Add 8.1 issues data
This commit is contained in:
@@ -0,0 +1,130 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.0
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-92893
|
||||||
|
|
||||||
|
Fixed an issue that occurred during the reboot process and caused some firewalls to go in to maintenance mode.
|
||||||
|
|
||||||
|
## PAN-92268
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where one or more dataplanes did not pass traffic when you ran several operational commands (from any firewall user interface or from the Panorama™ management server) while committing changes to device or network settings or while installing a content update.
|
||||||
|
|
||||||
|
## PAN-91774
|
||||||
|
|
||||||
|
Fixed an issue on Panorama virtual appliances for AWS in a high availability (HA) configuration where the primary peer did not synchronize template changes to the secondary peer.
|
||||||
|
|
||||||
|
## PAN-91429
|
||||||
|
|
||||||
|
Fixed an issue where PA-5200 Series firewalls rebooted when you ran the set ssh service-restart mgmt CLI command multiple times.
|
||||||
|
|
||||||
|
## PAN-91361
|
||||||
|
|
||||||
|
Fixed an issue where client connections initiated with HTTP/2 failed during SSL Inbound Inspection decryption because the firewall removed the Application-Layer Protocol Negotiation (ALPN) extension within the server hello packet instead of forwarding the extension to the client.
|
||||||
|
|
||||||
|
## PAN-91236
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server did not display new logs collected on M-Series Log Collectors because the logging search engine did not register during system startup when logging disk checks and RAID mounting took longer than two hours to complete.
|
||||||
|
|
||||||
|
## PAN-90954
|
||||||
|
|
||||||
|
A security-related fix was made to prevent a local privilege escalation vulnerability that could potentially result in the deletion of files (CVE-2018-9242).
|
||||||
|
|
||||||
|
## PAN-90842
|
||||||
|
|
||||||
|
Fixed an issue where commits failed after you changed the default **Size Limit** to a custom value for MacOSX files that the firewall forwarded to WildFire® (**Device** > **Setup** > **WildFire**).
|
||||||
|
|
||||||
|
## PAN-90835
|
||||||
|
|
||||||
|
A security-related fix was made to prevent a Cross-Site Scripting (XSS) attack through the PAN-OS® session browser (CVE-2018-7636).
|
||||||
|
|
||||||
|
## PAN-90521
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where Device Group and Template administrators could not display or edit the **Device** > **Log Settings** in a template.
|
||||||
|
|
||||||
|
## PAN-90168
|
||||||
|
|
||||||
|
Fixed an issue where, after you downgraded a firewall from PAN-OS 8.1 to a previous PAN-OS release and then clicked **Revert Content** on the Panorama management server (**Panorama** > **Device Deployment** > **Dynamic Updates**) the Current Version column displayed the content release version of the firewall when it ran PAN-OS 8.1 regardless of the content version currently installed on the firewall.
|
||||||
|
|
||||||
|
## PAN-89471
|
||||||
|
|
||||||
|
Fixed an issue where firewalls rebooted because the userid process restarted too often due to a socket binding failure that caused a memory leak.
|
||||||
|
|
||||||
|
## PAN-89030
|
||||||
|
|
||||||
|
Fixed an issue where the firewall could not authenticate to a hardware security module (HSM) partition when the partition password contained special characters.
|
||||||
|
|
||||||
|
## PAN-88292
|
||||||
|
|
||||||
|
Fixed an issue on Panorama management servers in an HA configuration where the Log Collector that ran locally on the passive peer did not forward logs to syslog servers.
|
||||||
|
|
||||||
|
## PAN-88200
|
||||||
|
|
||||||
|
Fixed an issue where firewalls with multiple virtual systems did not import external dynamic lists that you assigned to policy rules.
|
||||||
|
|
||||||
|
## PAN-88018
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the firewall was not able to override the local device configuration and failed to apply Dynamic Updates with an interval set to none.
|
||||||
|
|
||||||
|
## PAN-86873
|
||||||
|
|
||||||
|
Fixed an issue where the firewall advertised the OSPF not-so-stubby area (NSSA) link-state advertisement (LSA) type 7 default route to NSSA neighbors even when the OSPF backbone area was down.
|
||||||
|
|
||||||
|
## PAN-85410
|
||||||
|
|
||||||
|
Fixed two issues on a firewall configured for GlobalProtect™ Clientless VPN:
|
||||||
|
|
||||||
|
- The firewall dataplane restarted when client cookies contained a path that did not start with a forward slash (/).
|
||||||
|
- The firewall did not properly reinitialize client cookies that had a missing path and domain and instead used values from previously received cookies.
|
||||||
|
|
||||||
|
## PAN-84836
|
||||||
|
|
||||||
|
A security-related fix was made to address a Cross-Site Scripting (XSS) vulnerability in the PAN-OS response to a GlobalProtect gateway (CVE-2018-10139).
|
||||||
|
|
||||||
|
## PAN-84045
|
||||||
|
|
||||||
|
Fixed an issue where VM-Series firewalls in a high availability (HA) configuration with Data Plane Development Kit (DPDK) enabled experienced HA path monitoring failures and (in active/passive deployments) HA failover.
|
||||||
|
|
||||||
|
## PAN-83900
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server did not run **ACC** reports or custom reports because the reportd process stopped responding when an administrator tried to access a device group to which that administrator did not have access.
|
||||||
|
|
||||||
|
## PAN-82942
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rebooted because the User-ID™ process (useridd) restarted several times when endpoints, while requesting services that could not process HTTP 302 responses (such as Microsoft update services), authenticated to Captive Portal through NT LAN Manager (NTLM) and immediately disconnected.
|
||||||
|
|
||||||
|
## PAN-81417
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where, after an administrator selected **Force Template Values** when editing Push Scope selections (**Commit** > **Push to Devices**), the setting persisted as enabled for that administrator in all subsequent push operations instead of defaulting to disabled. With this fix, **Force Template Values** is disabled by default for every push operation until, and only if, the administrator manually enables the setting.
|
||||||
|
|
||||||
|
## PAN-80794
|
||||||
|
|
||||||
|
A protocol-related fix was made to address a bug in the OSPF protocol.
|
||||||
|
|
||||||
|
## PAN-80569
|
||||||
|
|
||||||
|
Fixed an issue where firewalls could not connect to M-500 or M-600 appliances in PAN-DB mode due to certificate validation failures. With this fix, the appliances add an IP address to the Subject Alternative Name (SAN) field when generating the certificates used for firewall connections.
|
||||||
|
|
||||||
|
## PAN-80505
|
||||||
|
|
||||||
|
Fixed an issue where a firewall was able connect to Panorama using an expired certificate.
|
||||||
|
|
||||||
|
## PAN-75775
|
||||||
|
|
||||||
|
Fixed an issue where SNMP managers indicated syntax errors in PAN-OS MIBs, such as forward slash (/) characters not used within quotation marks (“”). You can find the updated MIBs at [https://docs.paloaltonetworks.com/resources/snmp-mib-files](https://docs.paloaltonetworks.com/resources/snmp-mib-files).
|
||||||
|
|
||||||
|
## PAN-73316
|
||||||
|
|
||||||
|
Fixed an issue where a GlobalProtect user first logged in with a RADIUS authentication profile, the Domain-UserName appeared as user@domain (instead of domain\user) in the PAN-OS web interface.
|
||||||
|
|
||||||
|
## PAN-73154
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where commit operations stopped progressing after reaching 99 per cent completion.
|
||||||
@@ -0,0 +1,363 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.10
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-120548
|
||||||
|
|
||||||
|
Fixed an issue where the Captive Portal request limit was ignored when you configured the Captive Portal authentication method to browser-challenge.
|
||||||
|
|
||||||
|
## PAN-120409
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where firewalls running a 20G Network Processing Card (NPC) or a 20GQ NPC dropped stream control transmission protocol (SCTP) connections due to incorrect session handling.
|
||||||
|
|
||||||
|
## PAN-119257
|
||||||
|
|
||||||
|
Fixed an issue where the firewall could not establish an IKEv2 connection with SHA256 certificates.
|
||||||
|
|
||||||
|
## PAN-119030
|
||||||
|
|
||||||
|
Fixed an issue on Panorama™ M-Series and virtual appliances where bootstrapped managed firewalls were disconnected after you performed a partial revert if you did not first perform a manual commit. With this fix, the manual commit is not required.
|
||||||
|
|
||||||
|
## PAN-118656
|
||||||
|
|
||||||
|
Fixed an issue where the ifAdminStatus object identifier (OID) for dedicated high availability (HA) interfaces incorrectly displayed as up when interfaces were not used in an HA configuration.
|
||||||
|
|
||||||
|
## PAN-118423
|
||||||
|
|
||||||
|
Fixed an intermittent issue with local HA status changes where the mprelay process failed to commit changes to the HA state.
|
||||||
|
|
||||||
|
## PAN-118411
|
||||||
|
|
||||||
|
Fixed an issue where ARP entries took longer than expected to age out in a single run.
|
||||||
|
|
||||||
|
## PAN-118351
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.1.7, 8.1.8, and 8.1.9 only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where log forwarding stopped responding when you configured a second log collector to the collector group.
|
||||||
|
|
||||||
|
## PAN-118008
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a low memory condition prevented decoders from loading, which led to traffic inspection issues related to the impacted decoder(s).
|
||||||
|
|
||||||
|
## PAN-117921
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to create GTP inner sessions, which caused the firewall to drop GTP-U data packets when the firewall was deployed on S1-U and S-11 interfaces.
|
||||||
|
|
||||||
|
## PAN-117916
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane stopped responding when you pushed permitted IP addresses from Panorama to managed firewalls.
|
||||||
|
|
||||||
|
## PAN-117818
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a rare issue where an initialization delay with a process (brdagent) caused the dataplane to stop responding.
|
||||||
|
|
||||||
|
## PAN-116969
|
||||||
|
|
||||||
|
Fixed an issue where authentication failed when you configured a User Principal Name (UPN) and included a group in the profile.
|
||||||
|
|
||||||
|
## PAN-116807
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000, PA-5200, and PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped ICMP error messages when the security policy was configured to allow ICMP
|
||||||
|
|
||||||
|
## PAN-116218
|
||||||
|
|
||||||
|
Fixed an issue where test routing bgp virtual-router default restart peer <peer-ID> CLI command did not execute the operational request and returned the following error message: op command for client routed timed out as client is not available.
|
||||||
|
|
||||||
|
## PAN-115856
|
||||||
|
|
||||||
|
Fixed an issue where Dynamic IP and Port (DIPP) NAT pools did not release used ports after all sessions were removed.
|
||||||
|
|
||||||
|
## PAN-115852
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls on AWS where you could not change maximum transmission unit (MTU) values from the web interface and displayed the following error message: Malformed Request.
|
||||||
|
|
||||||
|
## PAN-115812
|
||||||
|
|
||||||
|
Fixed an issue where the child session did not inherit policy-base forwarding information when the parent session is allocated to separate dataplanes.
|
||||||
|
|
||||||
|
## PAN-115748
|
||||||
|
|
||||||
|
Fixed an intermittent issue on Panorama M-Series and virtual appliances where a memory issue caused the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-115695
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a large number of packets were received before acknowledgments were complete, which depleted descriptor queue entries and resulted in high latency during data transfers even though CPU usage looked normal.
|
||||||
|
|
||||||
|
## PAN-115354
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where renaming a device group followed by a partial commit did not change the device group hierarchy as expected.
|
||||||
|
|
||||||
|
## PAN-115219
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where Global Find caused the web interface to stop responding when you searched for common English words.
|
||||||
|
|
||||||
|
## PAN-115186
|
||||||
|
|
||||||
|
Fixed an issue where SaaS reports were not generated due to report definitions not getting pushed to the log collector.
|
||||||
|
|
||||||
|
## PAN-115160
|
||||||
|
|
||||||
|
Fixed an issue where a UDP packet without a payload did not trigger the multi-factor authentication (MFA) and was not discarded based on the authentication policy.
|
||||||
|
|
||||||
|
## PAN-115012
|
||||||
|
|
||||||
|
Fixed an issue where a process (appweb) stopped responding, which caused the web interface to stop responding.
|
||||||
|
|
||||||
|
## PAN-114958
|
||||||
|
|
||||||
|
Fixed an issue where the User-ID™ (useridd) process consumed more CPU cycles than expected when you configured User-ID redistribution.
|
||||||
|
|
||||||
|
## PAN-114855
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped syslog packets after you upgraded to PAN-OS® 8.1.6.
|
||||||
|
|
||||||
|
## PAN-114844
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where malformed API calls caused the appliance to reboot.
|
||||||
|
|
||||||
|
## PAN-114779
|
||||||
|
|
||||||
|
Fixed an issue where log purging took longer than expected, which prevented the firewall from capturing traffic logs.
|
||||||
|
|
||||||
|
## PAN-114695
|
||||||
|
|
||||||
|
Fixed an issue where a daemon (authd) stopped responding when you configured a GlobalProtect™ portal and gateway with Security Assertion Markup Language (SAML) authentication.
|
||||||
|
|
||||||
|
## PAN-114567
|
||||||
|
|
||||||
|
Fixed an issue where a system query (Eventideq globalprotectportal-config-succ) caused the management server (mgmtsrvr) process to stop responding.
|
||||||
|
|
||||||
|
## PAN-114533
|
||||||
|
|
||||||
|
Fixed an issue where traffic was blocked by safe search enforcement before matching the intended allow rule.
|
||||||
|
|
||||||
|
## PAN-114526
|
||||||
|
|
||||||
|
Fixed an issue where larger than expected number of packets sent over a GTP-U tunnel caused packet captures to fill the files faster than expected. With this fix, you can run the debug dataplane packet-diag set capture gtpu-lvl[1-30] command to ensure GTP-U traffic are captured.
|
||||||
|
|
||||||
|
## PAN-114475
|
||||||
|
|
||||||
|
Fixed an issue where Panorama in FIPS mode defaulted to FIPS-CC mode instead of Normal mode.
