||
@@ -474,7 +474,7 @@ Fixed an issue where the device-group-tags CLI command used an unnecessary confi
|
||||
VM-Series firewalls only AWS environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not send ICMP unreachable - Fragmentation Needed message when it received packets larger than the MTU.
|
||||
Fixed an issue where the firewall did not send **ICMP unreachable - Fragmentation Needed** message when it received packets larger than the MTU.
|
||||
|
||||
## PAN-286818
|
||||
|
||||
@@ -486,7 +486,7 @@ Fixed an issue where closing an SSH session to a Panorama using Ctrl+D did not g
|
||||
Panorama virtual appliances in HA configurations on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where plugin versions displayed when hovering over the Green Match icon were inconsistent even though the web interface reported the versions as matching.
|
||||
Fixed an issue where plugin versions displayed when hovering over the **Green Match** icon were inconsistent even though the web interface reported the versions as matching.
|
||||
|
||||
## PAN-286734
|
||||
|
||||
@@ -502,7 +502,7 @@ Added uplink counters to enhance debug capability for traffic drops.
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where the Require SSL/TLS secured connection in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.
|
||||
Fixed an issue where the **Require SSL/TLS secured connection** in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.
|
||||
|
||||
## PAN-286669
|
||||
|
||||
@@ -526,7 +526,7 @@ Fixed an issue on Panorama where logs were not forwarded to syslog servers due t
|
||||
|
||||
## PAN-286475
|
||||
|
||||
Fixed an issue where the option to sort sequence numbers was missing from Filters prefix list in the advanced routing filters.
|
||||
Fixed an issue where the option to sort sequence numbers was missing from **Filters prefix list** in the advanced routing filters.
|
||||
|
||||
## PAN-286443
|
||||
|
||||
@@ -538,7 +538,7 @@ Fixed an issue where, when getting transceiver information from ESCC for SFP 25G
|
||||
|
||||
## PAN-286299
|
||||
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tab became read-only.
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tab became read-only.
|
||||
|
||||
## PAN-286231
|
||||
|
||||
@@ -562,7 +562,7 @@ Fixed an issue where the XML API returned an error when attempting to view debug
|
||||
|
||||
## PAN-285834
|
||||
|
||||
Fixed an issue on Panorama where Policy recommendation displayed Unable to read data for certain profiles due to a large response size.
|
||||
Fixed an issue on Panorama where **Policy recommendation** displayed **Unable to read data** for certain profiles due to a large response size.
|
||||
|
||||
## PAN-285818
|
||||
|
||||
@@ -606,7 +606,7 @@ Fixed an issue where commits remained at 98% completion when static route config
|
||||
|
||||
## PAN-284907
|
||||
|
||||
Fixed an issue where the Panorama web interface displayed No Data when viewing configuration logs to see changes before and after a configuration change.
|
||||
Fixed an issue where the Panorama web interface displayed **No Data** when viewing configuration logs to see changes before and after a configuration change.
|
||||
|
||||
## PAN-284878
|
||||
|
||||
@@ -638,7 +638,7 @@ Fixed an issue where, when a firewall had more than 4,400 logical interfaces, co
|
||||
|
||||
## PAN-284441
|
||||
|
||||
Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message Network Connection is unreachable.
|
||||
Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message **Network Connection is unreachable**.
|
||||
|
||||
## PAN-284380
|
||||
|
||||
@@ -702,7 +702,7 @@ Fixed an issue where HTTP/2 child streams were blocked by strict-ip-check zone p
|
||||
|
||||
## PAN-283613
|
||||
|
||||
Fixed an issue on the web interface where the IP Tag Quota(%) value displayed as 2 even when changed.
|
||||
Fixed an issue on the web interface where the **IP Tag** **Quota(%)** value displayed as 2 even when changed.
|
||||
|
||||
## PAN-283575
|
||||
|
||||
@@ -726,7 +726,7 @@ Fixed an issue where the SAML single log out (SLO) URL was not correctly display
|
||||
|
||||
## PAN-283333
|
||||
|
||||
Fixed an issue where threat logs displayed logs from the N/A threat category when a random string was used for the category-of-threatid filter in threat logs.
