From 774345dee30d6ee94b768c6df65cb4cf23d0b9d2 Mon Sep 17 00:00:00 2001 From: Aaron Axvig Date: Tue, 14 Apr 2026 16:50:33 -0500 Subject: [PATCH] Add PAN-OS 11.1 known issue reference files --- reference/PAN-OS/known/11.1.0.html | 1648 +++++++++++++++++++ reference/PAN-OS/known/11.1.1.html | 1631 ++++++++++++++++++ reference/PAN-OS/known/11.1.10.html | 1624 ++++++++++++++++++ reference/PAN-OS/known/11.1.11.html | 1148 +++++++++++++ reference/PAN-OS/known/11.1.12.html | 1131 +++++++++++++ reference/PAN-OS/known/11.1.13.html | 975 +++++++++++ reference/PAN-OS/known/11.1.2.html | 1524 +++++++++++++++++ reference/PAN-OS/known/11.1.3.html | 1881 +++++++++++++++++++++ reference/PAN-OS/known/11.1.4.html | 2360 +++++++++++++++++++++++++++ reference/PAN-OS/known/11.1.5.html | 1452 ++++++++++++++++ reference/PAN-OS/known/11.1.6.html | 2230 +++++++++++++++++++++++++ reference/PAN-OS/known/11.1.7.html | 1757 ++++++++++++++++++++ reference/PAN-OS/known/11.1.8.html | 1585 ++++++++++++++++++ reference/PAN-OS/known/11.1.9.html | 1436 ++++++++++++++++ 14 files changed, 22382 insertions(+) create mode 100644 reference/PAN-OS/known/11.1.0.html create mode 100644 reference/PAN-OS/known/11.1.1.html create mode 100644 reference/PAN-OS/known/11.1.10.html create mode 100644 reference/PAN-OS/known/11.1.11.html create mode 100644 reference/PAN-OS/known/11.1.12.html create mode 100644 reference/PAN-OS/known/11.1.13.html create mode 100644 reference/PAN-OS/known/11.1.2.html create mode 100644 reference/PAN-OS/known/11.1.3.html create mode 100644 reference/PAN-OS/known/11.1.4.html create mode 100644 reference/PAN-OS/known/11.1.5.html create mode 100644 reference/PAN-OS/known/11.1.6.html create mode 100644 reference/PAN-OS/known/11.1.7.html create mode 100644 reference/PAN-OS/known/11.1.8.html create mode 100644 reference/PAN-OS/known/11.1.9.html diff --git a/reference/PAN-OS/known/11.1.0.html b/reference/PAN-OS/known/11.1.0.html new file mode 100644 index 0000000..2f496b9 --- /dev/null +++ b/reference/PAN-OS/known/11.1.0.html @@ -0,0 +1,1648 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-298505
+ +
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues. +
+
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-291288
+
+ An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. +
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-286231
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-280471
+
+
+ When applying filters or searching for logs in the + PanoramaMonitorLogs + section, you might experience slow performance. +
+
+
PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277034
+ +
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues +
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1 + or a later release, Panorama fails to upgrade if it is operating + within a Collector Group. The following error appears:Error: Traceback (most recent call last):File + "/opt/panrepo/releases/<PANOS release version>/validate"... + (min ([dts['min'] for dts in 10g_type_intv_dir.values() if + dts|'min']])-strftime ('%Y-%m-%d'), +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1.0. +
+
+
PAN-262287
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-262263
+
+
+ (PA-1400, PA-3400, and PA-5400 Series firewalls) The links on the firewall's RJ-45 ports may go up and down + additional times during a reboot, causing unexpected downtime. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.1.2-h9 Addressed Issues. +
+
+
+ The Panorama web interface intermittently displays logs or fails to + display logs completely. +
+
+
PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues. +
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+ This issue is now resolved. See PAN-OS 11.1.2-h3 Addressed Issues +
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-242910
+
+
+ On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled are + unable to push configuration changes to managed firewalls when + Managed Devices and + Push For Other Admins are disabled. +
+
+
PAN-242561
+
+
+ GlobalProtect tunnel might disconnect shortly after being established + when SSL is used as a transport protocol. +
+
+ Workaround: Disable Internet Protocol version 6 + (TCP/IPv6) on the PANGP Virtual Network Adapter. +
+
+
PAN-241041
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues +
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues +
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234408
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for + ChatGPT from traffic forwarded to the DLP cloud service from an NGFW. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-229081
+
+
+ (PA-7500 firewalls only) The CLI commands + show logging-status and + show logging-status verbose yes do + not display aggregate log forwarding statistics on the Management + Plane. +
+
+
PAN-228491
+
+
+ On the AWS environment, the session failover takes up to 4 minutes. +
+
+
PAN-225337
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-222805
+
+
+ (PA-7500 firewall only) The CLI command + show running resource-monitor ingress-backlogs + does not display the correct usage values. +
+
+
PAN-220577
+
+
+ With firewalls in AWS environment that are licensed with VM capacity + and secure web proxy licenses, it is observed that the enablement of + the web-proxy config fails. +
+
+ Workaround: Reboot the firewall after the web + proxy license is applied. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-208794
+
+
+ In firewalls with transparent proxy, it is observed that a reboot is + necessary to view the transit sessions. +
+
+ Workaround: Edit the virtual router settings with + any minor change and commit again. Any changes to the + network/interfaces or network/virtual routers usually fixes this + issue. +
+
+ Alternatively, you may try rebooting the firewall. This issue + disappears following reboot after the + swg is setup and configured. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.1.1.html b/reference/PAN-OS/known/11.1.1.html new file mode 100644 index 0000000..03b2a6c --- /dev/null +++ b/reference/PAN-OS/known/11.1.1.html @@ -0,0 +1,1631 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-298505
+ +
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues. +
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-291288
+
+ An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. +
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-280471
+
+
+ When applying filters or searching for logs in the + PanoramaMonitorLogssection, you might experience slow performance. +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-278296
+
+
+ The system MAC address of the aggregate interface is the same on both + the active and the passive devices, causing some packets to be sent + incorrectly to the passive device. This is causing the AE interface on + the active firewall to not come up. +
+
+
PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277034
+ +
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues +
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1 + or a later release, Panorama fails to upgrade if it is operating + within a Collector Group. The following error appears:Error: Traceback (most recent call last):File + "/opt/panrepo/releases/<PANOS release version>/validate"... + (min ([dts['min'] for dts in 10g_type_intv_dir.values() if + dts|'min']])-strftime ('%Y-%m-%d'), +
+
+
PAN-263987
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is + terminated on a Palo Alto Networks firewall and the NAT rule applied + to the NAT-T IPSec tunnel is also on the same firewall, then the data + traffic flowing through the NAT-T IPSec tunnel can't be NATed + correctly. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1.1. +
+
+
PAN-262287
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues. +
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.1.2-h9 Addressed Issues. +
+
+
+ The Panorama web interface intermittently displays logs or fails to + display logs completely. +
+
+
PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+ This issue is now resolved. See PAN-OS 11.1.2-h3 Addressed Issues +
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-242910
+
+
+ On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled are + unable to push configuration changes to managed firewalls when + Managed Devices and + Push For Other Admins are disabled. +
+
+
PAN-242837
+
+
+ Default login credentials and SSH fail after enabling FIPS-CC Mode on + a firewall or Panorama after converting through the Maintenance + Recovery Tool (MRT). The firewall or Panorama becomes stuck and + requires a factory reset to recover. +
+
+
PAN-242561
+
+
+ GlobalProtect tunnel might disconnect shortly after being established + when SSL is used as a transport protocol. +
+
+ Workaround: Disable Internet Protocol version 6 + (TCP/IPv6) on the PANGP Virtual Network Adapter. +
+
+
PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues +
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-238769
+
+
+ FIPS-CC VM only. Upgrading to 10.1.10-h2 or 10.1.11 will change all + locally created security Policy actions to Deny. Re-load the back-up + config taken before upgrading or the last version to get the previous + config back. Also, Unable to login to FIPSCC Mode devices with default + credentials after converting the mode for 10.1.12 release , 10.2.7 + release , 11.1.0 , 11.1.1, 11.0.3 versions. +
+
+
PAN-241041
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues +
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-225337
+
+ This issue is now resolved. See PAN-OS 11.1.2 Addressed Issues +
+
+
+ On the Panorama management server, the configuration push to a + multi-vsys firewall fails if you: +
+
    +
  1. +
    + Create a Shared and + vsys-specific device group configuration object with an indentical + name. For example, a + Shared address object called + SharedAO1 and a vsys-specific + address object also called + SharedAO1. +
    +
  2. +
  3. +
    + Reference the Shared object in + another Shared configuration. + For example, reference the + Shared address object (SharedAO1) in a Shared address group + called SharedAG1. +
    +
  4. +
  5. +
    + Use the Shared configuration + object with the reference in a vsys-specific configuration. For + example, reference the + Shared address group (SharedAG1) in a vsys-specific policy rule. +
    +
  6. +
+
+ Workaround: Select + PanoramaSetupManagement + and edit the Panorama Settings to enable one of the following: +
+
    +
  • +
    + Shared Unused Address and Service Objects with Devices—This options pushes all + Shared objects, along with + device group specific objects, to managed firewalls. +
    +
    + This is a global setting and applies to all managed firewalls, and + may result in pushing too many configuration objects to your + managed firewalls. +
    +
  • +
  • +
    + Objects defined in ancestors will take higher precedence—This option specifies that in the event of objects with the same + name, ancestor object take precedence over descendent objects. In + this case, the Shared objects + take precedence over the vsys-specific object. +
    +
    + This is a global setting and applies to all managed firewalls. In + the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device group + specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. +