|
||||||
|
|
||||||
|
## PAN-114395
|
||||||
|
|
||||||
|
Fixed an issue on a VM-Series firewall where a process (all_task) stopped responding, which caused the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-114264
|
||||||
|
|
||||||
|
Fixed an issue where sessions were offloaded as the application identification was performed when you configured a custom application with **Continue scanning for other application**.
|
||||||
|
|
||||||
|
## PAN-114222
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped traffic logs due to a negative log counter reading.
|
||||||
|
|
||||||
|
## PAN-114160
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to download ZIP files greater than 3GB through a GlobalProtect Clientless VPN application.
|
||||||
|
|
||||||
|
## PAN-114105
|
||||||
|
|
||||||
|
Fixed an issue on a Panorama M-Series appliance where the Summary (**Panorama** > **Managed Devices** > **Summary**) web interface refreshes every 10 seconds when set to manually refresh.
|
||||||
|
|
||||||
|
## PAN-114090
|
||||||
|
|
||||||
|
Fixed an issue on a Panorama virtual appliance in Legacy mode and in an HA active/passive configuration where logs were forwarded only to the active HA peer.
|
||||||
|
|
||||||
|
## PAN-114002
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to import variable CSV files when variable names contained a character space.
|
||||||
|
|
||||||
|
## PAN-113930
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where CPU loads were uneven across cores when more than 8 cores were allocated to the dataplane.
|
||||||
|
|
||||||
|
## PAN-113912
|
||||||
|
|
||||||
|
Fixed an issue where a process (ikemgr) stopped responding and caused the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-113887
|
||||||
|
|
||||||
|
Fixed an issue where loading custom app tags did not complete successfully, which prevented subsequent requests (such as commits, content installs, and FQDN refreshes) from executing as expected.
|
||||||
|
|
||||||
|
## PAN-113870
|
||||||
|
|
||||||
|
Fixed an issue where Security policies were not evaluated in sequential order when the policy was based on URL categories.
|
||||||
|
|
||||||
|
## PAN-113796
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect configured with the **pre-logon then on-demand** connect method was unable to authenticate during pre-logon when you configured the portal and gateway with an Authentication Override and without a certification profile.
|
||||||
|
|
||||||
|
## PAN-113767
|
||||||
|
|
||||||
|
Fixed an issue where the firewall silently dropped packets when Security profiles were attached and FPGA enabled AHO and DFA.
|
||||||
|
|
||||||
|
## PAN-113501
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server returned a Security Copy (SCP) server connection error after you created an SCP Scheduled Config Export profile (**Panorama** > **Scheduled Config Export**) due to the SCP server password exceeding 15 characters in length.
|
||||||
|
|
||||||
|
## PAN-113356
|
||||||
|
|
||||||
|
Fixed an issue where the web interface did not populate the Virtual System Name column (**Monitor** > **Manage Custom Reports <monitor-name>** > **Run Now**) when you generated reports from the application statistics database.
|
||||||
|
|
||||||
|
## PAN-113229
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances in an HA active/passive configuration where the passive HA peer displayed an out-of-sync shared policy status when you edited the Device Group.
|
||||||
|
|
||||||
|
## PAN-113185
|
||||||
|
|
||||||
|
Fixed an issue where the passive firewall in an HA active/passive configuration was processing traffic.
|
||||||
|
|
||||||
|
## PAN-113096
|
||||||
|
|
||||||
|
Fixed an issue where incorrect serial numbers were generated when you created VM-Series firewalls on AWS and swapped the interface with the mgmt-interface-swap=enable CLI command.
|
||||||
|
|
||||||
|
## PAN-112988
|
||||||
|
|
||||||
|
Fixed an issue where a process (useridd) leaked memory, which caused the firewall to drop traffic and display the following error message: Out-of-memory condition detected, kill process.
|
||||||
|
|
||||||
|
## PAN-112972
|
||||||
|
|
||||||
|
Fixed an issue where scheduled reports were not generated as expected when you added groups in a query builder.
|
||||||
|
|
||||||
|
## PAN-112566
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect Client was unable to download files from a web interface and sessions went into DISCARD state and displayed the following message: Packet dropped, control plane service not allowed.
|
||||||
|
|
||||||
|
## PAN-112529
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall incorrectly received several alerts.
|
||||||
|
|
||||||
|
## PAN-112467
|
||||||
|
|
||||||
|
Fixed an issue where obsolete IPv6 Neighbor Discovery (ND) entries did not clear as expected, which caused the IPv6 table to reach full capacity and caused new IPv6 ND entries to fail.
|
||||||
|
|
||||||
|
## PAN-112308
|
||||||
|
|
||||||
|
Fixed an issue where hardware security module (HSM) accounts were locked out after three attempts when you ran the show hsm ha-status CLI command.
|
||||||
|
|
||||||
|
## PAN-112293
|
||||||
|
|
||||||
|
Fixed an issue where the connection between the firewall and Log Collector flapped.
|
||||||
|
|
||||||
|
## PAN-112016
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where the physical port counters on the dataplane interfaces did not increase on KVM when you disabled DPDK.
|
||||||
|
|
||||||
|
## PAN-111660
|
||||||
|
|
||||||
|
Fixed an issue where an incorrect SSH key initialization caused a process (pan_comm) to stop responding every 15 minutes when you configured an SSH proxy on the firewall.
|
||||||
|
|
||||||
|
## PAN-111380
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200, PA-5200, and PA-7000 Series firewalls with 100Gbps cards only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the show qos interface ae1 throughput 0 CLI command incorrectly displayed the active data stream only and QoS was not working as expected on the first subinterface.
|
||||||
|
|
||||||
|
## PAN-110990
|
||||||
|
|
||||||
|
Fixed an issue where a logical operation not configured with receive_time in the traffic log filter did not respond as expected.
|
||||||
|
|
||||||
|
## PAN-110960
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where commits failed when you configured an address group object in the Include List (**Network** > **Zone** > **<zone-name>** > **Include List**).
|
||||||
|
|
||||||
|
## PAN-110839
|
||||||
|
|
||||||
|
Fixed a rare issue where a commit pushed from Panorama failed, which caused a process (routed) to stop responding.
|
||||||
|
|
||||||
|
## PAN-110304
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted due to a callback function, which caused a deadlock condition.
|
||||||
|
|
||||||
|
## PAN-110234
|
||||||
|
|
||||||
|
Fixed an issue where administrators with a Superuser (read-only) role was able to initiate a commit through the CLI.
|
||||||
|
|
||||||
|
## PAN-109861
|
||||||
|
|
||||||
|
Fixed an issue where BGP route attributes were processed from BGP updates, which caused the firewall to stop responding.
|
||||||
|
|
||||||
|
## PAN-109457
|
||||||
|
|
||||||
|
Fixed an issue where the firewall duplicated address objects when you imported a configuration to Panorama.
|
||||||
|
|
||||||
|
## PAN-109270
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall processed a high rate of packets.
|
||||||
|
|
||||||
|
## PAN-107786
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to import variable CSV files when the external gateway was configured with a source region of **Any**.
|
||||||
|
|
||||||
|
## PAN-107779
|
||||||
|
|
||||||
|
Fixed an issue where Wildfire® signature version information was no longer displayed after you activated a GlobalProtect client.
|
||||||
|
|
||||||
|
## PAN-106628
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not generate a system log when the firewall detected a RAM issue.
|
||||||
|
|
||||||
|
## PAN-106449
|
||||||
|
|
||||||
|
Fixed an issue when you connected to an internal GlobalProtect gateway on a firewall in an HA active/passive configuration and authenticated with multi-factor authentication (MFA) to access a resource where the first and second authentication factors succeeded but you would not be redirected to the actual resource.
|
||||||
|
|
||||||
|
## PAN-105286
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not record email header information in Data Filtering logs when you triggered a test mail that contained a data leak prevention (DLP) pattern.
|
||||||
|
|
||||||
|
## PAN-104808
|
||||||
|
|
||||||
|
Fixed an issue where scheduled SaaS reports generated and emailed empty PDF reports.
|
||||||
|
|
||||||
|
## PAN-104454
|
||||||
|
|
||||||
|
Fixed a memory leak issue with the User-ID (useridd) process when you enabled VM Monitoring.
|
||||||
|
|
||||||
|
## PAN-103865
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not detect user credentials when the number of users exceeded 60,000. To leverage this fix, you must upgrade Windows agents to User-ID agent 8.1.11 or a later User-ID agent 8.1 release.
|
||||||
|
|
||||||
|
## PAN-104251
|
||||||
|
|
||||||
|
Fixed an issue where the syslog server TCP keep-alive parameter caused the connection to unexpectedly age out.
|
||||||
|
|
||||||
|
## PAN-101613
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-800 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent congestion condition caused by paused frames on firewalls where flow control was enabled on adjacent firewalls. To leverage this fix, run the set system setting hol-system enable CLI command to enable head-of-line (HOL) system mode.
|
||||||
|
|
||||||
|
## PAN-98974
|
||||||
|
|
||||||
|
Fixed an issue where the export function (**Panorama** > **Managed Devices** > **Summary** > **Manage**) was not available for managed devices.
|
||||||
|
|
||||||
|
## PAN-50031
|
||||||
|
|
||||||
|
Fixed an issue where the show wildfire local statistics CLI command incorrectly returned samples pending analysis when there were no actual samples pending.
|
||||||
@@ -0,0 +1,515 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.12
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-133443
|
||||||
|
|
||||||
|
Fixed an issue where an XML API call incorrectly masked the response, which prevented role based administrators from running the response.
|
||||||
|
|
||||||
|
## PAN-132501
|
||||||
|
|
||||||
|
Fixed an issue where after you switched the **Context** from Panorama™ to a firewall, the DESTINATION ZONE (**Policies** > **Security** > **<policy-name>** > **Destination**) incorrectly displayed none.
|
||||||
|
|
||||||
|
## PAN-132104
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the <show><object><registered-ip></registered-ip></object></show> XML API call did not retrieve more than 500 entries.
|
||||||
|
|
||||||
|
## PAN-131054
|
||||||
|
|
||||||
|
Fixed an issue where the DNS packet parser incorrectly processed DNS packet headers when the QD count was 0. With this fix, the DNS packet parser aborts processing when QD!= 1.
|
||||||
|
|
||||||
|
## PAN-130073
|
||||||
|
|
||||||
|
Fixed an issue where a large number (65,000) of GlobalProtect™ user connections caused a process (sslvpn) to stop responding after you upgraded from PAN-OS® 8.1.10 to PAN-OS 8.1.11.
|
||||||
|
|
||||||
|
## PAN-129504
|
||||||
|
|
||||||
|
Fixed an issue where an incorrect commit job in the queue caused the FQDN to display Not resolved after you performed a commit.
|
||||||
|
|
||||||
|
## PAN-128324
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where internal path monitoring failures occurred due to either a buffer leak or buffer corruption.
|
||||||
|
|
||||||
|
## PAN-128269
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5250, PA-5260, and PA-5280 firewalls with 100GB AOC cables only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where after you upgraded the first peer in a high availability (HA) configuration to PAN-OS 8.1.9-h4 or a later] release, the High Speed Chassis Interconnect (HSCI) port did not come up due to an FEC mismatch until after you finished upgrading the second peer.
|
||||||
|
|
||||||
|
## PAN-127649
|
||||||
|
|
||||||
|
Fixed an issue where a purge script stopped responding, which caused a process (logrcvr) to discard incoming logs.
|
||||||
|
|
||||||
|
## PAN-127089
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the default route did not redistribute to an OSPF Not-So-Stubby Area (NSSA).
|
||||||
|
|
||||||
|
## PAN-127055
|
||||||
|
|
||||||
|
Fixed an issue on a VM-Series firewall deployed in Microsoft Azure where the CPU ID and serial number changed after you upgraded from PAN-OS 8.0.13 to PAN-OS 8.1.9-h4.
|
||||||
|
|
||||||
|
## PAN-126921
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where internal path monitoring failed when the firewall processed corrupt packets.
|
||||||
|
|
||||||
|
## PAN-126627
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) stopped responding due to a NULL pointer exception while cleaning up SSL proxy sessions previously configured for GlobalProtect.
|
||||||
|
|
||||||
|
## PAN-126534
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.1.10 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the data from Security policies did not export as expected.
|
||||||
|
|
||||||
|
## PAN-126283
|
||||||
|
|
||||||
|
Fixed an intermittent issue where after you configured **Cache EDNS Responses** (**Network** > **DNS Proxy** > **<DNS Proxy-name>** > **Advanced**) a process (dnsproxy) stopped responding.
|
||||||
|
|
||||||
|
## PAN-126159
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not match the Security policy when you configured the match condition to a shared local group.
|
||||||
|
|
||||||
|
## PAN-125898
|
||||||
|
|
||||||
|
Fixed an issue where a process (openssl) caused higher than expected management CPU usage due to the incompletion of the Online Certificate Status Protocol (OCSP) during the logging service certificate validation.
|
||||||
|
|
||||||
|
## PAN-125833
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/passive configuration where a daemon (routed) did not receive the updated interface status after an HA failover, which caused routes to remain in the routing and FIB tables.
|
||||||
|
|
||||||
|
## PAN-125793
|
||||||
|
|
||||||
|
Fixed an issue where multiple No valid URL filtering license warning messages were generated during a commit due to an expired URL filtering license. With this fix, the warning messages are grouped into a single message per virtual system (vsys).
|
||||||
|
|
||||||
|
## PAN-125746
|
||||||
|
|
||||||
|
Fixed an issue where commits failed and displayed the following error message: priority is invalid when you configured the GlobalProtect priority to **None**.
|
||||||
|
|
||||||
|
## PAN-125515
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where the firewall dropped all traffic traversing from the dataplane to the management plane.