|
||||
Fixed an issue where threat logs displayed logs from the **N/A** threat category when a random string was used for the **category-of-threatid** filter in threat logs.
|
||||
|
||||
## PAN-283316
|
||||
|
||||
@@ -738,7 +738,7 @@ Fixed an issue where the OSPFv3 area nssa default-information-originate CLI comm
|
||||
|
||||
## PAN-283206
|
||||
|
||||
Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking Send Test Log.
|
||||
Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking **Send Test Log**.
|
||||
|
||||
## PAN-283168
|
||||
|
||||
@@ -774,7 +774,7 @@ Fixed an issue where firewalls in air-gapped environments attempted to connect t
|
||||
|
||||
## PAN-282454
|
||||
|
||||
Fixed an issue where, when you added the Virtual System Name column under Unified Logs, the column did not remain visible in the table if you closed and re-opened the tab.
|
||||
Fixed an issue where, when you added the **Virtual System Name** column under **Unified Logs**, the column did not remain visible in the table if you closed and re-opened the tab.
|
||||
|
||||
## PAN-282277
|
||||
|
||||
@@ -786,7 +786,7 @@ Fixed an issue where firewalls became unstable and stopped responding, which res
|
||||
|
||||
## PAN-281776
|
||||
|
||||
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
|
||||
Fixed an issue on the Panorama web interface where the error message **PPPoEv6 Client Interface cannot be enabled with DHCPv6 client** was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
|
||||
|
||||
## PAN-281596
|
||||
|
||||
@@ -810,11 +810,11 @@ Fixed an issue on Panorama managed firewalls where, when the service route confi
|
||||
|
||||
## PAN-281096
|
||||
|
||||
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to all, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
|
||||
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to **all**, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
|
||||
|
||||
## PAN-281017
|
||||
|
||||
Fixed an issue where shared objects were displayed in the Push Scope after pushing the configuration from Panorama to managed firewalls.
|
||||
Fixed an issue where shared objects were displayed in the **Push Scope** after pushing the configuration from Panorama to managed firewalls.
|
||||
|
||||
## PAN-280910
|
||||
|
||||
@@ -846,7 +846,7 @@ Fixed an issue in the URL filtering logs where the columns and the displayed con
|
||||
|
||||
## PAN-280013
|
||||
|
||||
Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter ip notin 0.0.0.0.
|
||||
Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter **ip notin 0.0.0.0**.
|
||||
|
||||
## PAN-279829
|
||||
|
||||
@@ -870,7 +870,7 @@ Fixed an issue where threat names were displayed differently on the web interfac
|
||||
|
||||
## PAN-279584
|
||||
|
||||
Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when Reboot device after install was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent.
|
||||
Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when **Reboot device after install** was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent.
|
||||
|
||||
## PAN-279415
|
||||
|
||||
@@ -886,7 +886,7 @@ Fixed an issue where changes made to the management interface permitted IP addre
|
||||
|
||||
## PAN-279195
|
||||
|
||||
Fixed an issue on Panorama where Device Health displayed the device memory as 0%.
|
||||
Fixed an issue on Panorama where **Device Health** displayed the device memory as 0%.
|
||||
|
||||
## PAN-278836
|
||||
|
||||
@@ -902,7 +902,7 @@ Fixed an issue where the configd process restarted during a configuration push f
|
||||
|
||||
## PAN-278507
|
||||
|
||||
Fixed an issue where the OCSP Signing purpose was not included in the Extended Key Usage field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error Missing OCSP signing purpose in the ExtendedKeyUsage.
|
||||
Fixed an issue where the OCSP Signing purpose was not included in the **Extended Key Usage** field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error **Missing OCSP signing purpose in the ExtendedKeyUsage**.
|
||||
|
||||
## PAN-278364
|
||||
|
||||
@@ -926,7 +926,7 @@ Fixed an issue where the number of registered IP Tags on Panorama did not match
|
||||
VM-Series firewalls in AWS environments only
|
||||
```
|
||||
|
||||
Fixed an issue where HA failover mode incorrectly changed from interface move to secondary IP move after a reboot.