    +
  • +
+
+ Alternatively, you can remove the duplicate address objects from the + device group configuration to allow only the + Shared objects in your + configuration. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.1.10.html b/reference/PAN-OS/known/11.1.10.html new file mode 100644 index 0000000..1839bc2 --- /dev/null +++ b/reference/PAN-OS/known/11.1.10.html @@ -0,0 +1,1624 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
+ PAN-307795 This issue affects PAN-OS 11.1.10-h7 through 11.1.10-h11. +
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h12 Addressed Issues. +
+
+
+ On a standalone Panorama, the system incorrectly generates system logs + indicating a lost connection to its peer even when High Availability + is not configured. You can safely ignore these logs, as they do not + affect operations. +
+
+
PAN-306502
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h10 Addressed Issues. +
+
+
+ TLS sessions using version 1.2 or earlier may fail when session + traffic matches a decryption policy rule with the no-decrypt action + under either of the following conditions: +
+
+ +
+
+ If both of these conditions are met, the session is guaranteed to + fail. +
+
+
+
    +
  • +
    + Both HTTP header insertion (ObjectsSecurity ProfilesURL FilteringHTTP Header Insertion) and SSL/TLS handshake inspection (DeviceSetupSessionDecryption SettingsSSL Decryption Settings) are enabled. +
    +
  • +
  • +
    + Log Successful SSL Handshake + is not enabled in the decryption policy rule and neither + Block sessions with expired certificates + nor + Block sessions with untrusted issuers + is enabled in the attached decryption profile. +
    +
  • +
+
+ Workaround: Perform one of the following tasks: +
+
    +
  • +
    + Enable + Log Successful SSL Handshake in + all no-decrypt decryption policy rules. +
    +
  • +
  • + Enable either + Block sessions with expired certificates + or + Block sessions with untrusted issuers + in the decryption profiles attached to the no-decrypt decryption + policy rules. +
  • +
+
+
PAN-305301
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h12 Addressed Issues. +
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout + notifications used for GlobalProtect SSL tunnels may cause the + pan_task + process to stop responding and the dataplane to restart. +
+
+ Workaround: Select + Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings + and change the value of both + Notify Before Lifetime Expires (min) + and + Notify Before Inactivity Logout (min) + to 0. +
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-304576
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-303051
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues +
+
+ The reportd process experiences a + memory leak because it retains memory that was temporarily used for + report generation. Once a task is complete, the process fails to + release this memory for reuse, leading to continuous accumulation and + eventual memory exhaustion on the Panorama device. +
+
+
PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.1.10-h7 Addressed Issuesand + PAN-OS 11.1.12 Addressed Issues +
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.1.13 Addressed Issues +
+
+ (VM-Series firewalls on Microsoft Azure environments only) +
+ After upgrading to an affected release, the firewall restarts + continuously because the + brdagent process restarts multiple + times and exhausts its restart limit, resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-296977
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When you apply a filter in + Network > Interfaces and then try + to view Ethernet interface details + using the web interface, the web interface becomes unresponsive. +
+
+
PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues. +
+
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+ When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. +
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due + to log overflow` due to the SNMP counters rolling over. This is a + benign message and does not impact device functionality. +
+
+
PAN-289432
+
+
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues + and + PAN-OS 11.1.11 Addressed Issues. +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues. +
+
+
+ The + dscd + process crashes continuously on MIPS platforms (for example, PA-850 + firewalls) due to a runtime error related to an invalid memory address + or nil pointer dereference. This occurs when the golang library + upgrade in CIE is not compatible with the MIPS platform. +
+
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues + and + PAN-OS 11.1.11 Addressed Issues. +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues + and + PAN-OS 11.1.11 Addressed Issues. +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-282854
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log + collectors in a multi-collector environment. +
+ Workaround: Restart all the involved log collectors. +
+
PAN-279901
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+ To enable this fix, run the CLI command + bug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues +
+
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-276920
+
+
+ URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-251551
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
+
+
PAN-250903
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
+
+
PAN-247974
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.1.11.html b/reference/PAN-OS/known/11.1.11.html new file mode 100644 index 0000000..aaa9ae3 --- /dev/null +++ b/reference/PAN-OS/known/11.1.11.html @@ -0,0 +1,1148 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
PAN-307795
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ On a standalone Panorama, the system incorrectly generates system logs + indicating a lost connection to its peer even when High Availability + is not configured. You can safely ignore these logs, as they do not + affect operations. +
+
+
PAN-306502
+
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues. +
+
+
+ TLS sessions using version 1.2 or earlier may fail when session + traffic matches a decryption policy rule with the no-decrypt action + under either of the following conditions: +
+
+ +
+
+ If both of these conditions are met, the session is guaranteed to + fail. +
+
+
+
    +
  • +
    + Both HTTP header insertion (ObjectsSecurity ProfilesURL FilteringHTTP Header Insertion) and SSL/TLS handshake inspection (DeviceSetupSessionDecryption SettingsSSL Decryption Settings) are enabled. +
    +
  • +
  • +
    + Log Successful SSL Handshake + is not enabled in the decryption policy rule and neither + Block sessions with expired certificates + nor + Block sessions with untrusted issuers + is enabled in the attached decryption profile. +
    +
  • +
+
+ Workaround: Perform one of the following tasks: +
+
    +
  • +
    + Enable + Log Successful SSL Handshake in + all no-decrypt decryption policy rules. +
    +
  • +
  • + Enable either + Block sessions with expired certificates + or + Block sessions with untrusted issuers + in the decryption profiles attached to the no-decrypt decryption + policy rules. +
  • +
+
+
PAN-305301
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout + notifications used for GlobalProtect SSL tunnels may cause the + pan_task + process to stop responding and the dataplane to restart. +
+
+ Workaround: Select + Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings + and change the value of both + Notify Before Lifetime Expires (min) + and + Notify Before Inactivity Logout (min) + to 0. +
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-304576
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-303051
+
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues. +
+
+
+ The reportd process experiences a + memory leak because it retains memory that was temporarily used for + report generation. Once a task is complete, the process fails to + release this memory for reuse, leading to continuous accumulation and + eventual memory exhaustion on the Panorama device. +
+
+
PAN-298505
+
+ This issue is now resolved. See + PAN-OS 11.1.12 Addressed Issues +
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.1.13 Addressed Issues +
+
+ (VM-Series firewalls on Microsoft Azure environments only) +
+ After upgrading to an affected release, the firewall restarts + continuously because the + brdagent process restarts multiple + times and exhausts its restart limit, resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert + Clearing snmpd.log due to log overflow + due to the SNMP counters rolling over. This is a benign message and + does not impact device functionality. +
+
+
PAN-289432
+
+
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-276920
+
+
+ URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-251551
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
+
+
PAN-250903
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
+
+
PAN-247974
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.1.12.html b/reference/PAN-OS/known/11.1.12.html new file mode 100644 index 0000000..494d248 --- /dev/null +++ b/reference/PAN-OS/known/11.1.12.html @@ -0,0 +1,1131 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
PAN-307795
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ On a standalone Panorama, the system incorrectly generates system logs + indicating a lost connection to its peer even when High Availability + is not configured. You can safely ignore these logs, as they do not + affect operations. +
+
+
PAN-306502
+
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues. +
+
+
+ TLS sessions using version 1.2 or earlier may fail when session + traffic matches a decryption policy rule with the no-decrypt action + under either of the following conditions: +
+
+ +
+
+ If both of these conditions are met, the session is guaranteed to + fail. +
+
+
+
    +
  • +
    + Both HTTP header insertion (ObjectsSecurity ProfilesURL FilteringHTTP Header Insertion) and SSL/TLS handshake inspection (DeviceSetupSessionDecryption SettingsSSL Decryption Settings) are enabled. +
    +
  • +
  • +
    + Log Successful SSL Handshake + is not enabled in the decryption policy rule and neither + Block sessions with expired certificates + nor + Block sessions with untrusted issuers + is enabled in the attached decryption profile. +
    +
  • +
+
+ Workaround: Perform one of the following tasks: +
+
    +
  • +
    + Enable + Log Successful SSL Handshake in + all no-decrypt decryption policy rules. +
    +
  • +
  • + Enable either + Block sessions with expired certificates + or + Block sessions with untrusted issuers + in the decryption profiles attached to the no-decrypt decryption + policy rules. +
  • +
+
+
PAN-305301
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout + notifications used for GlobalProtect SSL tunnels may cause the + pan_task + process to stop responding and the dataplane to restart. +
+
+ Workaround: Select + Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings + and change the value of both + Notify Before Lifetime Expires (min) + and + Notify Before Inactivity Logout (min) + to 0. +
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-304576