|
||||||
|
|
||||||
|
## PAN-125478
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/passive configuration where the route to the passive firewall dropped during a failover.
|
||||||
|
|
||||||
|
## PAN-125302
|
||||||
|
|
||||||
|
Fixed an issue where the real-time clock (RTC) battery voltage exceeded the maximum threshold and triggered alerts in the system log.
|
||||||
|
|
||||||
|
## PAN-125018
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where after you configure the firewall with an API call commits took longer than expected.
|
||||||
|
|
||||||
|
## PAN-124890
|
||||||
|
|
||||||
|
Fixed a configuration lock issue where you were unable to log in after you upgraded from PAN-OS 8.1.6 to PAN-OS 8.1.9.
|
||||||
|
|
||||||
|
## PAN-124882
|
||||||
|
|
||||||
|
Fixed an issue where traffic logs that contained incorrect Security policies were generated during an active commit process when the Security policies were being added or removed.
|
||||||
|
|
||||||
|
## PAN-124630
|
||||||
|
|
||||||
|
Fixed an issue where new logs were not ingested due to a buffer exhaustion condition caused by invalid messages incorrectly handled by elastic search.
|
||||||
|
|
||||||
|
## PAN-124593
|
||||||
|
|
||||||
|
A fix was made to address a missing XML validation vulnerability in the PAN-OS web interface ([CVE-2020-1975](https://security.paloaltonetworks.com/CVE-2020-1975)).
|
||||||
|
|
||||||
|
## PAN-124435
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped pre-VLAN spanning tree (PVST+) packets from the virtual wire interface when you executed the set session rewrite-pvst-pvid yes CLI command.
|
||||||
|
|
||||||
|
## PAN-123661
|
||||||
|
|
||||||
|
A fix was made to address an authentication bypass vulnerability in the Panorama context switching feature ([CVE-2020-2018](https://security.paloaltonetworks.com/CVE-2020-2018)).
|
||||||
|
|
||||||
|
## PAN-123322
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls running PAN-OS 8.1.11 only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a process (all_pktproc) stopped responding due to a Work Query Entry (WQE) corruption that was caused by duplicate child sessions.
|
||||||
|
|
||||||
|
## PAN-123306
|
||||||
|
|
||||||
|
Fixed an issue where the **Dashboard** did not display the release dates for Application Version, Threat Version, and Antivirus Version.
|
||||||
|
|
||||||
|
## PAN-123220
|
||||||
|
|
||||||
|
Fixed an issue on a firewall running snmpwalk where 100GB interfaces were incorrectly displayed as 1GB.
|
||||||
|
|
||||||
|
## PAN-123190
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) restarted multiple times and caused the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-123167
|
||||||
|
|
||||||
|
Fixed an issue where a process (mprelay) stopped responding.
|
||||||
|
|
||||||
|
## PAN-122804
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the firewall stopped forwarding logs to Cortex Data Lake after you upgraded the cloud services plugin to 1.4.
|
||||||
|
|
||||||
|
## PAN-122788
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly logged target filenames when an antivirus signature was triggered over a Server Message Block (SMB) protocol.
|
||||||
|
|
||||||
|
## PAN-122779
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not respond to TCP DNS requests when the firewall acted as a DNS proxy.
|
||||||
|
|
||||||
|
## PAN-122455
|
||||||
|
|
||||||
|
Fixed an issue where the DHCP server incorrectly processed bootp unicast flag requests.
|
||||||
|
|
||||||
|
## PAN-122311
|
||||||
|
|
||||||
|
Fixed an issue where parent sessions were dropped while installing a duplicate predict session.
|
||||||
|
|
||||||
|
## PAN-122181
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series and PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not capture inbound Encapsulating Security Payload (ESP) protocol 50 packets at the receive stage.
|
||||||
|
|
||||||
|
## PAN-121917
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-800 Series and PA-220 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the hrProcessorLoad.2 OID displayed incorrect values.
|
||||||
|
|
||||||
|
## PAN-121609
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls using PA-7000-20G-NPC cards only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall restarted due to an internal path monitoring heartbeat failure during periods of more than expected traffic load.
|
||||||
|
|
||||||
|
## PAN-121484
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane sent positive acknowledgments to predict-status checks from FPP when the corresponding predict was deleted, which caused SIP and RTSP applications to perform less than the expected achievable performance.
|
||||||
|
|
||||||
|
## PAN-121481
|
||||||
|
|
||||||
|
Fixed an issue where downloading the GlobalProtect app software on your GlobalProtect portal took longer than expected.
|
||||||
|
|
||||||
|
## PAN-121472
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the dataplane stopped responding when processing compressed traffic.
|
||||||
|
|
||||||
|
## PAN-120986
|
||||||
|
|
||||||
|
Fixed an issue where a process (routed) stopped responding when you configured virtual interfaces.
|
||||||
|
|
||||||
|
## PAN-120965
|
||||||
|
|
||||||
|
Fixed an issue where certificate revocation list (CRL) and Online Certificate Status Protocol (OCSP) checks did not respond as expected when you configured **Block session if certificate status is unknown**.
|
||||||
|
|
||||||
|
## PAN-120900
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/passive configuration where after you submitted a host information profile (HIP) report a duplicate User-ID™ log was generated on the passive firewall.
|
||||||
|
|
||||||
|
## PAN-120893
|
||||||
|
|
||||||
|
Fixed an issue where the Security Parameter Index (SPI) size was incorrectly set in the IKE Phase 2 packet when you configured **commit-bit** on the neighboring device, which caused IKE negotiations to fail on the neighboring device.
|
||||||
|
|
||||||
|
## PAN-120701
|
||||||
|
|
||||||
|
Fixed an issue where URL filtering blocked web traffic by the security policy that did not have URL filtering enabled.
|
||||||
|
|
||||||
|
## PAN-120545
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where the ager ran faster than expected, which prematurely caused the master key to expire.
|
||||||
|
|
||||||
|
## PAN-120397
|
||||||
|
|
||||||
|
A fix was made to address an external control of path and data vulnerability in the Palo Alto Networks Panorama XSLT processing logic ([CVE-2020-2001](https://security.paloaltonetworks.com/CVE-2020-2001)).
|
||||||
|
|
||||||
|
## PAN-120351
|
||||||
|
|
||||||
|
Fixed an issue where the firewall caused unnecessary fragmentation when traffic and tunnel were content inspected, which caused retransmission and slowed response time.
|
||||||
|
|
||||||
|
## PAN-120300
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to view DHCP leases from the web interface or through the show dhcp server lease interface all CLI command due to the request taking longer than expected, which resulted in a time out.
|
||||||
|
|
||||||
|
## PAN-120106
|
||||||
|
|
||||||
|
Fixed an issue where Panorama did not send correlation events and logs to the syslog server after you upgraded the firewall from PAN-OS 8.0.9 to PAN-OS 8.1.7.
|
||||||
|
|
||||||
|
## PAN-120005
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly forwarded incomplete and corrupted files through the Server Message Block (SMB) protocol to WildFire.
|
||||||
|
|
||||||
|
## PAN-119950
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where a process (flow_ctrl) received and restarted due to a malformed ICMPv6 neighbor advertisement packet.
|
||||||
|
|
||||||
|
## PAN-119822
|
||||||
|
|
||||||
|
Fixed an issue where you were not redirected to the application URL after authentication.
|
||||||
|
|
||||||
|
## PAN-119820
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly calculated the TCP segment size when performing forward proxy decryption.
|
||||||
|
|
||||||
|
## PAN-119819
|
||||||
|
|
||||||
|
Fixed an issue where **Discover** (**Device** > **User Identification** > **User Mapping** > **Server Monitoring**) stopped responding after you configured a DNS proxy.
|
||||||
|
|
||||||
|
## PAN-119818
|
||||||
|
|
||||||
|
Fixed an issue where corrupt logs caused buffered log forwarding to stop responding.
|
||||||
|
|
||||||
|
## PAN-119550
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where communication between two processes (mgmtsrvr and logd) stopped responding.
|
||||||
|
|
||||||
|
## PAN-119452
|
||||||
|
|
||||||
|
An enhancement was made to improve subsequent loading times of device groups after the first load.
|
||||||
|
|
||||||
|
## PAN-119349
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where custom reports from the User-ID log displayed the incorrect receive date.
|
||||||
|
|
||||||
|
## PAN-119343
|
||||||
|
|
||||||
|
Fixed an issue where a daemon (dnsproxy) incorrectly handled TCP requests, which caused the daemon (dnsproxy) to stop responding.
|
||||||
|
|
||||||
|
## PAN-119185
|
||||||
|
|
||||||
|
Fixed an issue where a process (panio) caused more than expected CPU consumption.
|
||||||
|
|
||||||
|
## PAN-119047
|
||||||
|
|
||||||
|
Fixed an issue where local user group names that contained upper case characters were not converted to lower case characters prior to encoding, which caused the firewall not to load user groups names with upper case characters.
|
||||||
|
|
||||||
|
## PAN-118851
|
||||||
|
|
||||||
|
Fixed an issue where the BGP Conditional Advertisement suppress condition was not met, which caused the **Conditional Adv** (**Network** > **Virtual Routers** > **<router-name>** > **BGP**) not to apply the NEXT HOPS prefix range.
|
||||||
|
|
||||||
|
## PAN-118777
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in a high availability (HA) active/active configuration where larger than expected packets sizes were silently dropped when traversing through an HA3 link in an asymmetric network.
|
||||||
|
|
||||||
|
## PAN-118762
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect portal used an outdated jQuery library.
|
||||||
|
|
||||||
|
## PAN-118436
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where applications using the GlobalProtect Clientless VPN did not respond when the Clientless VPN used a VLAN interface.
|
||||||
|
|
||||||
|
## PAN-118430
|
||||||
|
|
||||||
|
Fixed an issue where pushed template configurations were overridden when you made a configuration change in the Master Key **Lifetime** (**Device** > **Master Key and Diagnostic** > **Edit**) field.
|
||||||
|
|
||||||
|
## PAN-118413
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the show system logd-quota CLI command did not display the Session log storage Quotas as expected.
|
||||||
|
|
||||||
|
## PAN-118259
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to generate WildFire analysis reports in the WildFire Submissions log when you configured **Proxy Server** (**Device** > **Setup** > **Services** > **Global**).
|
||||||
|
|
||||||
|
## PAN-118249
|
||||||
|
|
||||||
|
Fixed an issue where traffic logs and URL Filtering logs did not display the URL for decrypted traffic.
|
||||||
|
|
||||||
|
## PAN-118207
|
||||||
|
|
||||||
|
Fixed an issue where the Security Assertion Markup Language (SAML) for GlobalProtect did not respond as expected when you configured the IdP certificate as **None** on the SAML IdP server profile.
|
||||||
|
|
||||||
|
## PAN-118108
|
||||||
|
|
||||||
|
Fixed an issue where an API call against a Panorama management server, which triggered the request analyze-shared-policy command caused Panorama to reboot after you executed the command.
|
||||||
|
|
||||||
|
## PAN-118090
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where **User Activity Report** (**Monitor** > **PDF Reports**) did not generate reports as expected.
|
||||||
|
|
||||||
|
## PAN-118050
|
||||||
|
|
||||||
|
Fixed an issue where some packets had incorrect timestamps in the transmit stage during packet capture.
|
||||||
|
|
||||||
|
## PAN-117987
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not exclude video traffic from the GlobalProtect tunnel when you configured **Exclude video traffic from the tunnel (Windows and macOS only)** (**Network** > **GlobalProtect** > **Gateways** > **<gateway-name>** > **Agent** > **Video Traffic**).
|
||||||
|
|
||||||
|
## PAN-117969
|
||||||
|
|
||||||
|
An enhancement was made to enable administrators to select signature and digest algorithms for outgoing Security Assertion Markup Language (SAML) messages through a CLI command.
|
||||||
|
|
||||||
|
## PAN-117774
|
||||||
|
|
||||||
|
Fixed an Issue where the dataplane stopped responding due to an incorrect parsing of cookies for GlobalProtect Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-117736
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/active configuration where virtual MAC addresses pushed from Panorama were overridden on the local firewall.
|
||||||
|
|
||||||
|
## PAN-117463
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not release the default DHCP route when a new IP address was obtained on a DHCP configured interface.
|
||||||
|
|
||||||
|
## PAN-117446
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect authentication failed when you used the domain in the group mapping and a User Principle Name (UPN) format for authentication.
|
||||||
|
|
||||||
|
## PAN-117276
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in a high availability (HA) active/active configuration where the names of the virtual routers were pushed from the active-primary firewall to the active-secondary firewall when you sync the configuration, which caused schema verification to stop responding when you do a local commit on the active-secondary firewall.
|
||||||
|
|
||||||
|
## PAN-117251
|
||||||
|
|
||||||
|
Fixed an issue where vsysadmins were unable to view the locks on all the virtual systems they were assigned to. To view the locks in CLI run the new show commit-locks vsys and show config-locks vsys CLI commands.
|
||||||
|
|
||||||
|
## PAN-117167
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) exceeded the memory limit and stopped responding.
|
||||||
|
|
||||||
|
## PAN-117068
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where memory utilization increased more than expected when you deleted several rules with an XML API delete command.
|
||||||
|
|
||||||
|
## PAN-116889
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to establish an SSH session through a CLI command using a Diffie-Hellman (DH) algorithm.
|
||||||
|
|
||||||
|
## PAN-116634
|
||||||
|
|
||||||
|
Fixed an issue where the date in the GlobalProtect HTTP header was incorrectly set to a random date instead of a zero ( 0 ), which negatively and falsely impacted security scorecard ratings.
|
||||||
|
|
||||||
|
## PAN-116615
|
||||||
|
|
||||||
|
Fixed an issue where authentication failed for newly added groups in the authentication profile Allow List.
|
||||||
|
|
||||||
|
## PAN-116355
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where an HA1 heartbeat backup connection flap occurred and displayed the following error message: ha_ping_send/No buffer space available.