|
||||
Fixed an issue where HA failover mode incorrectly changed from **interface move** to **secondary IP move** after a reboot.
|
||||
|
||||
## PAN-277759
|
||||
|
||||
@@ -938,7 +938,7 @@ Fixed an issue that caused the request system private-data-reset CLI command to
|
||||
|
||||
## PAN-277682
|
||||
|
||||
Fixed an issue where moving an address object from a device group to shared and renaming it did not reflect in the address group, which caused commits to fail.
|
||||
Fixed an issue where moving an address object from a device group to **shared** and renaming it did not reflect in the address group, which caused commits to fail.
|
||||
|
||||
## PAN-277617
|
||||
|
||||
@@ -978,7 +978,7 @@ Fixed an issue on Panorama where the logd process stopped responding unexpectedl
|
||||
|
||||
## PAN-276795
|
||||
|
||||
Fixed an issue where the GlobalProtect client displayed an error message when you clicked Check Now and Preferred Releases and Base Releases were unchecked (Device > Software).
|
||||
Fixed an issue where the GlobalProtect client displayed an error message when you clicked **Check Now** and **Preferred Releases** and **Base Releases** were unchecked (**Device > Software**).
|
||||
|
||||
## PAN-276694
|
||||
|
||||
@@ -1002,11 +1002,11 @@ Fixed an issue where Panorama stopped responding when running reports.
|
||||
|
||||
## PAN-276484
|
||||
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes.
|
||||
|
||||
## PAN-276412
|
||||
|
||||
Fixed an issue where you were unable to download XML files from Panorama > Summary > Backups.
|
||||
Fixed an issue where you were unable to download XML files from **Panorama > Summary > Backups**.
|
||||
|
||||
## PAN-276352
|
||||
|
||||
@@ -1014,15 +1014,15 @@ Fixed an issue where multicast flows were dropped due to a missing sysd variable
|
||||
|
||||
## PAN-276321
|
||||
|
||||
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as unknown, which prevented access to resources based on AD group membership.
|
||||
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as **unknown**, which prevented access to resources based on AD group membership.
|
||||
|
||||
## PAN-276144
|
||||
|
||||
Fixed an issue on the web interface where the Response Page action column was not accessible.
|
||||
Fixed an issue on the web interface where the **Response Page** **action** column was not accessible.
|
||||
|
||||
## PAN-276033
|
||||
|
||||
Fixed an issue on Panorama managed firewalls where SAML identity provider and Clientless Apps objects did not have override or revert options.
|
||||
Fixed an issue on Panorama managed firewalls where **SAML identity provider** and **Clientless Apps** objects did not have override or revert options.
|
||||
|
||||
## PAN-276000
|
||||
|
||||
@@ -1038,7 +1038,7 @@ Fixed an issue where the Log Collector service did not start on a new Log Collec
|
||||
|
||||
## PAN-275601
|
||||
|
||||
Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the Validate option, the upload failed with the error Failed to create multi-upload job. No valid software deploy targets found.
|
||||
Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the **Validate** option, the upload failed with the error **Failed to create multi-upload job. No valid software deploy targets found**.
|
||||
|
||||
## PAN-275451
|
||||
|
||||
@@ -1066,7 +1066,7 @@ Fixed an issue where you were unable to to adjust the frequency of the Advanced
|
||||
|
||||
## PAN-274907
|
||||
|
||||
Fixed an issue on Panorama where Config Audit Commit Date displayed the timestamp of the configuration edit instead of the commit time.
|
||||
Fixed an issue on Panorama where **Config Audit Commit Date** displayed the timestamp of the configuration edit instead of the commit time.
|
||||
|
||||
## PAN-274650
|
||||
|
||||
@@ -1106,11 +1106,11 @@ Fixed an issue on Panorama where the request batch license info CLI command disp
|
||||
|
||||
## PAN-274038
|
||||
|
||||
Fixed an issue where you were unable to use the s_encrypted field in custom reports for the Panorama threat log database.
|
||||
Fixed an issue where you were unable to use the **s_encrypted** field in custom reports for the Panorama threat log database.