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-303051
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues +
+
+ The reportd process experiences a + memory leak because it retains memory that was temporarily used for + report generation. Once a task is complete, the process fails to + release this memory for reuse, leading to continuous accumulation and + eventual memory exhaustion on the Panorama device. +
+
+
PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.1.13 Addressed Issues +
+
+ (VM-Series firewalls on Microsoft Azure environments only) +
+ After upgrading to an affected release, the firewall restarts + continuously because the + brdagent process restarts multiple + times and exhausts its restart limit, resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: +
    +
  • D3_v2/DS3_v2 to D8ds_v5
  • +
  • D4_v2/DS4_v2 to D8ds_v5
  • +
  • D5_v2/DS5_v2 to D16ds_v5
  • +
+
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert + Clearing snmpd.log due to log overflow + due to the SNMP counters rolling over. This is a benign message and + does not impact device functionality. +
+
+
PAN-289432
+
+
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-279415
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-276920
+
+
+ URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-251551
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
+
+
PAN-250903
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
+
+
PAN-247974
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.1.13.html b/reference/PAN-OS/known/11.1.13.html new file mode 100644 index 0000000..c46f603 --- /dev/null +++ b/reference/PAN-OS/known/11.1.13.html @@ -0,0 +1,975 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
PAN-307795
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ On a standalone Panorama, the system incorrectly generates system logs + indicating a lost connection to its peer even when High Availability + is not configured. You can safely ignore these logs, as they do not + affect operations. +
+
+
PAN-305301
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout + notifications used for GlobalProtect SSL tunnels may cause the + pan_task + process to stop responding and the dataplane to restart. +
+
+ Workaround: Select + Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings + and change the value of both + Notify Before Lifetime Expires (min) + and + Notify Before Inactivity Logout (min) + to 0. +
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-304576
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command. +
+
+
PAN-303959
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue. +
+
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert + Clearing snmpd.log due to log overflow + due to the SNMP counters rolling over. This is a benign message and + does not impact device functionality. +
+
+
PAN-289432
+
+
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-279415
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-276920
+
+
+ URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-273158
+
+
+ (PA-7000 Series firewalls only) Due to an + incorrect configuration on the ASIC, receiving a mix of jumbo and + non-jumbo packets may cause silent packet drops or application + slowness. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-251551
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
+
+
PAN-250903
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
+
+
PAN-247974
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.1.2.html b/reference/PAN-OS/known/11.1.2.html new file mode 100644 index 0000000..40dc786 --- /dev/null +++ b/reference/PAN-OS/known/11.1.2.html @@ -0,0 +1,1524 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-298505
+ +
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues. +
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-291288
+
+ An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. +
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+ This issue affects PAN-OS 11.1.2-h9 +
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-280471
+
+
+ When applying filters or searching for logs in the + PanoramaMonitorLogssection, you might experience slow performance. +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-278296
+
+
+ The system MAC address of the aggregate interface is the same on both + the active and the passive devices, causing some packets to be sent + incorrectly to the passive device. This is causing the AE interface on + the active firewall to not come up. +
+
+
PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277034
+ +
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues +
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1 + or a later release, Panorama fails to upgrade if it is operating + within a Collector Group. The following error appears:Error: Traceback (most recent call last):File + "/opt/panrepo/releases/<PANOS release version>/validate"... + (min ([dts['min'] for dts in 10g_type_intv_dir.values() if + dts|'min']])-strftime ('%Y-%m-%d'), +
+
+
PAN-263987
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is + terminated on a Palo Alto Networks firewall and the NAT rule applied + to the NAT-T IPSec tunnel is also on the same firewall, then the data + traffic flowing through the NAT-T IPSec tunnel can't be NATed + correctly. +
+
+
PAN-263208
+
+ This issue is now resolved. See PAN-OS 11.1.2-h16 Addressed Issues. +
+
+
+ (PA-5440 and PA-5445 firewalls only) High + system load can cause the firewall to generate interrupts and trigger + dataplane crashes. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1.2. +
+
+
PAN-262287
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues. +
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.1.2-h9 Addressed Issues. +
+
+
+ The Panorama web interface intermittently displays logs or fails to + display logs completely. +
+
+
PAN-255538
+
+
+ On the PA-455 firewall, the LEDs indicating the link status of Ports 3 + and 4 are swapped. +
+
+
PAN-252085
+
+
+ The PA-450R, PA-450R-5G, and PA-455 firewalls can experience an + interruption of traffic when switching the combo port connection from + fiber to copper. +
+
+ Workaround: With the copper port connected, + initiate a soft reboot of the firewall using the CLI command + request restart system. After the + reboot, the copper port will be able to process traffic. +
+
+
PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-243951
+
+ This issue is now resolved. See PAN-OS 11.1.2-h3 Addressed Issues +
+
+
+ On the Panorama management sever in an active/passive High + Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync on the + passive HA peer when configuration changes are made to the SD-WAN + (PanoramaSD-WAN) configuration on the active HA peer. +
+
+ Workaround: Manually synchronize the Panorama HA + peers. +
+
    +
  1. +
    + Log in to the + Panorama web interface + on the active HA peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama the SD-WAN + configuration changes on the active HA peer. +
    +
    + On the passive HA peer, select + PanoramaManaged DevicesSummary + and observe that the managed devices are now + out-of-sync. +
    +
  4. +
  5. +
    + Log in to the primary HA peer + Panorama CLI + and trigger a manual synchronization between the active and + secondary HA peers. +
    +
    + request high-availability sync-to-remote running-config +
    +
  6. +
  7. +
    + Log back in to the active HA peer Panorama web interface and + select + CommitPush to Devices + and Push. +
    +
  8. +
+
+
PAN-241041
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues +
+
+
+ On the Panorama management server exporting template or template stack + variables (PanoramaTemplates) in CSV format results in an empty CSV file. +
+
+
PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues +
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-217307
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues. +
+
+
+ The following Security policy rule (PoliciesSecurity) filters return no results: +
+
+ log-start eq no +
+
log-end eq no
+
log-end eq yes
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.1.3.html b/reference/PAN-OS/known/11.1.3.html new file mode 100644 index 0000000..8206569 --- /dev/null +++ b/reference/PAN-OS/known/11.1.3.html @@ -0,0 +1,1881 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-298505
+ +
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues. +
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-291288
+
+ An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. +
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+ This issue affects PAN-OS 11.1.3-h2 +
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-280471
+
+
+ When applying filters or searching for logs in the + PanoramaMonitorLogssection, you might experience slow performance. +
+
+
PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Early aging and removal of firewall session while they are still + active can lead to intermittent instabilities and crashes for proxy + traffic, the Content and Threat detection engine, and any data-path + processing. +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-278296
+
+
+ The system MAC address of the aggregate interface is the same on both + the active and the passive devices, causing some packets to be sent + incorrectly to the passive device. This is causing the AE interface on + the active firewall to not come up. +
+
+
PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277034
+ +
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues +
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1 + or a later release, Panorama fails to upgrade if it is operating + within a Collector Group. The following error appears:Error: Traceback (most recent call last):File + "/opt/panrepo/releases/<PANOS release version>/validate"... + (min ([dts['min'] for dts in 10g_type_intv_dir.values() if + dts|'min']])-strftime ('%Y-%m-%d'), +
+
+
PAN-265336
+
(PAN-OS 11.1.3-h6 only)
+
+
+ Copper ports flap when generating a technical support file, executing + telemetry, or retrieving port status using a Management Data + Input/Output (MDIO) read. +
+
+
PAN-263987
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is + terminated on a Palo Alto Networks firewall and the NAT rule applied + to the NAT-T IPSec tunnel is also on the same firewall, then the data + traffic flowing through the NAT-T IPSec tunnel can't be NATed + correctly. +
+
+
PAN-263940
+
+
+ On a PA-7500 Series firewall node in an NGFW cluster, if the data + processing card is in slot 6, packet drops are expected. +
+
+
PAN-262287
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+ PAN-259769 +
+ This issue is now resolved. See PAN-OS 11.1.3-h6 Addressed Issues +
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-259733
+
+ This issue is now resolved. See PAN-OS 11.1.3-h2 Addressed Issues. +
+
+
+ Custom reports created in PAN-OS are not deleted as expected, + resulting in high memory use by the + reportd + process. This can lead to issues, such as out-of-memory conditions, + content installation failures, and unexpected firewall reboots. +
+
+
PAN-257615
+
+ This issue is now resolved. See + PAN-OS 11.1.3-h4 Addressed Issues. +
+
+
+ The Panorama web interface intermittently displays logs or fails to + display logs completely. +