|
||||||
|
|
||||||
|
## PAN-116173
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls using PA-7000-20G-NPC or PA-7000-20GQ-NPC cards only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue on a firewall in an HA active/passive configuration where traffic interruptions occurred until you triggered a manual failover.
|
||||||
|
|
||||||
|
## PAN-116100
|
||||||
|
|
||||||
|
Fixed an issue where a process (mprelay) stopped responding and invoked an out-of-memory (OOM) killer condition and displayed the following error messages: tcam full and pan_plfm_fe_cp_arp_delete.
|
||||||
|
|
||||||
|
## PAN-116061
|
||||||
|
|
||||||
|
Fixed an issue where traffic traversing through an IPSec tunnel did not use the default maximum interface bandwidth, which caused the traffic to traverse through the IPSec tunnel with latency.
|
||||||
|
|
||||||
|
## PAN-115505
|
||||||
|
|
||||||
|
Fixed an issue where more than expected re-connection attempts to Cortex Data Lake caused the management plane CPU to spike and caused a process (mgmtsrvr) to stop responding.
|
||||||
|
|
||||||
|
## PAN-115238
|
||||||
|
|
||||||
|
Fixed an issue where SSL renegotiation sessions incorrectly identified URL categories.
|
||||||
|
|
||||||
|
## PAN-115110
|
||||||
|
|
||||||
|
An enhancement was made to enable you to configure syslog parameters through the CLI debug command. To view the available parameters and change the configurations, run the debug syslogng-params settings CLI command and perform a commit force to apply the edits.
|
||||||
|
|
||||||
|
## PAN-115018
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to access the CPU information and caused the CPU frequency to set to 0, which resulted in a divide by zero error and caused a process (devsrvr) to stop responding.
|
||||||
|
|
||||||
|
## PAN-114438
|
||||||
|
|
||||||
|
Fixed an issue where the system log incorrectly reported intermittent certificate revocation list (CRL) fetches as successful even though the fetches were not successful.
|
||||||
|
|
||||||
|
## PAN-112145
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a process (useridd) incorrectly reported successful Ops commands and did not download Dynamic Address Group updates, which prevented virtual machines from updating Dynamic Address Groups.
|
||||||
|
|
||||||
|
## PAN-111650
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding when another process (masterd) sent a signal interruption after you upgraded from a PAN-OS 8.0 release to a PAN-OS 8.1 release.
|
||||||
|
|
||||||
|
## PAN-111135
|
||||||
|
|
||||||
|
Fixed an issue where Panorama displayed incorrect device monitoring values (**Panorama** > **Managed Devices** > **Health**) for the firewall.
|
||||||
|
|
||||||
|
## PAN-109406
|
||||||
|
|
||||||
|
Fixed an issue where the firewall restarted when you unplugged the QSFP+ module from the High Speed Chassis Interconnect (HSCI) port.
|
||||||
|
|
||||||
|
## PAN-108373
|
||||||
|
|
||||||
|
Fixed an issue where an application dependency warning incorrectly displayed when you configured **negate-source yes** on a security rule to deny an application.
|
||||||
|
|
||||||
|
## PAN-108012
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where you could not add and generate a certificate as expected.
|
||||||
|
|
||||||
|
## PAN-107864
|
||||||
|
|
||||||
|
Fixed an issue where the Online Certificate Status Protocol (OCSP) check stopped responding when the leaf certificate was sent twice in the OCSP request.
|
||||||
|
|
||||||
|
## PAN-106029
|
||||||
|
|
||||||
|
Fixed an issue where the firewall tried to resolve deleted FQDN address objects after an FQDN refresh.
|
||||||
|
|
||||||
|
## PAN-105866
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/active configuration where ARP entries were removed from a floating IP address on an Ethernet interface when you deleted another floating IP address on the same Ethernet interface.
|
||||||
|
|
||||||
|
## PAN-105763
|
||||||
|
|
||||||
|
An enhancement was made to enable you to set the signing algorithm to sha-1 or sha-256 in the Security Assertion Markup Language (SAML) message on the firewall.
|
||||||
|
|
||||||
|
## PAN-100946
|
||||||
|
|
||||||
|
Fixed an issue where VM-Series firewalls were unable to support the maximum number of tunnel interfaces due to less than expected memory allocation.
|
||||||
|
|
||||||
|
## PAN-98603
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where logs sent by the Endpoint Security Manager (ESM) server were incorrectly ingested.
|
||||||
@@ -0,0 +1,415 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.13
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-136698
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted when the firewall processed a malformed GPRS tunneling protocol (GTP) packet.
|
||||||
|
|
||||||
|
## PAN-135260
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls running PAN-OS 8.1.12 only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the dataplane process (all_pktproc_X) on a Network Processing Card (NPC) restarted when processing IPSec tunnel traffic.
|
||||||
|
|
||||||
|
## PAN-134678
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did not respond when plugged in with a Finisar 100G AOC cable.
|
||||||
|
|
||||||
|
## PAN-133582
|
||||||
|
|
||||||
|
Fixed an issue on the firewalls where some Dynamic Address Groups pushed from Panorama were missing member IP addresses.
|
||||||
|
|
||||||
|
## PAN-133440
|
||||||
|
|
||||||
|
Fixed an issue where fragmented traffic caused high dataplane use and firewall performance issues.
|
||||||
|
|
||||||
|
## PAN-133436
|
||||||
|
|
||||||
|
Introduced the clear url-cache all CLI command to aggressively clear the dataplane URL cache.
|
||||||
|
|
||||||
|
## PAN-133378
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where a process (configd) restarted during a commit using a RADIUS super admin role.
|
||||||
|
|
||||||
|
## PAN-133048
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 and PA-7000 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where traffic was processed asymmetrically when using Internet Protocol (IP) classifiers on virtual wire (vwire) subinterfaces.
|
||||||
|
|
||||||
|
## PAN-133042
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 and PA-7000 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where certain GPRS tunneling protocol (GTP) traffic was dropped even when gtp nodrop was enabled.
|
||||||
|
|
||||||
|
## PAN-131993
|
||||||
|
|
||||||
|
Fixed an issue where a process (reportd) stopped responding while running a log query.
|
||||||
|
|
||||||
|
## PAN-131907
|
||||||
|
|
||||||
|
Fixed an issue where GPRS tunneling protocol (GTP) version 2 handling was unable to handle fully qualified tunnel endpoint IDs (FTEID) coming in reverse order, leading to GTP-C and GTP-U flows with incorrect IP addresses and tunnel endpoint IDs (TEIDs). This caused a GTP stateful inspection failure for further packets on the respective flows.
|
||||||
|
|
||||||
|
## PAN-130773
|
||||||
|
|
||||||
|
Fixed an issue where users saw a page with a random phone number for authentication and could not proceed further in the authentication process when multi-factor authentication (MFA) was configured as the authentication portal.
|
||||||
|
|
||||||
|
## PAN-130640
|
||||||
|
|
||||||
|
Fixed an issue where the management plane CPU was high due to index generation on summary logs.
|
||||||
|
|
||||||
|
## PAN-130573
|
||||||
|
|
||||||
|
Fixed an issue where the software pool for Regex results was depleted and caused connection failures.
|
||||||
|
|
||||||
|
## PAN-130447
|
||||||
|
|
||||||
|
Fixed an issue where offloaded traffic was dropped by the firewall every time there was an explicit commit (**Commit** on the firewall locally or **Commit All Changes** in Panorama) or an implicit commit (Antivirus update, Dynamic Update, or WildFire update, and so on) was performed on the firewall.
|
||||||
|
|
||||||
|
## PAN-130345
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama VM rebooted while filtering for configuration logs when the query value was not one of the predefined string results.
|
||||||
|
|
||||||
|
## PAN-130290
|
||||||
|
|
||||||
|
Fixed an issue where in the web interface, traffic logs did not display the destination zone (**Monitor > Logs > Traffic > To Zone**) for multicast sessions.
|
||||||
|
|
||||||
|
## PAN-130262
|
||||||
|
|
||||||
|
Fixed a rare issue where 200 OK messages were dropped during the offload of traffic for App-ID inspection.
|
||||||
|
|
||||||
|
## PAN-130229
|
||||||
|
|
||||||
|
Fixed an issue on Panorama appliances where you could not change maximum transmission unit (MTU) values from the web interface and displayed the following error message: Malformed Request.
|
||||||
|
|
||||||
|
## PAN-130069
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly interpreted an external dynamic list MineMeld instability error code as an empty external dynamic list.
|
||||||
|
|
||||||
|
## PAN-129658
|
||||||
|
|
||||||
|
Fixed an issue where GTP inspection stopped functioning after unrelated changes in policy and a commit followed by a high availability (HA) failover.
|
||||||
|
|
||||||
|
## PAN-129518
|
||||||
|
|
||||||
|
Fixed an issue where the firewall restarted due to an out-of-memory condition caused by a leak in a process (ikemgr).
|
||||||
|
|
||||||
|
## PAN-129490
|
||||||
|
|
||||||
|
Fixed an issue where CRL/OCSP verifications failed due to requests routing through the management interface even when service route was configured.
|
||||||
|
|
||||||
|
## PAN-128908
|
||||||
|
|
||||||
|
If an admin user password was changed but no commit was performed afterward, the new password did not persist after a reboot. Instead, the admin user could still use the old password to log in, and the calculation of expiry days was incorrect based on the password change timestamp in the database.
|
||||||
|
|
||||||
|
## PAN-128856
|
||||||
|
|
||||||
|
Fixed an issue where the disk usage calculation was getting corrupted and purging logs.
|
||||||
|
|
||||||
|
## PAN-128717
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where after switching context to a managed device, the session idle timeout was not being updated, and the web session timed out even when the administrator was actively working.
|
||||||
|
|
||||||
|
## PAN-128248
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability with a race condition due to an insecure creation of a file in a temporary directory in PAN-OS ([CVE-2020-2016](https://security.paloaltonetworks.com/CVE-2020-2016)).
|
||||||
|
|
||||||
|
## PAN-127087
|
||||||
|
|
||||||
|
Fixed an issue in the firewalls where a push operation (**Commit All Changes**) from Panorama failed on the passive firewall when pushing a large number of security policy additions to both firewalls in an HA pair.
|
||||||
|
|
||||||
|
## PAN-126412
|
||||||
|
|
||||||
|
Fixed an issue where hardware security model (HSM) authentication from the web interface failed if the password contained an ampersand (&).
|
||||||
|
|
||||||
|
## PAN-126278
|
||||||
|
|
||||||
|
Fixed an issue where a burst of VLAN-tagged packets in a congested system caused an overflow and locked up the firewall. The threshold has been increased with this fix.
|
||||||
|
|
||||||
|
## PAN-126202
|
||||||
|
|
||||||
|
Fixed an issue where a process (routed) stopped responding when users accessed the web interface to view the OSPF interface data (**Network > Virtual Routers > More Runtime Stats > OSPF > Interface**) if OSPF MD5 was configured in the OSPF Auth profile.
|
||||||
|
|
||||||
|
## PAN-126069
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where logs couldn't be viewed when an additional log collector was configured in the existing log collector group.
|
||||||
|
|
||||||
|
## PAN-126017
|
||||||
|
|
||||||
|
Fixed an issue where set application dump on rule CLI command did not accept rule names greater than 32 characters despite a stated limit of 63 characters.
|
||||||
|
|
||||||
|
## PAN-125804
|
||||||
|
|
||||||
|
A fix was made to address an issue where an OS command injection vulnerability in the PAN-OS management server allowed authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode ([CVE-2020-2028](https://security.paloaltonetworks.com/CVE-2020-2028)).
|
||||||
|
|
||||||
|
## PAN-125546
|
||||||
|
|
||||||
|
Fixed an issue where a process failed to restart even when the system logs displayed the following message: virtual memory exceeded, restarting.
|
||||||
|
|
||||||
|
## PAN-125306
|
||||||
|
|
||||||
|
Fixed an issue where a Transmission Control Protocol (TCP) connection reuse was incorrectly handled by a high availability (HA) active/active cluster with asymmetric flows.
|
||||||
|
|
||||||
|
## PAN-125243
|
||||||
|
|
||||||
|
Fixed an issue where the VM-Series firewall restarted due to a deadlock condition occurring when processing QoS-enabled L7 traffic.
|
||||||
|
|
||||||
|
## PAN-125194
|
||||||
|
|
||||||
|
Fixed an issue where system startup failed when the collector group was configured with an incorrect serial number of invalid length.
|
||||||
|
|
||||||
|
## PAN-125122
|
||||||
|
|
||||||
|
A fix was made to address a cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS and Panorama that disclosed an authenticated PAN-OS administrator's PAN-OS session cookie ([CVE-2020-2013](https://security.paloaltonetworks.com/CVE-2020-2013)).
|
||||||
|
|
||||||
|
## PAN-125032
|
||||||
|
|
||||||
|
Fixed an issue when **Minimum Password Complexity** was **Enabled** for all local administrators, the setting was also applied to plugin users. This caused API calls from plugin users to fail (HTTP Error code 502) because the password change was not made for the users and authentication failed.
|
||||||
|
|
||||||
|
## PAN-124802
|
||||||
|
|
||||||
|
Fixed an issue where LACP connectivity issues were observed due to high CPU utilization when multiple dataplanes were used.
|
||||||
|
|
||||||
|
## PAN-124621
|
||||||
|
|
||||||
|
A fix was made to address an issue where an OS command injection vulnerability in the PAN-OS web management interface allowed authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS configuration ([CVE-2020-2029](https://security.paloaltonetworks.com/CVE-2020-2029)).
|
||||||
|
|
||||||
|
## PAN-124495
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the task manager showed locally executed jobs but did not show tasks or jobs pushed to managed firewalls.