|
||||
|
||||
## PAN-273991
|
||||
|
||||
Fixed an issue where the transmit power for a cable that was used on port 44 displayed as N/A.
|
||||
Fixed an issue where the transmit power for a cable that was used on port 44 displayed as **N/A**.
|
||||
|
||||
## PAN-273969
|
||||
|
||||
@@ -1134,7 +1134,7 @@ Fixed an issue where firewalls configured with a VPN tunnel stopped responding w
|
||||
|
||||
## PAN-273010
|
||||
|
||||
Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the Rule Changes field of the Security policy rule.
|
||||
Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the **Rule Changes** field of the Security policy rule.
|
||||
|
||||
## PAN-273008
|
||||
|
||||
@@ -1154,15 +1154,15 @@ Fixed an issue where you were unable to export the GlobalProtect client software
|
||||
|
||||
## PAN-272790
|
||||
|
||||
Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an scp export failed error. This was due to the system attempting to retrieve the file from an incorrect directory.
|
||||
Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an **scp export failed** error. This was due to the system attempting to retrieve the file from an incorrect directory.
|
||||
|
||||
## PAN-272743
|
||||
|
||||
Fixed an issue where non-captive portal traffic was not visible under Traffic Logs when the traffic was denied by an authentication rule and the session was discarded.
|
||||
Fixed an issue where non-captive portal traffic was not visible under **Traffic Logs** when the traffic was denied by an authentication rule and the session was discarded.
|
||||
|
||||
## PAN-272726
|
||||
|
||||
Fixed an issue on the web interface where the URL Filtering change category feature did not work.
|
||||
Fixed an issue on the web interface where the **URL Filtering** change category feature did not work.
|
||||
|
||||
## PAN-272505
|
||||
|
||||
@@ -1170,7 +1170,7 @@ Fixed an issue where GlobalProtect cookie authentication failed with the error U
|
||||
|
||||
## PAN-272469
|
||||
|
||||
Fixed an issue where the DNS exception displayed 0 instead of no result in the anti-spyware profile when no threat ID was available for a DNS Security category.
|
||||
Fixed an issue where the DNS exception displayed **0** instead of **no result** in the anti-spyware profile when no threat ID was available for a DNS Security category.
|
||||
|
||||
## PAN-272408
|
||||
|
||||
@@ -1222,7 +1222,7 @@ A CLI counter was added to indicate a full suppression queue.
|
||||
|
||||
## PAN-271412
|
||||
|
||||
Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as #43; on the GlobalProtect client after upgrading to a PAN-OS 10.2 release.
|
||||
Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as **#43;** on the GlobalProtect client after upgrading to a PAN-OS 10.2 release.
|
||||
|
||||
## PAN-271301
|
||||
|
||||
@@ -1242,7 +1242,7 @@ Fixed an issue where the firewall displayed an incorrect maximum translated IP c
|
||||
|
||||
## PAN-271061
|
||||
|
||||
Fixed an issue on the web interface where you were unable to add Threat IDs to Signature Exceptions.
|
||||
Fixed an issue on the web interface where you were unable to add Threat IDs to **Signature Exceptions**.
|
||||
|
||||
## PAN-270747
|
||||
|
||||
@@ -1266,11 +1266,11 @@ Fixed an issue threat reports were empty when generated from Panorama, but displ
|
||||
|
||||
## PAN-269843
|
||||
|
||||
Fixed an issue where the firewall dropped non-SYN TCP packets even when the Reject non-SYN TCP option was set to No when a session rematch was triggered.
|
||||
Fixed an issue where the firewall dropped non-SYN TCP packets even when the **Reject non-SYN TCP** option was set to **No** when a session rematch was triggered.
|
||||
|
||||
## PAN-269716
|
||||
|
||||
Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option toTrue.
|
||||
Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option to True.
|
||||
|
||||
## PAN-269659
|
||||
|
||||
@@ -1310,7 +1310,7 @@ Fixed an issue where the aggressive clean-up threshold for disk space was set to
|
||||
|
||||
## PAN-269176
|
||||
|
||||
Fixed an issue where the domain-edl column was empty in the threat log even when a threat was detected as a DNS alert.