+
+
PAN-255868
+
+ This issue is now resolved. See PAN-OS 11.1.3-h1 Addressed Issues. +
+
+
+ (PA-3400 Series firewalls only) After enabling + kernel data collection during a silent reboot, the firewall fails and + reboots to maintenance mode. +
+
+ Workaround: To recover the firewall, initiate a + reboot from maintenance mode. +
+
+
PAN-255579
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues. +
+
+
+ Demo Mode and Log Forwarding: PA-7500 Series firewalls and Panorama + display data plane logs after a delay. +
+
+
PAN-255285
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues. +
+
+
+ If only the HCSI-A link is connected on NGFW cluster nodes (the HSCI-B + link is not connected) and the management interfaces goes down, the + situation will result in a split brain. +
+
+
PAN-255116
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ When QoS is applied, traffic on an NGFW cluster node going from an + MC-LAG interface to a destination stops when a member of the MC-LAG + goes down. +
+
+
PAN-254927
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ Certain types of data packets sent to threat inspection processing on + the Networking cards of PA-7500 Series firewalls cause a pan_task + crash. +
+
+
PAN-254827
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ When you change an IP address on a management interface on any of the + NGFW cluster nodes, there's no workflow in cluster-config to detect + this change, so the subsequent commit-all will not push the updated + management IP address. +
+
+ Workaround: You must manually make an unrelated + change to cluster-config in order for Panorama to detect this change; + the subsequent commit-all will push the cluster-config with the + updated management IP address to cluster-manager. +
+
+
PAN-254351
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ An NGFW cluster node could get stuck in suspended state in some cases + when you use GRE tunnel termination with keepalive enabled on both + ends. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-253466
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ In the event of a cluster manager restart on the leader node of an + NGFW cluster, traffic stops because the state machine transitions to + unknown and the leader is not changing. +
+
+
PAN-253466
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On an NGFW cluster node, an expected packet buffer leak occurs with + FTP/SIP traffic over an extended period of time. +
+
+
PAN-252358
+
+
+ (PA-7500 Series firewalls only) In the event of + a corosync restart, an NGFW cluster node goes to failed state. +
+
+
PAN-251639
+
+ This issue is now resolved. See PAN-OS 11.1.4 Addressed Issues. +
+
+
+ When a Wildfire Analysis security profile is enabled, an out of memory + condition might occur due to a memory leak in the + varrcvr process. +
+
+
PAN-251551
+
+
+ (PA-7500 Series firewalls only) When an NGFW + cluster agent crashes and doesn't recover, leader election will take + approximately 45 seconds to begin and traffic failover will occur + during that time. +
+
+
PAN-251501
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ Upon a reboot, an NGFW cluster node will occasionally fail to rejoin a + cluster due to a timing issue. +
+
+
PAN-250903
+
+
+ (PA-7500 Series firewalls only) In a congestion + scenario on an HSCI port of an NGFW cluster node, the QoS priorities + of cross node traffic streams might be reversed if you're using the + default QoS profile with class1 to class8 set as high to low. +
+
+
PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-250043
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On an NGFW cluster node, if you configure a QoS interface with an + Egress Max (Mbps) that exceeds 68000, the operation will fail with a + message indicating "...is not a valid reference.…" The QoS Max + bandwidth on any interface cannot be configured to be more than 68000. +
+
+
PAN-249727
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On an NGFW cluster node, the Custom/Pre-defined URL category is not + part of the session flow data and a promoted session after failover + does not include it. +
+
+
PAN-248762
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ A firewall using the Advanced Routing Engine configured with OSPF + crashes when connecting to the neighbor while exchanging route maps. +
+
+
PAN-247974
+
+
+ (PA-7500 Series firewalls only) LACP flap is + expected during a device failover in an NGFW cluster due to an L2 + ctrld restart on the new leader node. +
+
+
PAN-240529
+
+ This issue is now resolved. See + PAN-OS 11.1.7 Addressed Issues +
+
+
+ (PA-7500 Series firewalls only) Cloud + application information is missing from traffic logs on NGFW cluster + nodes. +
+
+
PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues +
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-227978
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ The UI widget does not accurately list the status of the port when + NGFW clustering is enabled. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.1.4.html b/reference/PAN-OS/known/11.1.4.html new file mode 100644 index 0000000..56d89a0 --- /dev/null +++ b/reference/PAN-OS/known/11.1.4.html @@ -0,0 +1,2360 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-298505
+ +
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues. +
+
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+ When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. +
+
PAN-291288
+
+ An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. +
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+ This issue affects PAN-OS 11.1.4-h4 +
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-286255
+
+ This issue affects PAN-OS 11.1.4-h15 +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions , NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+
PAN-286255
+
+ This issue affects PAN-OS 11.1.7-h2 +
+
+ This issue is now resolved. See PAN-OS 11.1.6-h7 Addressed Issues. +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions , NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-285587
+
+ This issue affects PAN-OS 11.1.4-h13. +
+
+
+ Bootstrapping the VM-Series firewall on OpenStack with user-data does + not function correctly. When you run the command show + system bootstrap status shows, the + output shows the message + No Install media detected. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-280471
+
+
+ When applying filters or searching for logs in the + PanoramaMonitorLogssection, you might experience slow performance. +
+
+
PAN-279746
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ This issue is now resolved. See + PAN-OS 11.1.4-h15 Addressed Issues. +
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if + the Client Hello arrives in multiple TCP segments and the traffic is + not subject to SSL decryption (for example, SMTP over SSL). +
+
+
PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Early aging and removal of firewall session while they are still + active can lead to intermittent instabilities and crashes for proxy + traffic, the Content and Threat detection engine, and any data-path + processing. +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-278296
+
+
+ The system MAC address of the aggregate interface is the same on both + the active and the passive devices, causing some packets to be sent + incorrectly to the passive device. This is causing the AE interface on + the active firewall to not come up. +
+
+
PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277034
+ +
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-275905
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ A high volume of incoming logs to a Collector Group can significantly + increase CPU usage on the Elasticsearch and Management Server, + potentially causing process instability or crashes. +
+
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-274791
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ This issue is now resolved. See + PAN-OS 11.1.6-h3 Addressed Issues. +
+
+
+ The firewall might reboot when traffic matches with certain Advanced + features (such as Advanced Threat Prevention and Advanced URL + Filtering with properly configured URL + Filtering/Anti-Spyware/Vulnerability security profiles) and Shared + Pool Type 32 becomes depleted. +
+
+
PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues +
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1 + or a later release, Panorama fails to upgrade if it is operating + within a Collector Group. The following error appears:Error: Traceback (most recent call last):File + "/opt/panrepo/releases/<PANOS release version>/validate"... + (min ([dts['min'] for dts in 10g_type_intv_dir.values() if + dts|'min']])-strftime ('%Y-%m-%d'), +
+
+ PAN-272085 +
+ (This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.) +
+
+
+ When DoH is enabled for DNS Security, multiple DoH transactions in a + single HTTP/1 connection might unexpectedly cause the firewall to + crash and reboot. +
+
+ Workaround: Manually disable DoH support for DNS + Security using the + set deviceconfig setting dns-over-https enable no + CLI command. Alternatively, you can remove the DNS Security + configuration used to handle DoH traffic. +
+
+
PAN-270549
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ This issue is now resolved. See + PAN-OS 11.1.6-h1 Addressed Issues. +
+
+
+ Some TLS connections are not handled correctly leading to an + instability in the dataplane of PAN-OS. +
+
+ PAN-270224 +
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ This issue is now resolved. See PAN-OS 11.1.4-h9 Addressed Issues. +
+
+
+ When querying for logs in the + Monitor tab in Panorama, some + forwarded logs might be missing from the results. +
+
+
PAN-269106
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues. +
+
+
+ When using a cloud-based ML detection engine (MICA), the + wifclient might crash during + server cert verification for MICA gRPC connections and cause the + dataplane to restart. On certain platforms, this might cause the + firewall to reboot. +
+
+ Workaround: Disable CRL using the following CLI + command:debug iot eal key-value PAN_ICD_SERVER_CERT_USE_CRL=False +
+
+
PAN-267671
+
+ This issue is now resolved. See PAN-OS 11.1.4-h13 Addressed Issues. +
+
+
+ Exporting reports in PDF or CSV format and processing hourly scheduled + report results can potentially trigger memory leaks. As a result, this + can lead to process crashes and firewall reboots. +
+
+
PAN-268815
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues. +
+
+
+ When using IoT Security, the + wifclient might exit multiple + times causing the firewall to reboot. +
+
+ Workaround: Uninstall the IoT Security license and + disable + Enable enhanced application logging + (DeviceManagementCloud LoggingCloud Logging Settings). +
+
+
PAN-263226
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ When SSL decryption is enabled and Client Hello messages span multiple + TCP segments, elements from the proxy_l2info memory pool may not be + freed properly. Memory leaks in this pool cause some SSL decryption + sessions to fail. +
+
+ Workaround: Disable Client Hello accumulation + using the + debug dataplane set ssl-decrypt accumulate-client-hello disable + yes + CLI command. +