|
||||||
|
|
||||||
|
## PAN-124428
|
||||||
|
|
||||||
|
Fixed an issue where Address Resolution Protocol (ARP) randomly failed on one of the interfaces for a firewall deployed in the KVM/GCP/ESXi clouds.
|
||||||
|
|
||||||
|
## PAN-124087
|
||||||
|
|
||||||
|
Fixed an issue where GPRS tunneling protocol (GTP) v2 protocol handling was not able to handle the secondary Modify Bearer Request/Response in the GTP-C session.
|
||||||
|
|
||||||
|
## PAN-123858
|
||||||
|
|
||||||
|
Fixed an issue on firewalls where a process (useridd) restarted while processing incorrect ip-user mappings that contained blank usernames from User-ID agents.
|
||||||
|
|
||||||
|
## PAN-123843
|
||||||
|
|
||||||
|
Fixed an issue for Cloud/VM platforms where the tunnels between the log collectors did not come up when a public IP was used for the log collectors in an environment with a Panorama management server and two or more log collectors.
|
||||||
|
|
||||||
|
## PAN-123830
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect™ portal used an outdated getbootstrap version.
|
||||||
|
|
||||||
|
## PAN-123747
|
||||||
|
|
||||||
|
Fixed an issue where App-ID signatures failed to match when there were more than 12 partial App-ID matches within the same session.
|
||||||
|
|
||||||
|
## PAN-123736
|
||||||
|
|
||||||
|
Fixed an issue where Create Session Request message looped internally causing continuous packet inspection and consuming firewall resources.
|
||||||
|
|
||||||
|
## PAN-123391
|
||||||
|
|
||||||
|
A fix was made to address a predictable temporary file vulnerability in PAN-OS ([CVE-2020-1994](https://security.paloaltonetworks.com/CVE-2020-1994)).
|
||||||
|
|
||||||
|
## PAN-123295
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted due to a race condition when a configuration push and a Netflow update occurred simultaneously.
|
||||||
|
|
||||||
|
## PAN-122909
|
||||||
|
|
||||||
|
Fixed an issue on the firewalls where enabling **SSL Forward Proxy** using the hardware security module (HSM) led to intermittent failure while loading random secure websites with the following message: ERR_CERT_INVALID. This occurred mainly with servers presenting ECDSA certificates.
|
||||||
|
|
||||||
|
## PAN-122872
|
||||||
|
|
||||||
|
Fixed an issue where the Aggregate Ethernet (AE) subinterface showed a different status from the AE parent interface.
|
||||||
|
|
||||||
|
## PAN-122565
|
||||||
|
|
||||||
|
Fixed an issue where a log collector with a dynamically assigned IP address could not establish communication between other log collectors.
|
||||||
|
|
||||||
|
## PAN-121827
|
||||||
|
|
||||||
|
Fixed an issue where allow lists and auth profiles in multi-vsys systems would not allow a user to be identified in user groups.Users would show as **Not in allow list** because the multi-vsys (vsys1) was shown as **vsys0**.
|
||||||
|
|
||||||
|
## PAN-121822
|
||||||
|
|
||||||
|
Fixed an issue with certificate authentication where only the topmost certificate was used to validate the client certificate.
|
||||||
|
|
||||||
|
## PAN-121596
|
||||||
|
|
||||||
|
Fixed an issue where the OSPF protocol didn't choose the correct loopback address for the forwarding address in the Not-So-Stubby Area (NSSA).
|
||||||
|
|
||||||
|
## PAN-121319
|
||||||
|
|
||||||
|
A fix was made to address a stack-based buffer overflow vulnerability in the management server component of PAN-OS ([CVE-2020-1990](https://security.paloaltonetworks.com/CVE-2020-1990)).
|
||||||
|
|
||||||
|
## PAN-121258
|
||||||
|
|
||||||
|
Fixed an issue where some SSLv3 session traffic logs showed an Allow action even when the security rule policy had a Deny action when the url-proxy setting was enabled.
|
||||||
|
|
||||||
|
## PAN-121058
|
||||||
|
|
||||||
|
A fix was made to address a DOM-based cross site scripting vulnerability in the PAN-OS and Panorama management web interfaces ([CVE-2020-2017](https://security.paloaltonetworks.com/CVE-2020-2017)).
|
||||||
|
|
||||||
|
## PAN-120726
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly populated the username after the user had been served an Anti-Phishing Continue Page due to credential phishing detection.
|
||||||
|
|
||||||
|
## PAN-120640
|
||||||
|
|
||||||
|
Fixed an issue where ‘show routing bfd‘ related commands triggered a routed memory leak.
|
||||||
|
|
||||||
|
## PAN-120350
|
||||||
|
|
||||||
|
Fixed an issue where an Address Resolution Protocol (ARP) broadcast storm potentially overloaded the Log Processing Card (LPC) and caused the device to reboot.
|
||||||
|
|
||||||
|
## PAN-119810
|
||||||
|
|
||||||
|
A fix was made to address the improper restriction of the XML external entity (XXE) vulnerability in the Palo Alto Networks Panorama management server ([CVE-2020-2012](https://security.paloaltonetworks.com/CVE-2020-2012)).
|
||||||
|
|
||||||
|
## PAN-119173
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5000 and PA-3000 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the passive device in a high availability (HA) pair started processing traffic, which resulted in a packet buffer leak.
|
||||||
|
|
||||||
|
## PAN-118957
|
||||||
|
|
||||||
|
A fix was made to address an authentication bypass spoofing vulnerability in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS ([CVE-2020-2002](https://security.paloaltonetworks.com/CVE-2020-2002)).
|
||||||
|
|
||||||
|
## PAN-118075
|
||||||
|
|
||||||
|
Fixed an issue where the BGP conditional advertisement did not respond as expected, which caused the prefix in the **Advertise Filters** (**Network > Virtual Router > BGP > Conditional Adv**) to be incorrectly advertised.
|
||||||
|
|
||||||
|
## PAN-117479
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability with the Nginx web server included with PAN-OS ([CVE-2017-7529](https://security.paloaltonetworks.com/CVE-2017-7529)).
|
||||||
|
|
||||||
|
## PAN-117108
|
||||||
|
|
||||||
|
Fixed an issue on the firewalls where the user mappings populated by the XML API were lost after rebooting.
|
||||||
|
|
||||||
|
## PAN-116842
|
||||||
|
|
||||||
|
Fixed an issue in the firewalls where after enabling a Cortex Data Lake license, if some connections between the firewall and Customer Support Portal server were blocked, the management plane memory utilization would start increasing, leading to multiple process restarts due to an out-of-memory condition.
|
||||||
|
|
||||||
|
## PAN-115562
|
||||||
|
|
||||||
|
Fixed an issue where superuser CLI permissions for role-based administrators did not match superuser privileges.
|
||||||
|
|
||||||
|
## PAN-114648
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where high availability (HA1) hearbeat backup connection flaps occurred due to ping failures caused by unavailability of buffer space when **Heartbeat Backup** was configured (**Device > High Availability > Election Settings**).
|
||||||
|
|
||||||
|
## PAN-114236
|
||||||
|
|
||||||
|
Java Runtime Environment (JRE) was upgraded to 1.8.0_201.
|
||||||
|
|
||||||
|
## PAN-112899
|
||||||
|
|
||||||
|
Fixed an issue where the content update failed due to the appweb process periodically restarting.
|
||||||
|
|
||||||
|
## PAN-111636
|
||||||
|
|
||||||
|
A fix was made to address OpenSSH issues ([PAN-SA-2020-0002](https://security.paloaltonetworks.com/PAN-SA-2020-0002) / CVE-2018-20685, CVE-2019-6109, and CVE-2019-6111).
|
||||||
|
|
||||||
|
## PAN-111061
|
||||||
|
|
||||||
|
A fix was made to upgrade OpenSSH software included with PAN-OS ([PAN-SA-2020-0005](https://security.paloaltonetworks.com/PAN-SA-2020-0005) / CVE-2016-10012).
|
||||||
|
|
||||||
|
## PAN-109808
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama API where exporting packet capture (pcap) using the XML API failed, and the web interface displayed the following error message: session id is missing. For Panorama, you can specify either the serial number or both the device_name and sessionid.
|
||||||
|
|
||||||
|
## PAN-109767
|
||||||
|
|
||||||
|
Fixed an issue where high availability (HA) sync would fail due to a large core being enabled on one peer.
|
||||||
|
|
||||||
|
## PAN-108992
|
||||||
|
|
||||||
|
A fix was made to address an improper authorization vulnerability in PAN-OS ([CVE-2020-1998](https://security.paloaltonetworks.com/CVE-2020-1998)).
|
||||||
|
|
||||||
|
## PAN-108356
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where progress stopped on a commit if there was a missing device group.
|
||||||
|
|
||||||
|
## PAN-107650
|
||||||
|
|
||||||
|
Fixed an isolated issue that caused a process (configd) to restart due to kernel segmentation fault errors and caused a core file to be generated.
|
||||||
|
|
||||||
|
## PAN-106784
|
||||||
|
|
||||||
|
Fixed an issue to simplify the code in the web interface when changing administrator passwords.
|
||||||
|
|
||||||
|
## PAN-105880
|
||||||
|
|
||||||
|
Fixed an issue where Panorama failed to commit templates, including log correlation configurations, to firewalls that do not support log correlation. **Note:** Correlation is not supported on PA-200, PA-220, PA-500, PA-820, PA-850, and PA-VM platforms.
|
||||||
|
|
||||||
|
## PAN-104701
|
||||||
|
|
||||||
|
Fixed an issue where the dynamic update sync to peer failed when the firewalls were in a high availability (HA) configuration.
|
||||||
|
|
||||||
|
## PAN-103038
|
||||||
|
|
||||||
|
A fix was made to address a predictable temporary filename vulnerability ([CVE-2020-1981](https://security.paloaltonetworks.com/CVE-2020-1981)).
|
||||||
|
|
||||||
|
## PAN-102839
|
||||||
|
|
||||||
|
Fixed an issue where the IPSec tunnel size limit set by the customer was not maintained correctly in the system.
|
||||||
|
|
||||||
|
## PAN-102674
|
||||||
|
|
||||||
|
A fix was made to address a shell command injection vulnerability in the PAN-OS CLI ([CVE-2020-1980](https://security.paloaltonetworks.com/CVE-2020-1980)).
|
||||||
|
|
||||||
|
## PAN-102096
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where first packet processor packet buffer is not allocated with proper alignment, which caused memory corruption.
|
||||||
|
|
||||||
|
## PAN-100734
|
||||||
|
|
||||||
|
A fix was made to address a buffer flow vulnerability in the PAN-OS management interface where authenticated users were able to crash system processes or execute arbitrary code with root privileges ([CVE-2020-2015](https://security.paloaltonetworks.com/CVE-2020-2015)).
|
||||||
|
|
||||||
|
## PAN-99359
|
||||||
|
|
||||||
|
Fixed an issue where the ZIP hardware processing engine stopped processing ZIP-related requests.
|
||||||
|
|
||||||
|
## PAN-97584
|
||||||
|
|
||||||
|
A fix was made to address a format string vulnerability in the PAN-OS log daemon (logd) on Panorama ([CVE-2020-1979](https://security.paloaltonetworks.com/CVE-2020-1979)).
|
||||||
|
|
||||||
|
## PAN-95651
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where incomplete core dump files were generated when the dataplane stopped responding, which made troubleshooting difficult.
|
||||||
|
|
||||||
|
## PAN-74442
|
||||||
|
|
||||||
|
Resolved an issue where after enabling debugs on the dataplane, the debug logs contained information about unrelated traffic.
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.14-h2
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-144251
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.1.14 only
|
||||||
|
```
|
||||||
|
|
||||||
|
(PA-7000 Series firewalls only) Fixed an issue where SSL decryption failed due to memory allocation failure.
|
||||||
|
|
||||||
|
## PAN-142249
|
||||||
|
|
||||||
|
Fixed an issue where WildFire submission reports could not be viewed when the firewall was using the public WildFire cloud.