|
||||
Fixed an issue where the **domain-edl** column was empty in the threat log even when a threat was detected as a DNS alert.
|
||||
|
||||
## PAN-269155
|
||||
|
||||
@@ -1342,7 +1342,7 @@ Fixed an issue where the configd process stopped responding when a configuration
|
||||
|
||||
## PAN-268606
|
||||
|
||||
Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking connect or login.
|
||||
Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking **connect** or **login**.
|
||||
|
||||
## PAN-268597
|
||||
|
||||
@@ -1354,7 +1354,7 @@ Fixed an issue where the web interface was slower than expected when logging in
|
||||
|
||||
## PAN-268522
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4.
|
||||
|
||||
## PAN-268426
|
||||
|
||||
@@ -1376,11 +1376,9 @@ Fixed an issue where importing a device configuration into Panorama failed with
|
||||
|
||||
To use this fix:
|
||||
|
||||
Enable the configuration. Commit failures may occur if the device is not able to support the number of objects.
|
||||
|
||||
Export and push the device group only.
|
||||
|
||||
Push the template.
|
||||
1. Enable the configuration. Commit failures may occur if the device is not able to support the number of objects.
|
||||
2. Export and push the device group only.
|
||||
3. Push the template.
|
||||
|
||||
Note: This fix is supported on PAN-OS 10.2 and later releases.
|
||||
|
||||
@@ -1390,7 +1388,7 @@ Fixed an issue where commits failed with a validation error when you changed the
|
||||
|
||||
## PAN-267912
|
||||
|
||||
Fixed an issue on the Panorama web interface where Application and Category was not able to be selected under Test Policy Match.
|
||||
Fixed an issue on the Panorama web interface where **Application** and **Category** was not able to be selected under **Test Policy Match**.
|
||||
|
||||
## PAN-267830
|
||||
|
||||
@@ -1406,7 +1404,7 @@ Fixed an issue where the Panorama web interface was slower than expected due to
|
||||
Firewalls in HA configuration only
|
||||
```
|
||||
|
||||
Fixed an issue where the Network pre-negotiation enabled page did not display on the firewall dashboard.
|
||||
Fixed an issue where the **Network pre-negotiation enabled** page did not display on the firewall dashboard.
|
||||
|
||||
## PAN-267381
|
||||
|
||||
@@ -1426,7 +1424,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where BGP route refreshes occurred when a commit was performed if AS Set was enabled for BGP aggregate routes.
|
||||
Fixed an issue where BGP route refreshes occurred when a commit was performed if **AS Set** was enabled for BGP aggregate routes.
|
||||
|
||||
## PAN-267045
|
||||
|
||||
@@ -1438,7 +1436,7 @@ Fixed an issue where the firewall generated AAAA DNS queries when IPv6 firewalli
|
||||
|
||||
## PAN-266905
|
||||
|
||||
Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a no-decrypt policy.
|
||||
Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a **no-decrypt** policy.
|
||||
|
||||
## PAN-266698
|
||||
|
||||
@@ -1506,7 +1504,7 @@ Fixed an issue where the routed process core failed the automation run.
|
||||
|
||||
## PAN-264040
|
||||
|
||||
Fixed an issue where AAAA DNS queries went out even when IPv6 firewalling was disabled.
|
||||
Fixed an issue where AAAA DNS queries went out even when **IPv6 firewalling** was disabled.
|
||||
|
||||
## PAN-263699
|
||||
|
||||
@@ -1558,7 +1556,7 @@ Fixed an issue where Voice over WiFi (VoWiFi) stopped working after switching fr
|
||||
|
||||
## PAN-261936
|
||||
|
||||
Fixed an issue where WildFire submission logs were not displayed when filtered by Sender Address.
|
||||
Fixed an issue where WildFire submission logs were not displayed when filtered by **Sender Address**.
|
||||
|
||||
## PAN-261602
|
||||
|
||||
@@ -1566,7 +1564,7 @@ Fixed an issue where GlobalProtect Decryption logs were not forwarded to Panoram
|
||||
|
||||
## PAN-260879
|
||||
|
||||
Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the Secure Communication Settings.