+
+
PAN-263987
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is + terminated on a Palo Alto Networks firewall and the NAT rule applied + to the NAT-T IPSec tunnel is also on the same firewall, then the data + traffic flowing through the NAT-T IPSec tunnel can't be NATed + correctly. +
+
+
PAN-263940
+
+
+ On a PA-7500 Series firewall node in an NGFW cluster, if the data + processing card is in slot 6, packet drops are expected. +
+
+
PAN-263208
+
+ This issue is now resolved. See PAN-OS 11.1.4-h9 Addressed Issues. +
+
+
+ (PA-5440 and PA-5445 firewalls only) High + system load can cause the firewall to generate interrupts and trigger + dataplane crashes. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1. +
+
+
PAN-262287
+
+
+ Dereferencing a NULL pointer that occurs might cause + pan_task + processes to crash. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-260512
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ This issue is now resolved. See PAN-OS 11.1.4-h9 Addressed Issues. +
+
+
+ When accessing the IP addresses of Dynamic address group objects from + the Panorama user interface in a configuration with numerous Device + Groups, the configd process might stop + responding. +
+
+
PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues. +
+
+
+ GlobalProtect portal is not accessible via a web browser and the app + displays the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-259733
+
+ This issue is now resolved. See + PAN-OS 11.1.4-h1 Addressed Issues +
+ . +
+
+ Custom reports created in PAN-OS are not deleted as expected, + resulting in high memory use by the + reportd + process. This can lead to issues, such as out-of-memory conditions, + content installation failures, and unexpected firewall reboots. +
+
+
PAN-258570
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7. +
+
+ This issue is now resolved. See + PAN-OS 11.1.6-h3 Addressed Issues. +
+
+
+ The + varrcvr + process might progressively use more memory resulting in unexpected + reboots when WildFire file forwarding is handling PE files. +
+
+
PAN-257957
+
+ This issue affects 11.1.4-h1. +
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ If you enable FIPS-CC mode and use the PAP or CHAP authentication + methods for your RADIUS server, the authd process may restart + unexpectedly. To avoid this issue, use one of the following + workarounds: +
+
    +
  • + If you use PAN-OS 10.2.10-h3, 10.2.11, or an earlier version, + configure the RADIUS server so that it does not send the message + authenticator back to client. +
  • +
  • + Use other protocols, such as LDAP, Kerberos, TACACS+, SAML, RADIUS + EAP, instead of RADIUS PAP or CHAP. +
  • +
  • Change from FIPS mode to normal mode.
  • +
+
+
PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.1.4-h1 Addressed Issues. +
+
+
+ The Panorama web interface intermittently displays logs or fails to + display logs completely. +
+
+
PAN-255579
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues. +
+
+
+ Demo Mode and Log Forwarding: PA-7500 Series firewalls and Panorama + display data plane logs after a delay. +
+
+
PAN-255285
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues. +
+
+
+ If only the HCSI-A link is connected on NGFW cluster nodes (the HSCI-B + link is not connected) and the management interfaces goes down, the + situation will result in a split brain. +
+
+
PAN-255116
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ When QoS is applied, traffic on an NGFW cluster node going from an + MC-LAG interface to a destination stops when a member of the MC-LAG + goes down. +
+
+
PAN-254927
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ Certain types of data packets sent to threat inspection processing on + the Networking cards of PA-7500 Series firewalls cause a pan_task + crash. +
+
+
PAN-254827
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ When you change an IP address on a management interface on any of the + NGFW cluster nodes, there's no workflow in cluster-config to detect + this change, so the subsequent commit-all will not push the updated + management IP address. +
+
+ Workaround: You must manually make an unrelated + change to cluster-config in order for Panorama to detect this change; + the subsequent commit-all will push the cluster-config with the + updated management IP address to cluster-manager. +
+
+
PAN-254351
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ An NGFW cluster node could get stuck in suspended state in some cases + when you use GRE tunnel termination with keepalive enabled on both + ends. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-253557
+
+
+ In the event of a cluster manager restart on the leader node of an + NGFW cluster, traffic stops because the state machine transitions to + unknown and the leader is not changing. +
+
+
PAN-253466
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On an NGFW cluster node, an expected packet buffer leak occurs with + FTP/SIP traffic over an extended period of time. +
+
+
PAN-252358
+
+
+ (PA-7500 Series firewalls only) In the event of + a corosync restart, an NGFW cluster node goes to failed state. +
+
+
PAN-251551
+
+
+ (PA-7500 Series firewalls only) When an NGFW + cluster agent crashes and doesn't recover, leader election will take + approximately 45 seconds to begin and traffic failover will occur + during that time. +
+
+
PAN-251501
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ Upon a reboot, an NGFW cluster node will occasionally fail to rejoin a + cluster due to a timing issue. +
+
+
PAN-250903
+
+
+ (PA-7500 Series firewalls only) In a congestion + scenario on an HSCI port of an NGFW cluster node, the QoS priorities + of cross node traffic streams might be reversed if you're using the + default QoS profile with class1 to class8 set as high to low. +
+
+
PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues. +
+
+
+ Device telemetry might fail at configured intervals due to bundle + generation issues. +
+
+
PAN-250043
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On an NGFW cluster node, if you configure a QoS interface with an + Egress Max (Mbps) that exceeds 68000, the operation will fail with a + message indicating "...is not a valid reference.…" The QoS Max + bandwidth on any interface cannot be configured to be more than 68000. +
+
+
PAN-249727
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On an NGFW cluster node, the Custom/Pre-defined URL category is not + part of the session flow data and a promoted session after failover + does not include it. +
+
+
PAN-248762
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ A firewall using the Advanced Routing Engine configured with OSPF + crashes when connecting to the neighbor while exchanging route maps. +
+
+
PAN-247974
+
+
+ (PA-7500 Series firewalls only) LACP flap is + expected during a device failover in an NGFW cluster due to an L2 + ctrld restart on the new leader node. +
+
+
PAN-240529
+
+ This issue is now resolved. See + PAN-OS 11.1.7 Addressed Issues +
+
+
+ (PA-7500 Series firewalls only) Cloud + application information is missing from traffic logs on NGFW cluster + nodes. +
+
+
PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues +
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-227978
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ The UI widget does not accurately list the status of the port when + NGFW clustering is enabled. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues +
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.1.5.html b/reference/PAN-OS/known/11.1.5.html new file mode 100644 index 0000000..aa75abf --- /dev/null +++ b/reference/PAN-OS/known/11.1.5.html @@ -0,0 +1,1452 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-298505
+ +
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues. +
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+ When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. +
+
PAN-292202
+
+ This issue is now resolved. See +
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due + to log overflow` due to the SNMP counters rolling over. This is a + benign message and does not impact device functionality. +
+
+
PAN-291288
+
+ An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. +
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287871
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives + fragmented Client Hello packets that include the TCP timestamp option, + the Client Hello message is forwarded to the destination server + without the timestamp option. +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.6-h14 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-286255
+
+ This issue is now resolved. See PAN-OS 11.1.6-h7 Addressed Issues. +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions, NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+ PAN-286231 +
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-280471
+
+
+ When applying filters or searching for logs in the + PanoramaMonitorLogssection, you might experience slow performance. +
+
+
PAN-279746
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if + the Client Hello arrives in multiple TCP segments and the traffic is + not subject to SSL decryption (for example, SMTP over SSL). +
+
+
PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Early aging and removal of firewall session while they are still + active can lead to intermittent instabilities and crashes for proxy + traffic, the Content and Threat detection engine, and any data-path + processing. +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-278296
+
+
+ The system MAC address of the aggregate interface is the same on both + the active and the passive devices, causing some packets to be sent + incorrectly to the passive device. This is causing the AE interface on + the active firewall to not come up. +
+
+
PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277034
+ +
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues +
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1 + or a later release, Panorama fails to upgrade if it is operating + within a Collector Group. The following error appears:Error: Traceback (most recent call last):File + "/opt/panrepo/releases/<PANOS release version>/validate"... + (min ([dts['min'] for dts in 10g_type_intv_dir.values() if + dts|'min']])-strftime ('%Y-%m-%d'), +
+
+
PAN-269193
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues. +
+
+
+ When multiple application are configured for GlobalProtect Clientless + VPN, users are directed to the first application instead of the portal + page with a list of application. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-261429
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues + and + PAN-OS 11.1.8 Addressed Issues. +
+
+
+ The command + show auth radius-require-msg-authentic + might return no output. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-252358
+
+
+ (PA-7500 Series firewalls only) In the event of + a corosync restart, an NGFW cluster node goes to failed state. +
+
+
PAN-251551
+
+
+ (PA-7500 Series firewalls only) When an NGFW + cluster agent crashes and doesn't recover, leader election will take + approximately 45 seconds to begin and traffic failover will occur + during that time. +
+
+
PAN-250903
+
+