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.15-h3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-150172
|
||||||
|
|
||||||
|
Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||||
@@ -0,0 +1,299 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.15
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5320
|
||||||
|
|
||||||
|
Fixed an issue where the WF-500 cluster did not synchronize verdicts after successful verdict recheck queries with the WildFire global cloud.
|
||||||
|
|
||||||
|
## WF500-4716
|
||||||
|
|
||||||
|
Fixed an intermittent issue on WildFire appliances where failure to purge old sample information to make room for new samples caused a cluster to be unavailable.
|
||||||
|
|
||||||
|
## PAN-148988
|
||||||
|
|
||||||
|
A fix was made to address a Security Assertion Markup Language (SAML) authentication issue ([CVE-2020-2021](https://security.paloaltonetworks.com/CVE-2020-2021)).
|
||||||
|
|
||||||
|
## PAN-148068
|
||||||
|
|
||||||
|
Fixed an issue where SSL connections were blocked if you enabled decryption with the option to block sessions that have expired certificates. This issue included servers that sent an expired AddTrust certificate authority (CA) in the certificate chain.
|
||||||
|
|
||||||
|
## PAN-144782
|
||||||
|
|
||||||
|
Fixed an issue where a configuration audit created a large number of opresult.out files, which filled up the session/pan/user_tmp directory in opt/pancfg. This caused a slow Panorama response until a device restart was performed or the files were manually deleted from the root of the device.
|
||||||
|
|
||||||
|
## PAN-144479
|
||||||
|
|
||||||
|
Fixed an issue where SNMP objects from the HOST-RESOURCES-MIB returned incorrect values when queried.
|
||||||
|
|
||||||
|
## PAN-144251
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where SSL decryption failed due to memory allocation failure.
|
||||||
|
|
||||||
|
## PAN-143957
|
||||||
|
|
||||||
|
Fixed an issue where, after loading a saved configuration snapshot by API, a custom role-based administrator required Superuser privileges to perform a full commit.
|
||||||
|
|
||||||
|
## PAN-142346
|
||||||
|
|
||||||
|
Fixed an issue where the YARA version caused the WF-500 appliance virtual machine controllers to stop responding.
|
||||||
|
|
||||||
|
## PAN-142249
|
||||||
|
|
||||||
|
Fixed an issue where WildFire submission reports could not be viewed when the firewall was using the public WildFire cloud.
|
||||||
|
|
||||||
|
## PAN-142031
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) failed to restart even when Panorama displayed the following message: virtual memory exceeded, restarting.
|
||||||
|
|
||||||
|
## PAN-145195
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
and PAN-145149
|
||||||
|
```
|
||||||
|
|
||||||
|
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||||
|
|
||||||
|
## PAN-145151
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
and PAN-145149
|
||||||
|
```
|
||||||
|
|
||||||
|
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||||
|
|
||||||
|
## PAN-145150
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
and PAN-145149
|
||||||
|
```
|
||||||
|
|
||||||
|
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||||
|
|
||||||
|
## PAN-141563
|
||||||
|
|
||||||
|
Fixed an issue where Slot 8 path monitoring failure occurred due to a memory buildup in a process (logrcvr) that was caused by slow communication and connection between log forwarding and Cortex Data Lake.
|
||||||
|
|
||||||
|
## PAN-140846
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted during a commit when **Netflow** was enabled.
|
||||||
|
|
||||||
|
## PAN-140386
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall used IP addresses instead of domain names for URL category lookup after upgrading to 9.0.6.
|
||||||
|
|
||||||
|
## PAN-139935
|
||||||
|
|
||||||
|
Fixed an issue in the URL process where a process (devsrvr) stopped responding.
|
||||||
|
|
||||||
|
## PAN-139587
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where high and continuous CPU utilization was seen on dataplanes after IPSec Encapsulating Security Payload (ESP) rekeying occurred for multiple tunnels.
|
||||||
|
|
||||||
|
## PAN-138870
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) restarted and administrators received one of the following error messages: Timed out while getting config lock. Please try again or Please wait while the server reboots... due to a database error.
|
||||||
|
|
||||||
|
## PAN-138813
|
||||||
|
|
||||||
|
Fixed a performance drop issue seen when using API to configure larger sets of objects (more than 25 objects).
|
||||||
|
|
||||||
|
## PAN-138739
|
||||||
|
|
||||||
|
Fixed an issue where, in a high availability (HA) active/active configuration in a virtual wire deployment with asymmetric traffic, decryption did not work for some sites.
|
||||||
|
|
||||||
|
## PAN-138648
|
||||||
|
|
||||||
|
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
|
||||||
|
|
||||||
|
## PAN-137966
|
||||||
|
|
||||||
|
Fixed a configuration lock issue where Panorama timed out due to a process (configd) being unable to read another process (mongod).
|
||||||
|
|
||||||
|
## PAN-137387
|
||||||
|
|
||||||
|
Fixed an issue where URL filtering used the IP address instead of the hostname, which led to incorrect URL categorization.
|
||||||
|
|
||||||
|
## PAN-136649
|
||||||
|
|
||||||
|
Fixed an issue where PA-7000 20GXM and PA-7000 20GQXM Network Processing Cards (NPCs) failed to process some sessions for Layer 7 inspection due to internal maximum threshold value that was not set.
|
||||||
|
|
||||||
|
## PAN-136612
|
||||||
|
|
||||||
|
Fixed an issue where fragmented packets leaked, which caused the depletion of Work Query Entry (WQE) pools.
|
||||||
|
|
||||||
|
## PAN-136608
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where the Security policy **Target** displayed the serial number of the targeted device instead of the hostname.
|
||||||
|
|
||||||
|
## PAN-136390
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series with 100GB NPC only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue during firewall bootup where the following error message: Bootloader upgrade failed, ret 255 appeared when small form-factor pluggable (SFP) modules were installed.
|
||||||
|
|
||||||
|
## PAN-135141
|
||||||
|
|
||||||
|
Fixed an issue where the Log Processing Card (LPC) did not come up intermittently in a fully loaded PA-7000 Series.
|
||||||
|
|
||||||
|
## PAN-135039
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where a memory leak occurred during an HA sync commit.
|
||||||
|
|
||||||
|
## PAN-134309
|
||||||
|
|
||||||
|
Fixed an issue where a process (devsrvr) restarted when it hit the limit of the number of custom patterns available in the allocated memory.
|
||||||
|
|
||||||
|
## PAN-133411
|
||||||
|
|
||||||
|
Fixed an issue where after making configuration changes and selecting **Preview Changes**, a 500 Internal Server Error message displayed due to a memory leak.
|
||||||
|
|
||||||
|
## PAN-132712
|
||||||
|
|
||||||
|
Fixed an issue where scheduled reports did not run on a PA-7000 Series firewall not managed by Panorama after upgrade to 8.1.10 or 9.0.4 and later versions.
|
||||||
|
|
||||||
|
## PAN-132047
|
||||||
|
|
||||||
|
Fixed a rare issue where log forwarding from a PA-7080 firewall to an M-600 appliance appeared to slow or fail due to an elastic search error.
|
||||||
|
|
||||||
|
## PAN-131792
|
||||||
|
|
||||||
|
Fixed an issue where the **Name** log filter (**Monitor > Logs > Traffic**) was not maintained when viewing the **Log Viewer** for a Security policy rule (**Policies > Security**) from the drop-down.
|
||||||
|
|
||||||
|
## PAN-130776
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where Applications and Threats content update deployment failed due to the content version date check.
|
||||||
|
|
||||||
|
## PAN-128195
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where processes (vld) ran on high CPU when the incoming system log rate was 0.
|
||||||
|
|
||||||
|
## PAN-128078
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
|
||||||
|
|
||||||
|
## PAN-127358
|
||||||
|
|
||||||
|
Fixed an issue with a memory leak in a process (configd) where virtual memory exceeded the limit, which caused the process to restart.
|
||||||
|
|
||||||
|
## PAN-127260
|
||||||
|
|
||||||
|
Fixed an issue where the /opt/pancfg partition became full due to a large amount of botnet reports that were not automatically deleted.
|
||||||
|
|
||||||
|
## PAN-126944
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama Template did not allow for **Ethernet Interface Link Speed** configurations greater than 1,000Mbps.
|
||||||
|
|
||||||
|
## PAN-120614
|
||||||
|
|
||||||
|
Fixed an issue where a commit from a Panorama appliance running PAN-OS 9.1 to a managed firewall running PAN-OS 9.0 or earlier failed with the following error message in ms.log: error generating tranform ike-pre-transform.xsl.
|
||||||
|
|
||||||
|
## PAN-120454
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not fail over to the secondary LDAP server when the primary LDAP server was not reachable and the configured LDAP bind timeout was not properly honored when SSL protocol was used.
|
||||||
|
|
||||||
|
## PAN-120113
|
||||||
|
|
||||||
|
Fixed an issue where the **to**, **from**, and **subject** fields did not populate in the threat logs if the fields were out of order.
|
||||||
|
|
||||||
|
## PAN-120105
|
||||||
|
|
||||||
|
Fixed an issue where email header information intermittently was not present in threat logs.
|
||||||
|
|
||||||
|
## PAN-119645
|
||||||
|
|
||||||
|
Fixed an issue where a process (panio) used unnecessary memory and caused an out-of-memory (OOM) condition on the dataplane if the dataplane was already low on memory.
|
||||||
|
|
||||||
|
## PAN-119289
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to query Cortex Data Lake by the serial number filter.
|
||||||
|
|
||||||
|
## PAN-117606
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) crashed while making configuration changes on Panorama.
|
||||||
|
|
||||||
|
## PAN-117487
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding due to a memory corruption issue when acquiring a configuration lock.
|
||||||
|
|
||||||
|
## PAN-117359
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with an AutoFocus license only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where AutoFocus threat intelligence did not display when hovering over source and destination addresses in the logs when you configure a service route or proxy.
|
||||||
|
|
||||||
|
## PAN-117075
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not process the TLS record in SSL Inbound Inspection as expected, which introduced out-of-order packets in the transmit stage packet capture and affected client performance while accessing HTTP video applications.
|
||||||
|
|
||||||
|
## PAN-116002
|
||||||
|
|
||||||
|
Fixed an issue where an incorrect optimization could cause IP address-to-user mapping to not update within 60 seconds.
|
||||||
|
|
||||||
|
## PAN-115093
|
||||||
|
|
||||||
|
Fixed an issue where the firewall generated excessive logs for content decoder (CTD) errors.
|
||||||
|
|
||||||
|
## PAN-115035
|
||||||
|
|
||||||
|
Fixed a rare issue where **Traffic** logs, **Threat** logs and **URL filtering** logs stopped generating.
|
||||||
|
|
||||||
|
## PAN-112120
|
||||||
|
|
||||||
|
Fixed an issue where threat **Name** field of a threat **Custom Report** displayed the threat ID instead of the threat name.
|
||||||
|
|
||||||
|
## PAN-108929
|
||||||
|
|
||||||
|
Fixed an issue where software deployment failed for managed devices.
|
||||||
|
|
||||||
|
## PAN-106773
|
||||||
|
|
||||||
|
Fixed an issue where Panorama was unable to access api.threatvault.paloaltonetworks.com with the configure proxy option.
|
||||||
|
|
||||||
|
## PAN-106763
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane crashed while freeing up memory due to a corrupted or long certificate field in the handshake.
|
||||||
|
|
||||||
|
## PAN-104368
|
||||||
|
|
||||||
|
Fixed an issue where a daemon (routed) stopped responding when authentication was used for RIP.
|
||||||
|
|
||||||
|
## PAN-103290
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall stopped recording dataplane diagnostic data in dp-monitor.log after a few hours of uptime.
|
||||||
|
|
||||||
|
## PAN-102202
|
||||||
|
|
||||||
|
Fixed an issue where the OSPF summary Link State Advertisement (LSA) for the default 0.0.0.0/0 route were not advertised by the Area Border Router (ABR).
|
||||||
|
|
||||||
|
## PAN-98933
|
||||||
|
|
||||||
|
Fixed an issue on an M-Series appliances in an HA active/passive configuration where the schedules (*Device > Dynamic Updates*) were unresponsive after a failover or restart of Panorama.
|
||||||
|
|
||||||
|
## PAN-98863
|
||||||
|
|
||||||
|
Fixed an issue where a process (routed) restarted when navigating through **OSPF** tabs in **Virtual Routers**.
|
||||||
|
|
||||||
|
## PAN-98628
|
||||||
|
|
||||||
|
Fixed an issue where debug software pprof service <service-name> CLI command did not yield any data.
|
||||||
@@ -0,0 +1,299 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.17
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A security issue has been fixed ([CVE-2021-3064](https://security.paloaltonetworks.com/CVE-2021-3064)).
|
||||||
|
|
||||||
|
## PAN-154181
|
||||||
|
|
||||||
|
Fixed an issue where, on Panorama, context switching to the web interface of a managed firewall running PAN-OS 8.1.16 did not work.
|
||||||
|
|
||||||
|
## PAN-153813
|
||||||
|
|
||||||
|
Fixed an issue where the proxy configuration did not get honored, which caused certificate revocation list (CRL) checks to fail from the firewall.
|
||||||
|
|
||||||
|
## PAN-152285
|
||||||
|
|
||||||
|
Fixed an issue where certain GPRS tunneling protocol (GTP-U) sessions that could not complete installation still occupied the flow table, which led to higher session table usage.
|
||||||
|
|
||||||
|
## PAN-152106
|
||||||
|
|
||||||
|
Fixed an issue where the management plane CPU usage remained high for a longer period of time than expected due to a process (genindex.sh).
|
||||||
|
|
||||||
|
## PAN-151405
|
||||||
|
|
||||||
|
Fixed an issue where administrators were unable to export Security Assertion Markup Language (SAML) metadata files from virtual system (vsys) specific authentication profiles.
|
||||||
|
|
||||||
|
## PAN-151203
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped certain GTPv1 Update PDP Context packets.
|
||||||
|
|
||||||
|
## PAN-151057
|
||||||
|
|
||||||
|
Fixed an issue where upgrading the capacity license on a virtual machine (VM) high availability (HA) pair resulted in both firewalls going into a non-functional state instead of only the higher capacity license firewall.
|
||||||
|
|
||||||
|
## PAN-150750
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall dropped packets when two or more GTP packets on the same GTP tunnel were very close to each other.
|
||||||
|
|
||||||
|
## PAN-150748
|
||||||
|
|
||||||
|
Fixed an issue where the firewall silently dropped GTPv2-C Delete Session Response packets.
|
||||||
|
|
||||||
|
## PAN-150746
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped GTP packets with Delete Bearer messages for EBI 6 if they were received within two seconds of receiving the Delete Bearer messages for EBI 5.
|
||||||
|
|
||||||
|
## PAN-150613
|
||||||
|
|
||||||
|
Fixed an issue that caused a process (mprelay) to stop responding when committing changes in the Netflow Server Profile configuration (**Device > Server Profiles > Netflow**).
|
||||||
|
|
||||||
|
## PAN-149912
|
||||||
|
|
||||||
|
Fixed an issue where FIB entries were removed incorrectly due to miscommunication between internal processes.
|
||||||
|
|
||||||
|
## PAN-149839
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Added CLI commands to enable/disable resource-control groups and CLI commands to set an upper memory limit of 8G on a process (mgmtsrvr). To enable resource-control groups, use debug software resource-control enable and to disable them, use debug software resource-control disable. To set the memory limit, use debug management-server limit-memory enable, and to remove the limit, use debug management-server limit-memory disable. For the memory limit change to take effect, the firewall must be rebooted.
|
||||||
|
|
||||||
|
## PAN-147996
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a buffer overflow issue.
|
||||||
|
|
||||||
|
## PAN-147741
|
||||||
|
|
||||||
|
Fixed an issue where an API call for correlated events did not return any events.