|
||||
Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the **Secure Communication Settings**.
|
||||
|
||||
## PAN-260790
|
||||
|
||||
@@ -1582,7 +1580,7 @@ Fixed an issue where daily email reports generated from the custom report did no
|
||||
|
||||
## PAN-260581
|
||||
|
||||
Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to None.
|
||||
Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to **None**.
|
||||
|
||||
## PAN-260540
|
||||
|
||||
@@ -1606,7 +1604,7 @@ Fixed an issue where the firewall dropped GRE keepalive packets that were encaps
|
||||
|
||||
## PAN-259343
|
||||
|
||||
Fixed an issue on the Panorama web interface where the Configuration tab did not accurately display changes made to URL filtering profiles.
|
||||
Fixed an issue on the Panorama web interface where the **Configuration** tab did not accurately display changes made to URL filtering profiles.
|
||||
|
||||
## PAN-259284
|
||||
|
||||
@@ -1638,7 +1636,7 @@ Fixed an issue where the firewall dataplane stopped responding, which caused BGP
|
||||
|
||||
## PAN-257616
|
||||
|
||||
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
||||
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message **Failed to generate selective push configuration. Schema validation failed. Please try a full push**.
|
||||
|
||||
## PAN-257362
|
||||
|
||||
@@ -1654,11 +1652,11 @@ Fixed an issue where the mp-monitor logs did not print disk SMART data.
|
||||
|
||||
## PAN-257074
|
||||
|
||||
Fixed an issue on the Panorama web interface where the template sync status showed Out-of-Sync for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum.
|
||||
Fixed an issue on the Panorama web interface where the template sync status showed **Out-of-Sync** for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum.
|
||||
|
||||
## PAN-256560
|
||||
|
||||
Fixed an issue where exporting a Custom Report to CSV format did not display the full report if it contained non-ASCII characters.
|
||||
Fixed an issue where exporting a **Custom Report** to CSV format did not display the full report if it contained non-ASCII characters.
|
||||
|
||||
## PAN-256552
|
||||
|
||||
@@ -1746,7 +1744,7 @@ Fixed an issue where the class of service (CoS) priority bit was not modified, c
|
||||
|
||||
## PAN-252706
|
||||
|
||||
Fixed an issue where the URL filtering response page for Continue and Override did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
|
||||
Fixed an issue where the URL filtering response page for **Continue** and **Override** did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
|
||||
|
||||
## PAN-252699
|
||||
|
||||
@@ -1786,17 +1784,17 @@ Fixed an issue on the Panorama web interface where you were unable to add static
|
||||
|
||||
## PAN-242777
|
||||
|
||||
Fixed and issue where users previously reported limitations due to session count caps when utilizing Web Proxy features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific PA-5400F series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
|
||||
Fixed and issue where users previously reported limitations due to session count caps when utilizing **Web Proxy** features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific **PA-5400F** series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
|
||||
|
||||
The supported session limits are:
|
||||
|
||||
| Platform | Max Sessions |
|
||||
| --- | --- |
|
||||
| PA-5410 | 95K |
|
||||
| PA-5420 | 95K |
|
||||
| PA-5430 | 95K |
|
||||
| PA-5440 | 225K |
|
||||
| PA-5445 | 250K |
|
||||
| -------- | ------------ |
|
||||
| PA-5410 | 95K |
|
||||
| PA-5420 | 95K |
|
||||
| PA-5430 | 95K |
|
||||
| PA-5440 | 225K |
|
||||
| PA-5445 | 250K |
|
||||
|
||||
## PAN-241953
|
||||
|
||||
@@ -1812,7 +1810,7 @@ Fixed an issue where the SNMP get request status value for Panorama connections
|
||||
|
||||
## PAN-238208
|
||||
|
||||
Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error Session is invalid if the session is not available for the cookie.
|
||||
Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error **Session is invalid** if the session is not available for the cookie.
|
||||
|
||||
## PAN-234993
|
||||
|
||||
|
||||
Reference in New Issue
Block a user