+ (PA-7500 Series firewalls only) In a congestion + scenario on an HSCI port of an NGFW cluster node, the QoS priorities + of cross node traffic streams might be reversed if you're using the + default QoS profile with class1 to class8 set as high to low. +
+
+
PAN-247974
+
+
+ (PA-7500 Series firewalls only) LACP flap is + expected during a device failover in an NGFW cluster due to an L2 + ctrld restart on the new leader node. +
+
+
PAN-240529
+
+ This issue is now resolved. See + PAN-OS 11.1.7 Addressed Issues +
+
+
+ (PA-7500 Series firewalls only) Cloud + application information is missing from traffic logs on NGFW cluster + nodes. +
+
+
PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues +
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.1.6.html b/reference/PAN-OS/known/11.1.6.html new file mode 100644 index 0000000..dd676c3 --- /dev/null +++ b/reference/PAN-OS/known/11.1.6.html @@ -0,0 +1,2230 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
+ PAN-307795 This issue affects PAN-OS 11.1.6-h21 through 11.1.6-h24 + +
+
+ This issue is now resolved. See PAN-OS 11.1.10-h12 Addressed Issues. +
+
+
+ On a standalone Panorama, the system incorrectly generates system logs + indicating a lost connection to its peer even when High Availability + is not configured. You can safely ignore these logs, as they do not + affect operations. +
+
+
PAN-306502
+
+ This issue is now resolved. See PAN-OS 11.1.6-h23 Addressed Issues. +
+
+
+ TLS sessions using version 1.2 or earlier may fail when session + traffic matches a decryption policy rule with the no-decrypt action + under either of the following conditions: +
+
+ +
+
+ If both of these conditions are met, the session is guaranteed to + fail. +
+
+
+
    +
  • +
    + Both HTTP header insertion (ObjectsSecurity ProfilesURL FilteringHTTP Header Insertion) and SSL/TLS handshake inspection (DeviceSetupSessionDecryption SettingsSSL Decryption Settings) are enabled. +
    +
  • +
  • +
    + Log Successful SSL Handshake + is not enabled in the decryption policy rule and neither + Block sessions with expired certificates + nor + Block sessions with untrusted issuers + is enabled in the attached decryption profile. +
    +
  • +
+
+ Workaround: Perform one of the following tasks: +
+
    +
  • +
    + Enable + Log Successful SSL Handshake in + all no-decrypt decryption policy rules. +
    +
  • +
  • + Enable either + Block sessions with expired certificates + or + Block sessions with untrusted issuers + in the decryption profiles attached to the no-decrypt decryption + policy rules. +
  • +
+
+
PAN-305301
+
+ This issue is now resolved. See PAN-OS 11.1.10-h12 Addressed Issues. +
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout + notifications used for GlobalProtect SSL tunnels may cause the + pan_task + process to stop responding and the dataplane to restart. +
+
+ Workaround: Select + Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings + and change the value of both + Notify Before Lifetime Expires (min) + and + Notify Before Inactivity Logout (min) + to 0. +
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-304576
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command. +
+
+
+ PAN-303051This issue affects PAN-OS 11.1.6-h10 +
+
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues +
+
+ The reportd process experiences a memory + leak because it retains memory that was temporarily used for report + generation. Once a task is complete, the process fails to release this + memory for reuse, leading to continuous accumulation and eventual memory + exhaustion on the Panorama device. +
+
PAN-298505
+ +
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294436
+
+
+ (PA-410, PA-440, PA-450, and PA-460 firewalls) + After upgrading to 11.1.6-h6, the Eth1/2, Eth1/3, Eth1/8, and HA + interfaces (if configured) fail to display counters and statistics in + the CLI and SNMP. +
+
+
PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues. +
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+ When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. +
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due + to log overflow` due to the SNMP counters rolling over. This is a + benign message and does not impact device functionality. +
+
+
PAN-291288
+
+ An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. +
+
PAN-290996
+ +
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues. +
+
+
+ The + dscd + process crashes continuously on MIPS platforms (for example, PA-850 + firewalls) due to a runtime error related to an invalid memory address + or nil pointer dereference. This occurs when the golang library + upgrade in CIE is not compatible with the MIPS platform. +
+
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues. +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.6-h14 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286897
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues + and + PAN-OS 11.1.10 Addressed Issues. +
+
+
+ The + pan_task + process might fail when the firewall attempts to forward files to the + WildFire public cloud, which can cause the dataplane to experience + heartbeat failures. +
+
+ Workaround: Disable the firewall WildFire Analysis + profile. +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.1.6-h14 Addressed Issues +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286255
+
+ This issue affects PAN-OS 11.1.6-h4 +
+
+ This issue is now resolved. See PAN-OS 11.1.6-h7 Addressed Issues. +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions , NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-285590
+
+
+ VM-Series firewalls deployed behind an AWS GWLB might experience 100% + dataplane CPU utilization when an Anti-Spyware profile is applied to + traffic. +
+
+
PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues. +
+
+
+ (PA-3400 Series firewalls only) The firewall + might unexpectedly reboot and enter maintenance mode due to a + ctd-agent + out-of-memory (OOM) condition when undergoing advanced services load + testing with a high volume of IoT EAL log forwarding. +
+
+ Workaround: Limit the number of EAL logs generated + by the firewall using the following CLI command: + debug iot eal key-value EAL_PENDING_BYTES=1000. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-282854
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log + collectors in a multi-collector environment. +
+ Workaround: Restart all the involved log collectors. +
+
PAN-282236
+
(PAN-OS 11.1.6-h3 only)
+
+ This issue is now resolved. See + PAN-OS 11.1.6-h4 Addressed Issues. +
+
+
+ The firewall doesn't reassemble IPv6 packets correctly after they are + fragmented. IPv6 SSL sessions may not be established if the client + hello arrives in multiple segments. +
+
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-280471
+
+
+ When applying filters or searching for logs in the + PanoramaMonitorLogssection, you might experience slow performance. +
+
+
PAN-279901
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+ To enable this fix, run the CLI command + bug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279746
+
(PAN-OS 11.1.6-h3 only)
+
+ This issue is now resolved. See + PAN-OS 11.1.6-h4 Addressed Issues. +
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if + the Client Hello arrives in multiple TCP segments and the traffic is + not subject to SSL decryption (for example, SMTP over SSL). +
+
+
PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Early aging and removal of firewall session while they are still + active can lead to intermittent instabilities and crashes for proxy + traffic, the Content and Threat detection engine, and any data-path + processing. +
+
+
PAN-279604
+
(PAN-OS 11.1.6-h1 only)
+
+
+ The scheduled SaaS application usage reports are incorrectly generated + and only the login page appears instead of the intended report + content. +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-278322
+
+
+ VM-Series firewalls deployed behind an AWS GWLB might display an + incorrect or empty Source User field in traffic logs and session + details. +
+
+
PAN-278296
+
+ (This issue affects PAN-OS 11.1.6-h6.) +
+
+ This issue is now resolved. See PAN-OS 11.1.6-h6 Addressed Issues. +
+
+
+ The system MAC address of the aggregate interface is the same on both + the active and the passive devices, causing some packets to be sent + incorrectly to the passive device. This is causing the AE interface on + the active firewall to not come up. +
+
+
PAN-277417
+
Thibx
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277090
+
+
+ When you enable Advanced Routing and configure a BGP Authentication + profile, if you configure a Secret that includes any special + characters apart from these seven special characters !@#%^_-, an error + message displays, indicating that + The value in this field is invalid. +
+
+ Workaround: Don't include any special character + apart from the !@#%^_- characters in the Secret for a BGP + Authentication profile. +
+
+
PAN-277034
+ +
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-276920
+
+
+ URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
+
+ PAN-275905 +
(PAN-OS 11.1.6-h3 only)
+
+
+ A high volume of incoming logs to a Collector Group can significantly + increase CPU usage on the Elasticsearch and Management Server, + potentially causing process instability or crashes. +
+
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-274146
+
+
+ VM-Series firewalls deployed behind an AWS GWLB might crash and reboot + unexpectedly if tunnel sessions are moving through the firewall. +
+
+ PAN-272085 +
+ (This issue affects PAN-OS 11.1.6-h3.) +
+
+
+ When DoH is enabled for DNS Security, multiple DoH transactions in a + single HTTP/1 connection might unexpectedly cause the firewall to + crash and reboot. +
+
+ Workaround: Manually disable DoH support for DNS + Security using the + set deviceconfig setting dns-over-https enable no + CLI command. Alternatively, you can remove the DNS Security + configuration used to handle DoH traffic. +
+
+
PAN-269193
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues. +
+
+
+ When multiple application are configured for GlobalProtect Clientless + VPN, users are directed to the first application instead of portal + page with a list of application. +
+
+ PAN-268705 +
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues. +
+
+
+ The firewall intermittently fails to process FTP traffic. +
+
+ Workaround: Configure an application override + policy rule for FTP applications. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-261429
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues + and + PAN-OS 11.1.8 Addressed Issues. +
+
+
+ The command + show auth radius-require-msg-authentic + might return no output. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-252358
+
+
+ (PA-7500 Series firewalls only) In the event of + a corosync restart, an NGFW cluster node goes to failed state. +
+
+
PAN-251551
+
+
+ (PA-7500 Series firewalls only) When an NGFW + cluster agent crashes and doesn't recover, leader election will take + approximately 45 seconds to begin and traffic failover will occur + during that time. +
+
+
PAN-250903
+
+