|
||||||
|
|
||||||
|
## PAN-147595
|
||||||
|
|
||||||
|
Fixed an issue where, after a policy commit and session rematch, stream control transmission protocol (SCTP) logs for an existing SCTP session still showed old rule information.
|
||||||
|
|
||||||
|
## PAN-147305
|
||||||
|
|
||||||
|
Fixed an issue where a process (useridd) stopped responding to requests.
|
||||||
|
|
||||||
|
## PAN-146650
|
||||||
|
|
||||||
|
A fix was made to address an authentication bypass vulnerability in the GlobalProtect SSL VPN component of PAN-OS that allowed an attacker to bypass all client certificate checks with an invalid certificate. As a result, the attacker was able to authenticate as any user and gain access to restricted VPN network resources when the gateway or portal was configured to rely only on certificate-based authentication ([CVE-2020-2050](https://security.paloaltonetworks.com/CVE-2020-2050)).
|
||||||
|
|
||||||
|
## PAN-146506
|
||||||
|
|
||||||
|
Fixed an issue where memory usage on a process (useridd) was high, which caused the process to restart on the firewall acting as the User-ID redistribution agent. This issue occurred when multiple clients requested IP address-to-user mappings at the same time.
|
||||||
|
|
||||||
|
## PAN-146284
|
||||||
|
|
||||||
|
Fixed an issue where Application and Threat Content installation failed on the firewall with the following error message: Error: Threat database handler failed.
|
||||||
|
|
||||||
|
## PAN-145823
|
||||||
|
|
||||||
|
Fixed an issue where BGP learned routes were incorrectly populated with a VR error as a next hop.
|
||||||
|
|
||||||
|
## PAN-145133
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability in the PAN-OS signature-based threat detection engine that allowed an attacker to evade threat prevention signatures using specifically crafted TCP packets ([CVE-2020-1999](https://security.paloaltonetworks.com/CVE-2020-1999)).
|
||||||
|
|
||||||
|
## PAN-144919
|
||||||
|
|
||||||
|
Fixed an issue on an M-600 appliance where the Panorama management server stopped receiving new logs from firewalls because delayed log purging caused log storage on the Log Collectors to reach maximum capacity.
|
||||||
|
|
||||||
|
## PAN-144448
|
||||||
|
|
||||||
|
Fixed an issue with the automated correlation engine that caused firewalls to stop generating correlated event logs for the beacon-heuristics object (ID 6005).
|
||||||
|
|
||||||
|
## PAN-143959
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a custom administrator with all rights enabled was not able to display the content of the external dynamic list (EDL) on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-143809
|
||||||
|
|
||||||
|
Fixed an issue where Log Collectors had problems ingesting logs for older days received at a high rate.
|
||||||
|
|
||||||
|
## PAN-143241
|
||||||
|
|
||||||
|
Fixed an issue where the firewall unexpectedly stopped processing traffic to due a buffer allocation failure under the QOS-based buffer allocation method.
|
||||||
|
|
||||||
|
## PAN-141551
|
||||||
|
|
||||||
|
Fixed an issue where SSH service restart management did not take effect in the SSH management server profile.
|
||||||
|
|
||||||
|
## PAN-140883
|
||||||
|
|
||||||
|
Fixed an issue where, after rebooting the firewall, the SNMP object identifier (OID) for TCP connections per second (panVsysActiveTcpCps / .1.3.6.1.4.1.25461.2.1.2.3.9.1.6.1) returned 0 until another OID was pulled. Additionally, after a restart of a daemon (snmpd), if the above OID was called before other OIDs, there was an approximate 10 second delay in populating the data pulled by each OID.
|
||||||
|
|
||||||
|
## PAN-140382
|
||||||
|
|
||||||
|
Fixed an issue where the Host Evasion Threat ID signature did not trigger for the initial session even after the DNS response was received before the session expired.
|
||||||
|
|
||||||
|
## PAN-140375
|
||||||
|
|
||||||
|
Fixed an issue where a process (logrcvr) exited due to a race condition.
|
||||||
|
|
||||||
|
## PAN-140227
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a rare issue where the firewall rebooted due to path monitoring failure on the Log Processing Card (LPC).
|
||||||
|
|
||||||
|
## PAN-140157
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability where the password for a configured system proxy server for a PAN-OS appliance was displayed in cleartext when using the CLI in PAN-OS ([CVE-2020-2048](https://security.paloaltonetworks.com/CVE-2020-2048)).
|
||||||
|
|
||||||
|
## PAN-139991
|
||||||
|
|
||||||
|
Fixed an issue where the web interface and the CLI were inaccessible, which caused the following error message to display on the web interface: Timed out while getting config lock.
|
||||||
|
|
||||||
|
## PAN-139680
|
||||||
|
|
||||||
|
Fixed an issue where dynamic route updates triggered an unintentional refresh of the DHCP client interface IP address, which led to the removal and re-addition of the default route associated with the DHCP client IP address and caused traffic disruption.
|
||||||
|
|
||||||
|
## PAN-139365
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Enhanced latency-sensitive protocols processing. With this fix, the following latency-sensitive control traffic will be prioritized: BGP, Bidirectional Forwarding Detection (BFD), LACP, OSPF, OSPFv3, Protocol Independent Multicast (PIM), and Internet Group Management Protocol (IGMP).
|
||||||
|
|
||||||
|
## PAN-139233
|
||||||
|
|
||||||
|
Fixed an issue where host information profile (HIP) reports failed to show up via the web interface or the CLI.
|
||||||
|
|
||||||
|
## PAN-139136
|
||||||
|
|
||||||
|
Fixed an issue where a large number of groups in group mappings caused a process (useridd) to exit.
|
||||||
|
|
||||||
|
## PAN-138938
|
||||||
|
|
||||||
|
Added an enhancement to reduce the memory usage of a process (logrcvr) to avoid out-of-memory (OOM) conditions on lower-end platforms.
|
||||||
|
|
||||||
|
## PAN-138573
|
||||||
|
|
||||||
|
Fixed an issue where the keyword **[Disabled]** was missing from the disabled policies exported in CSV/PDF format.
|
||||||
|
|
||||||
|
## PAN-137741
|
||||||
|
|
||||||
|
Fixed an issue where the data for a botnet report was deleted before the botnet report was completed.
|
||||||
|
|
||||||
|
## PAN-137656
|
||||||
|
|
||||||
|
Fixed an issue where the show config diff CLI command did not work correctly and produced unexpected output.
|
||||||
|
|
||||||
|
## PAN-135540
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3220 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall generated some core files when generating tech support files
|
||||||
|
|
||||||
|
## PAN-135354
|
||||||
|
|
||||||
|
Fixed an issue where the paths between the control plane and the dataplanes in network processing cards (NPCs) stalled in the dataplane-to-control plane direction due to the Ring Descriptor entries becoming out of sync on each side. This produced unrecoverable data path monitoring failures, which caused the chassis to become nonfunctional.
|
||||||
|
|
||||||
|
## PAN-134226
|
||||||
|
|
||||||
|
Fixed an issue where **AdminStatus** for HA1 and High Speed Chassis Interconnect (HSCI) interfaces were incorrectly reported.
|
||||||
|
|
||||||
|
## PAN-133934
|
||||||
|
|
||||||
|
Fixed an intermittent issue where user-to-IP address mappings were not redistributed to client firewalls.
|
||||||
|
|
||||||
|
## PAN-133388
|
||||||
|
|
||||||
|
Fixed an issue where an HA configuration went out of sync when the HA sync job was queued and processed during an ongoing content installation job on the passive firewall.
|
||||||
|
|
||||||
|
## PAN-130955
|
||||||
|
|
||||||
|
Fixed an issue where templates on the secondary Panorama appliance were out of sync with the primary Panorama appliance due to an empty content-preview node.
|
||||||
|
|
||||||
|
## PAN-130357
|
||||||
|
|
||||||
|
Fixed a memory leak issue where virtual memory used by the SNMP process started to slowly increase when the request was sent with a request-id of 0.
|
||||||
|
|
||||||
|
## PAN-129376
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-800 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue that prevented ports 9-12 from being powered down by hardware after being requested to do so.
|
||||||
|
|
||||||
|
## PAN-128172
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the show system logdb-quota CLI command took more time than expected, which caused the configuration lock to time out.
|
||||||
|
|
||||||
|
## PAN-128048
|
||||||
|
|
||||||
|
Fixed an issue where certificate-based authentication with IKEv2 IPSec tunnels failed to establish with some third-party vendors.
|
||||||
|
|
||||||
|
## PAN-127318
|
||||||
|
|
||||||
|
Fixed an issue where the firewall intermittently dropped DNS A or AAAA queries received over IPSec tunnels due to a session installation failure.
|
||||||
|
|
||||||
|
## PAN-125218
|
||||||
|
|
||||||
|
A fix was made to address an information exposure vulnerability in Panorama that disclosed the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performed a context switch ([CVE-2020-2022](https://security.paloaltonetworks.com/CVE-2020-2022)).
|
||||||
|
|
||||||
|
## PAN-124916
|
||||||
|
|
||||||
|
Added two ciphers for GlobalProtect Portal TLS connections.
|
||||||
|
|
||||||
|
## PAN-124331
|
||||||
|
|
||||||
|
Fixed an issue where the LDAP query took longer than expected to populate in the web interface.
|
||||||
|
|
||||||
|
## PAN-122672
|
||||||
|
|
||||||
|
Fixed an issue where the firewall returned incorrect information about the logging service status when the information was requested through the web interface.
|
||||||
|
|
||||||
|
## PAN-121944
|
||||||
|
|
||||||
|
Fixed an issue where the **Device Connectivity** status was grey on the firewall web interface even when the SSL session to the logging service was successful.
|
||||||
|
|
||||||
|
## PAN-121483
|
||||||
|
|
||||||
|
Fixed an issue where Data Filtering profiles did not generate a packet capture (pcap) for Server Message Block (SMB) when action was set to Alert.
|
||||||
|
|
||||||
|
## PAN-120245
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where WildFire cloud content download failed for content deployment to the WF-500 appliance.
|
||||||
|
|
||||||
|
## PAN-109877
|
||||||
|
|
||||||
|
Fixed an issue where BGP flapped continuously with Jumbo Frames enabled on the firewall.
|
||||||
|
|
||||||
|
## PAN-104254
|
||||||
|
|
||||||
|
Fixed a rare issue where a dataplane process stopped responding.
|
||||||
|
|
||||||
|
## PAN-100254
|
||||||
|
|
||||||
|
Fixed an issue where an incorrect subnet mask was displayed for redistributed routes in the show routing protocol redist all CLI command.
|
||||||
|
|
||||||
|
## PAN-96528
|
||||||
|
|
||||||
|
A fix was made to address a memory corruption vulnerability in the GlobalProtect portal and GlobalProtect gateway that enabled an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges ([CVE-2021-3064](https://security.paloaltonetworks.com/CVE-2021-3064)).
|
||||||
|
|
||||||
|
## PAN-96187
|
||||||
|
|
||||||
|
Fixed an issue where Panorama did not set the preference list on a firewall for a Log Collector that was configured through the CLI.
|
||||||
@@ -0,0 +1,134 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.19
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-161731
|
||||||
|
|
||||||
|
Functionality was added to enable, via the CLI, the removal of key exchange algorithms used by SSH.
|
||||||
|
|
||||||
|
- Use debug system ssh-kex-prune cipher [diffie-hellman-group1-sha1 diffie-hellman-group-exchange-sha1 .. ] to enable removal of specified key exchanges.
|
||||||
|
- Use debug system ssh-kex-prune none to enable addition of key exchanges.
|
||||||
|
|
||||||
|
## PAN-159135
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
|
||||||
|
|
||||||
|
## PAN-158988
|
||||||
|
|
||||||
|
Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented.
|
||||||
|
|
||||||
|
## PAN-158844
|
||||||
|
|
||||||
|
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
|
||||||
|
|
||||||
|
## PAN-158638
|
||||||
|
|
||||||
|
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
|
||||||
|
|
||||||
|
## PAN-156240
|
||||||
|
|
||||||
|
A fix was made to address an issue where a cryptographically weak pseudo-random number (PRNG) was used during authentication to the PAN-OS interface. As a result, attackers with the capability to observe their own authentication secrets over a long duration on the firewall had the ability to impersonate another authenticated web interface administrator’s session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
|
||||||
|
|
||||||
|
## PAN-155009
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where executing the request system bootstrap-usb prepare CLI command returned a server error.
|
||||||
|
|
||||||
|
## PAN-154114
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where secrets in PAN-OS XML API requests were logged in cleartext in the web server logs when the API was used incorrectly ([CVE-2021-3036](https://security.paloaltonetworks.com/CVE-2021-3036)).
|
||||||
|
|
||||||
|
## PAN-153213
|
||||||
|
|
||||||
|
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
|
||||||
|
|
||||||
|
## PAN-152648
|
||||||
|
|
||||||
|
Fixed an issue where multiple all_pktproc processes stopped responding, which caused the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-152098
|
||||||
|
|
||||||
|
Fixed an issue where the Policy Optimizer for some device groups showed incorrect data with a - character in the rule usage column.
|
||||||
|
|
||||||
|
## PAN-151458
|
||||||
|
|
||||||
|
Fixed an issue on firewalls with high availability active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
|
||||||
|
|
||||||
|
## PAN-150998
|
||||||
|
|
||||||
|
Fixed an issue where, when deploying a VM-Series firewall on VMware NSX that had been assigned a serial number that was used by a previously deactivated firewall, the new firewall was deployed in a deactivated or partially deactivated state.
|
||||||
|
|
||||||
|
## PAN-150852
|
||||||
|
|
||||||
|
Fixed an issue with SMTP that occurred when attachment file names were longer than the allocated buffer. If the file name was longer than the buffer and Layer 7 inspection was enabled, the file was dropped, which caused session errors and an email to not be sent.