+ (PA-7500 Series firewalls only) In a congestion + scenario on an HSCI port of an NGFW cluster node, the QoS priorities + of cross node traffic streams might be reversed if you're using the + default QoS profile with class1 to class8 set as high to low. +
+
+
PAN-247974
+
+
+ (PA-7500 Series firewalls only) LACP flap is + expected during a device failover in an NGFW cluster due to an L2 + ctrld restart on the new leader node. +
+
+
PAN-240529
+
+ This issue is now resolved. See + PAN-OS 11.1.7 Addressed Issues +
+
+
+ (PA-7500 Series firewalls only) Cloud + application information is missing from traffic logs on NGFW cluster + nodes. +
+
+
PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues +
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
+
PAN-164885
+
+
+ On the Panorama management server, pushes to managed firewalls (CommitPush to Devices + or Commit and Push) may fail when an + EDL (ObjectsExternal Dynamic Lists) is configured to + Check for updates every 5 minutes + due to the commit and EDL fetch processes overlapping. This is more + likely to occur when multiple EDLs are configured to check for updates + every 5 minutes. +
+
diff --git a/reference/PAN-OS/known/11.1.7.html b/reference/PAN-OS/known/11.1.7.html new file mode 100644 index 0000000..992dd65 --- /dev/null +++ b/reference/PAN-OS/known/11.1.7.html @@ -0,0 +1,1757 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-304576
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command. +
+
+
PAN-303051
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues +
+ The reportd process experiences a memory + leak because it retains memory that was temporarily used for report + generation. Once a task is complete, the process fails to release this + memory for reuse, leading to continuous accumulation and eventual memory + exhaustion on the Panorama device. +
+
PAN-298505
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h7 Addressed Issues + and + PAN-OS 11.1.12 Addressed Issues +
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues. +
+
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+ When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. +
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due + to log overflow` due to the SNMP counters rolling over. This is a + benign message and does not impact device functionality. +
+
+
PAN-291288
+
+ An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. +
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.7-h1 Addressed Issues + and + PAN-OS 11.1.10-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues. +
+
+
+ The + dscd + process crashes continuously on MIPS platforms (for example, PA-850 + firewalls) due to a runtime error related to an invalid memory address + or nil pointer dereference. This occurs when the golang library + upgrade in CIE is not compatible with the MIPS platform. +
+
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286897
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ The + pan_task + process might fail when the firewall attempts to forward files to the + WildFire public cloud, which can cause the dataplane to experience + heartbeat failures. +
+
+ Workaround: Disable the firewall WildFire Analysis + profile. +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-286255
+
+ This issue affects PAN-OS 11.1.7-h2 +
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions , NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ (PA-3400 Series firewalls only) The firewall + might unexpectedly reboot and enter maintenance mode due to a + ctd-agent + out-of-memory (OOM) condition when undergoing advanced services load + testing with a high volume of IoT EAL log forwarding. +
+
+ Workaround: Limit the number of EAL logs generated + by the firewall using the following CLI command: + debug iot eal key-value EAL_PENDING_BYTES=1000. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-279901
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+ To enable this fix, run the CLI command + bug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279746
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues. +
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if + the Client Hello arrives in multiple TCP segments and the traffic is + not subject to SSL decryption (for example, SMTP over SSL). +
+
+
PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Early aging and removal of firewall session while they are still + active can lead to intermittent instabilities and crashes for proxy + traffic, the Content and Threat detection engine, and any data-path + processing. +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-278296
+
+
+ The system MAC address of the aggregate interface is the same on both + the active and the passive devices, causing some packets to be sent + incorrectly to the passive device. This is causing the AE interface on + the active firewall to not come up. +
+
+
PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues +
+
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-276920
+
+
+ URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
+
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-272085
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues. +
+
+
+ When DoH is enabled for DNS Security, multiple DoH transactions in a + single HTTP/1 connection might unexpectedly cause the firewall to + crash and reboot. +
+
+ Workaround: Manually disable DoH support for DNS + Security using the following CLI command: + set deviceconfig setting dns-over-https enable no. Alternatively, you can remove the DNS Security configuration used + to handle DoH traffic. +
+
+
PAN-269193
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues. +
+
+
+ When multiple application are configured for GlobalProtect Clientless + VPN, users are directed to the first application instead of portal + page with a list of application. +
+
+ PAN-268705 +
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.. +
+
+
+ The firewall intermittently fails to process FTP traffic. +
+
+ Workaround: Configure an application override + policy rule for FTP applications. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-261429
+
+ This issue is now resolved. See + PAN-OS 11.1.8 Addressed Issues. +
+
+
+ The command + show auth radius-require-msg-authentic + might return no output. +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-252358
+
+
+ (PA-7500 Series firewalls only) In the event of + a corosync restart, an NGFW cluster node goes to failed state. +
+
+
PAN-251551
+
+
+ (PA-7500 Series firewalls only) When an NGFW + cluster agent crashes and doesn't recover, leader election will take + approximately 45 seconds to begin and traffic failover will occur + during that time. +
+
+
PAN-250903
+
+
+ (PA-7500 Series firewalls only) In a congestion + scenario on an HSCI port of an NGFW cluster node, the QoS priorities + of cross node traffic streams might be reversed if you're using the + default QoS profile with class1 to class8 set as high to low. +
+
+
PAN-247974
+
+
+ (PA-7500 Series firewalls only) LACP flap is + expected during a device failover in an NGFW cluster due to an L2 + ctrld restart on the new leader node. +
+
+
PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues +
+
+
+ LSVPN satellite certificates may be generated with serial numbers + exceeding 40 hexadecimal characters. This causes certificate + revocation and deletion operations to fail with the following error + messages: +
+
    +
  • + db-serialno can be at most 40 characters +
  • +
  • + db-serialno is invalid +
  • +
+ Workaround: +
+ To resolve this issue, use the following CLI commands with the LSVPN + satellite serial number to manually delete or revoke the affected + certificates: +
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name + <name> serialno + <satellite_serial> +
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal + <name> serialno + <list_of_satellite_serials> +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-219644
+
+
+ Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate instead of the + custom certificate configured on the firewall. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.1.8.html b/reference/PAN-OS/known/11.1.8.html new file mode 100644 index 0000000..dfc90a3 --- /dev/null +++ b/reference/PAN-OS/known/11.1.8.html @@ -0,0 +1,1585 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-304576
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command. +
+
+
PAN-303051
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues +
+ The reportd process experiences a memory + leak because it retains memory that was temporarily used for report + generation. Once a task is complete, the process fails to release this + memory for reuse, leading to continuous accumulation and eventual memory + exhaustion on the Panorama device. +
+
PAN-298505
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h7 Addressed Issues + and + PAN-OS 11.1.12 Addressed Issues +
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues. +
+
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+ When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. +
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due + to log overflow` due to the SNMP counters rolling over. This is a + benign message and does not impact device functionality. +
+
+
PAN-289432
+
+
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues. +
+
+
+ The + dscd + process crashes continuously on MIPS platforms (for example, PA-850 + firewalls) due to a runtime error related to an invalid memory address + or nil pointer dereference. This occurs when the golang library + upgrade in CIE is not compatible with the MIPS platform. +
+
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286897
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ The + pan_task + process might fail when the firewall attempts to forward files to the + WildFire public cloud, which can cause the dataplane to experience + heartbeat failures. +
+
+ Workaround: Disable the firewall WildFire Analysis + profile. +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286255
+
+ This issue affects PAN-OS 11.1.7-h2 +
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ When a firewall receives an unexpected termination request for certain + SSL sessions , NGFW dataplane might experience a slow buffer resource + leak. +
+
+ Workaround: Disable accumulation proxy on the + NGFW. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ (PA-3400 Series firewalls only) The firewall + might unexpectedly reboot and enter maintenance mode due to a + ctd-agent + out-of-memory (OOM) condition when undergoing advanced services load + testing with a high volume of IoT EAL log forwarding. +
+
+ Workaround: Limit the number of EAL logs generated + by the firewall using the following CLI command: + debug iot eal key-value EAL_PENDING_BYTES=1000. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-282854
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log + collectors in a multi-collector environment. +
+ Workaround: Restart all the involved log collectors. +
+
PAN-281885
+
+
+ When exporting and importing the CSV file, the hash values of + pre-shared key (PSK) variables set at template and template stack + levels inconsistently change, resulting in both variables displaying + the same hash value. +
+
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-279901
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+ To enable this fix, run the CLI command + bug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Early aging and removal of firewall session while they are still + active can lead to intermittent instabilities and crashes for proxy + traffic, the Content and Threat detection engine, and any data-path + processing. +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ Memory leak issues can occur during the parsing of server certificates + used for SSL Inbound Inspection, preventing the firewall from + completing inspection. +
+
+
PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues +
+
+
PAN-276920
+
+
+ URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
+
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+ PAN-268705 +
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues. +
+
+
+ The firewall intermittently fails to process FTP traffic. +
+
+ Workaround: Configure an application override + policy rule for FTP applications. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-251551
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
+
+
PAN-250903
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
+
+
PAN-247974
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+
diff --git a/reference/PAN-OS/known/11.1.9.html b/reference/PAN-OS/known/11.1.9.html new file mode 100644 index 0000000..6aaa3d1 --- /dev/null +++ b/reference/PAN-OS/known/11.1.9.html @@ -0,0 +1,1436 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-308564
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes). +
+
+
PAN-304756
+
+ This issue is now resolved. See + PAN-OS 11.1.13-h1 Addressed Issues. +
+
+
+ After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems. +
+
+
PAN-304576
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command. +
+
+
PAN-303051
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues +
+
+ The reportd process experiences a + memory leak because it retains memory that was temporarily used for + report generation. Once a task is complete, the process fails to + release this memory for reuse, leading to continuous accumulation and + eventual memory exhaustion on the Panorama device. +
+
+
PAN-298505
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h7 Addressed Issues + and + PAN-OS 11.1.12 Addressed Issues +
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+
+
PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues. +
+
+ On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. +
+
PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+ When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. +
+
PAN-292202
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due + to log overflow` due to the SNMP counters rolling over. This is a + benign message and does not impact device functionality. +
+
+
PAN-289432
+
+
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+
+
PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues. +
+
+
+ The + dscd + process crashes continuously on MIPS platforms (for example, PA-850 + firewalls) due to a runtime error related to an invalid memory address + or nil pointer dereference. This occurs when the golang library + upgrade in CIE is not compatible with the MIPS platform. +
+
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes. +
+
+
PAN-289383
+
+
+ (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
+
+ Workaround: Enable auto-negotiation on the + connected peer firewall. +
+
+
PAN-288097
+
+ This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
+
+
+ Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
+
+
PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues +
+
+
+ A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
+
+
PAN-286897
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ The + pan_task + process might fail when the firewall attempts to forward files to the + WildFire public cloud, which can cause the dataplane to experience + heartbeat failures. +
+
+ Workaround: Disable the firewall WildFire Analysis + profile. +
+
+
PAN-286848
+
+
+ ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
+
+
PAN-286496
+
+
+ (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
+
+
PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues +
+
+
+ When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
+
+
PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
+
+ This issue is more likely to occur in the following scenarios: +
    +
  • +
    + When you run Commit and Push operations as a + single action. +
    +
  • +
  • +
    + When you trigger multiple parallel commit-all jobs at the same + time. +
    +
  • +
  • +
    + Device groups and templates have different configuration + synchronization versions. +
    +
  • +
+
+
+ Workaround: Perform one of the following steps: +
+
    +
  • + Perform commit and push as two separate, sequential steps. +
  • +
  • Perform a full push instead of selective push.
  • +
+
+
PAN-285894
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
+
+ Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
+
+
PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ (PA-3400 Series firewalls only) The firewall + might unexpectedly reboot and enter maintenance mode due to a + ctd-agent + out-of-memory (OOM) condition when undergoing advanced services load + testing with a high volume of IoT EAL log forwarding. +
+
+ Workaround: Limit the number of EAL logs generated + by the firewall using the following CLI command: + debug iot eal key-value EAL_PENDING_BYTES=1000. +
+
+
PAN-283429
+
+
+ When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
+
+ Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
+
+
PAN-282854
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log + collectors in a multi-collector environment. +
+ Workaround: Restart all the involved log collectors. +
+
PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues. +
+
+
+ When you use a single syslog server over TCP for log forwarding, and + the connectivity to the syslog server breaks, syslog forwarding does + not resume even after the connectivity to the server restores. +
+
+ Workaround: Performing one of the following tasks: +
+
    +
  • Reboot the firewall.
  • +
  • + Temporarily, configure syslog to use UDP, commit the configuration, + revert to TCP, and then commit. +
  • +
+
+
PAN-279901
+
+
+ When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
+
    +
  • +
    + The segmented Client Hello packets arrive out-of-order +
    +
  • +
  • +
    + The segmented Client Hello packets arrive out-of-order and can be + reassembled into a complete Client Hello when the first contiguous + segment is formed by NGFW +
    +
  • +
  • +
    + The first segment of the Client Hello packets is less than 5 bytes +
    +
  • +
  • +
    + A decryption policy rule excludes this traffic from decryption and + a Security policy rule (URL filtering) denies this session +
    +
  • +
+
+ To enable this fix, run the CLI command + bug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+
+
+ Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
+
+
PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues +
+
+ WildFire reports might not fully display or be downloadable because some + static resources fail to load. +
+
PAN-276920
+
+
+ URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
+
+
PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues +
+
+
+ When Panorama is not internet-connected and you try to upload images + to the managed firewalls by using the + Validate option, the upload fails + with the following error: + Failed to create multi-upload job. No valid software deploy targets + found. +
+
+
PAN-275047
+
+
+ (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
+
+
PAN-262556
+
+
+ The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
+
+
PAN-260851
+
+
+ From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
+
+
PAN-254240
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
+
+
PAN-253963
+
+
+ The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
+
+
PAN-251551
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
+
+
PAN-250903
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
+
+
PAN-247974
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
+
+
PAN-234015
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
+
+
PAN-224502
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
+
+
PAN-220180
+
+
+ Configured botnet reports (MonitorBotnet) are not generated. +
+
+
PAN-207733
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
+
+
PAN-207611
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
+
+
PAN-207442
+
+
+ For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
+
+ Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
+
    +
  1. +
    + Log in to the Panorama web interface + of the active-primary HA + peer. +
    +
  2. +
  3. +
    + Select Commit and + Commit to Panorama. +
    +
  4. +
  5. +
    + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    +
  6. +
+
+
PAN-207040
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name. +
+
+
PAN-206913
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall. +
+
+
PAN-206909
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
+
+ This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
+
+ Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
+
    +
  1. + +
  2. +
  3. +
    + Confirm the Dedicated Log Collector is disconnected from Panorama. +
    + +
    +
    admin> show panorama-status
    +
    + Verify the Connected status + is no. +
    +
    +
  4. +
  5. +
    + Restart the mgmtsrvr process. +
    + +
    +
    admin> debug software restart process management-server
    +
    +
  6. +
+
+
PAN-197588
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis. +
+
+
PAN-197419
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value. +
+
+
PAN-196758
+
+
+ On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
+
+
PAN-195968
+
+
+ (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
+
+
PAN-194978
+
+
+ (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
+
+
PAN-187685
+
+
+ On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
+
+ Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
+
+
PAN-187407
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
+
+
PAN-186283
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
+
+ Workaround: Use + CommitPush to Devices + to synchronize the templates. +
+
+
PAN-184708
+
+
+ Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
+
    +
  • + A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report. +
  • +
  • + A scheduled report contains only a SaaS Application Usage Report. +
  • +
+
+ Workaround: To receive a scheduled report email + for all other PDF report types: +
+
    +
  1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
  2. +
  3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
    + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
    +
  4. +
  5. + Commit. +
    + (Panorama managed firewalls) Select + CommitCommit and Push +
    +
  6. +
+
+
PAN-184406
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
+
+ Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
+
+
PAN-183404
+
+
+ Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
+
+
PAN-181933
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs. +
+