|
||||||
|
|
||||||
|
## PAN-150798
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
|
||||||
|
|
||||||
|
## PAN-150023
|
||||||
|
|
||||||
|
A fix was made to address an issue where an improper authentication vulnerability enabled a Security Assertion Markup Language (SAML) authenticated user to impersonate any user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
|
||||||
|
|
||||||
|
## PAN-149641
|
||||||
|
|
||||||
|
Fixed an issue where firewalls stopped refreshing IP tag information when configured with the **VM Information Sources** feature with a VMWare vCenter Server.
|
||||||
|
|
||||||
|
## PAN-149339
|
||||||
|
|
||||||
|
Fixed an issue where, when an ECMP route changed, the flow table in the offload engine was not updated.
|
||||||
|
|
||||||
|
## PAN-147783
|
||||||
|
|
||||||
|
Checks were added to help prevent the dataplane from restarting.
|
||||||
|
|
||||||
|
## PAN-147781
|
||||||
|
|
||||||
|
A fix was made to address an issue where an OS command argument injection vulnerability in the PAN-OS web interface enabled an authenticated administrator to read any arbitrary file from the file system ([CVE-2021-3045](https://security.paloaltonetworks.com/CVE-2021-3045)).
|
||||||
|
|
||||||
|
## PAN-147254
|
||||||
|
|
||||||
|
jQuery was updated to 3.5.1.
|
||||||
|
|
||||||
|
## PAN-147221
|
||||||
|
|
||||||
|
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
|
||||||
|
|
||||||
|
## PAN-145733
|
||||||
|
|
||||||
|
Fixed an issue where the SNMP INDEX for panZoneTable on the PAN-COMMON-MIB.my file did not work as expected, which led to entries in panZoneTable not being uniquely identified.
|
||||||
|
|
||||||
|
## PAN-144975
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a high traffic load in a Layer 2 deployment caused SNMP and Panorama health monitoring failures.
|
||||||
|
|
||||||
|
## PAN-136347
|
||||||
|
|
||||||
|
Fixed an issue wherer DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
|
||||||
|
|
||||||
|
## PAN-136073
|
||||||
|
|
||||||
|
Fixed an issue where the High Speed Chassis Interconnect (HSCI) port flapped continuously after an upgrade or reboot.
|
||||||
|
|
||||||
|
## PAN-132035
|
||||||
|
|
||||||
|
Fixed an issue on Panorama appliances in an active/passive HA configuration where a managed firewall generated high priority alerts that it failed to connect to the passive Panorama appliance's User-ID agent server. This issue occurred because the firewall was only able to connect to one Panorama User-ID server at a time, and it connected only to the active Panorama appliance's User-ID server.
|
||||||
|
|
||||||
|
## PAN-131474
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where the connection details for a scheduled configuration export were logged in system logs ([CVE-2021-3037](https://security.paloaltonetworks.com/CVE-2021-3037)).
|
||||||
|
|
||||||
|
## PAN-128042
|
||||||
|
|
||||||
|
Fixed an issue where the dynamic address group failed due to a process (devsrvr) not being synced with another process (useridd).
|
||||||
|
|
||||||
|
## PAN-124579
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_task_3) restarted, which caused the tunnels to reset.
|
||||||
@@ -0,0 +1,383 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-4599
|
||||||
|
|
||||||
|
Fixed an issue on WF-500 appliance clusters where attempts to submit samples for analysis through the WildFire XML API failed with a 499 or 502 error in the HTTP response when the local worker was fully loaded.
|
||||||
|
|
||||||
|
## WF500-4535
|
||||||
|
|
||||||
|
Fixed an issue where the WF-500 appliance couldn’t forward logs over TCP or SSL to a syslog server.
|
||||||
|
|
||||||
|
## WF500-4473
|
||||||
|
|
||||||
|
Fixed an issue where the root partition on the WF-500 appliance reached its maximum storage capacity because the following log files had no size limit and grew continuously: appweb_access.log, trap-access.log, wpc_build_detail.log, rsyncd.log, cluster-mgr.log, and cluster-script.log. With this fix, the appweb_access.log, trap-access.log, and wpc_build_detail.log logs have a limit of 10MB and the WF-500 appliance maintains one rotating backup file for each of these logs to store old data when a log exceeds the limit. Also with this fix, the rsyncd.log, cluster-mgr.log, and cluster-script.log logs have a limit of 5MB and the WF-500 appliance maintains eight rotating backup files for each of these logs.
|
||||||
|
|
||||||
|
## WF500-4397
|
||||||
|
|
||||||
|
Fixed an issue in a WF-500 appliance cluster where the controller backup node was stuck in global-db-service: WaitingforLeaderReady status when you tried to add nodes to the cluster.
|
||||||
|
|
||||||
|
## WF500-4363
|
||||||
|
|
||||||
|
Fixed an issue where firewalls and Panorama management servers couldn’t retrieve reports from a WF-500 appliance due to an interruption in its data migration after you upgraded the appliance from a PAN-OS 7.1 release to a PAN-OS 8.0 or later release. With this fix, you can run the new debug device data-migration show CLI command on the WF-500 appliance after each upgrade to verify data migration finished successfully (output is Migration inMySQL is successful). Don't perform additional upgrades on the WF-500 appliance until the data migration finishes.
|
||||||
|
|
||||||
|
## PAN-95536
|
||||||
|
|
||||||
|
Fixed an issue where Dedicated Log Collectors failed to forward logs to syslog servers.
|
||||||
|
|
||||||
|
## PAN-95504
|
||||||
|
|
||||||
|
Fixed an issue on the firewall and Panorama management server where the web interface became unresponsive because the management server process (mgmtsrvr) restarted after you set its debugging level to debug (through the debug management-server on debug CLI command).
|
||||||
|
|
||||||
|
## PAN-95288
|
||||||
|
|
||||||
|
Fixed an issue where the firewall web interface didn't display System logs (**Monitor** > **Logs** > **System**) after you upgraded to PAN-OS 8.1 and then logged in using an administrative account that existed before the upgrade.
|
||||||
|
|
||||||
|
## PAN-94845
|
||||||
|
|
||||||
|
Fixed an issue where App-ID didn’t recognize GPRS Tunneling Protocol User Plane (GTP-U) in GTP messages on port 2152 when only single-direction message packets arrived (Traffic logs indicated application insufficient-data).
|
||||||
|
|
||||||
|
## PAN-94741
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where characters in the **Secret** string of a TACACS+ server profile changed on the firewall after you pushed the server profile configuration from a template stack (**Device** > **Server Profiles** > **TACACS+**).
|
||||||
|
|
||||||
|
## PAN-94700
|
||||||
|
|
||||||
|
Fixed an issue on the PA-200, PA-220, PA-220R, PA-500, and PA-800 Series firewalls where the GlobalProtect data file installation failed after you upgraded the firewall to PAN-OS 8.1.
|
||||||
|
|
||||||
|
## PAN-94661
|
||||||
|
|
||||||
|
Fixed an issue where the firewall and Panorama management server displayed policy rules in a jumbled order when you scrolled the rule list in the **Policies** tab. The firewall and Panorama also opened the wrong rule for editing when you double-clicked one.
|
||||||
|
|
||||||
|
## PAN-94640
|
||||||
|
|
||||||
|
Fixed an issue where System logs included the following debugging information even though the firewall successfully resolved IP addresses: Failed to resolve domain name:xxx.yyy.zzafter trying all attempts to name servers: A.B.C.D, W.X.Y.Z. With this fix, daemon logs include that debugging information instead of System logs.
|
||||||
|
|
||||||
|
## PAN-94633
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading the firewall to PAN-OS 8.1, LDAP authentication failed if the associated authentication profile had an **Allow List** with entries other than **All** (**Device** > **Authentication Profile**).
|
||||||
|
|
||||||
|
## PAN-94569
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect client authentication failed after you entered domains in upper case characters in the **Allow List** of an authentication profile (**Device** > **Authentication Profile** > **<authentication_profile>** > **Advanced**).
|
||||||
|
|
||||||
|
## PAN-94445
|
||||||
|
|
||||||
|
Fixed an issue where Server Message Block (SMB) sessions were in a discard state with the session end reason resources-unavailable.
|
||||||
|
|
||||||
|
## PAN-94387
|
||||||
|
|
||||||
|
Fixed an issue where the **Check URL Category** link in URL Filtering profiles opened a page that displayed a page not found error instead of opening the web page used to check the PAN-DB URL Filtering database for the URL Filtering category of a URL (**Objects** > **Security Profiles** > **URL Filtering**).
|
||||||
|
|
||||||
|
## PAN-94386
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped packet data protocol (PDP) context update and delete messages that had a tunnel endpoint identifier (TEID) of zero in GPRS Tunneling Protocol (GTP) traffic, and the traffic failed when the dropped messages were valid.
|
||||||
|
|
||||||
|
## PAN-94379
|
||||||
|
|
||||||
|
Fixed an issue in a Panorama deployment with a Collector Group containing multiple Log Collectors where the logging search engine restarted after you changed the SSH keys used for high availability (HA). The disruption to the search engine caused an out-of-memory condition and caused Panorama to display logs and report data from only one Log Collector in the Collector Group.
|
||||||
|
|
||||||
|
## PAN-94317
|
||||||
|
|
||||||
|
Fixed the following LDAP authentication issues:
|
||||||
|
|
||||||
|
- Authentication failed for users who belonged to user groups for which you specified LDAP short names instead of long names in the **Allow List** of an authentication profile (**Device** > **Authentication Profile**).
|
||||||
|
- When performing LDAP lookups based on entries in the **Allow List** of LDAP authentication profiles, the firewall treated unknown group names as usernames.
|
||||||
|
- Authentication failed for users who belonged to multiple groups that you entered in the **Allow List** of different LDAP authentication profiles.
|
||||||
|
|
||||||
|
## PAN-94288
|
||||||
|
|
||||||
|
Fixed an issue where the default view and maximized view of the Application Usage report (**ACC** > **Network Activity**) didn't display matching values when you set the **Time** to **Last 12 Hrs** or a longer period.
|
||||||
|
|
||||||
|
## PAN-94170
|
||||||
|
|
||||||
|
Fixed an issue where GTP traffic failed because the firewall dropped GTP-U echo request packets.
|
||||||
|
|
||||||
|
## PAN-94135
|
||||||
|
|
||||||
|
Fixed an issue where device monitoring did not work on the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-93930
|
||||||
|
|
||||||
|
Fixed an issue on firewalls with SSL decryption configured where the dataplane restarted because the all_pktproc process stopped responding after decryption errors occurred.
|
||||||
|
|
||||||
|
## PAN-93865
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect agent couldn't split tunnel applications based on the destination domain because the **Include Domain** and **Exclude Domain** lists were not pushed to the agent after the user established the GlobalProtect connection (**Network** > **GlobalProtect** > **Gateways** > **gateway>** > **Agent** > **Client Settings** > **client_settings_configuration>** > **Split Tunnel** > **Domain and Application**). In addition, the GlobalProtect agent couldn't include applications in the VPN tunnel based on the application process name because the **Include Client Application Process Name** list was not pushed to the agent after the user established the GlobalProtect connection.
|
||||||
|
|
||||||
|
## PAN-93854
|
||||||
|
|
||||||
|
Fixed an issue where the VM-Series firewall for NSX randomly disrupted traffic due to high CPU usage by the pan_task process.
|
||||||
|
|
||||||
|
## PAN-93640
|
||||||
|
|
||||||
|
Fixed an issue on firewalls where the Log Collector preference list displayed the IP address as unknown for a Panorama Log Collector deployed on AWS if the interface (ethernet1/1 to ethernet1/5) used for sending logs did not have a public IP address configured and you pushed configurations to the Collector Group.
|
||||||
|
|
||||||
|
## PAN-93431
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server failed to export Traffic logs as a CSV file (**Monitor** > **Logs** > **Traffic**) after you set the **Max Rows in CSV Export** to more than 500,000 rows (**Panorama** > **Setup** > **Management** > **Logging and Reporting Settings** > **Log Export and Reporting**).
|
||||||
|
|
||||||
|
## PAN-93430
|
||||||
|
|
||||||
|
Fixed an issue where the firewall web interface didn't display Host Information Profile (HIP) information in HIP Match logs for end users who had Microsoft-supported special characters in their domains or usernames.
|
||||||
|
|
||||||
|
## PAN-93336
|
||||||
|
|
||||||
|
Fixed an issue where the firewall intermittently became unresponsive because the management server process (mgmtsrvr) stopped responding during a commit after you configured policy rules to use external dynamic lists (EDLs).
|
||||||
|
|
||||||
|
## PAN-93106
|
||||||
|
|
||||||
|
Fixed an issue where the Google Chrome browser displayed certificate warnings for self-signed ECDSA certificates that you generated on the firewall.
|
||||||
|
|
||||||
|
## PAN-93090
|
||||||
|
|
||||||
|
Fixed an issue where the GCP DHCP Server took 30-50 seconds to respond to a DHCP discover request, causing DHCP IP assignments to fail.
|
||||||
|
|
||||||
|
## PAN-93089
|
||||||
|
|
||||||
|
A security-related fix was made to prevent denial of service (DoS) to the management web interface (CVE-2018-8715).
|
||||||
|
|
||||||
|
## PAN-93072
|
||||||
|
|
||||||
|
Fixed an issue on hardware firewalls that were decrypting SSL traffic where multiple commits in a short period of time caused the firewalls to become unresponsive.
|
||||||
|
|
||||||
|
## PAN-93052
|
||||||
|
|
||||||
|
Fixed an issue where IPv6 BGP peering persisted (not all BGP routes were withdrawn) after the associated firewall interface went down.
|
||||||
|
|
||||||
|
## PAN-92950
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama appliance experienced memory depletion after allowing you to mistakenly enter the IP address of the appliance when using the set deviceconfig system panorama-server <IP_address> or set log-collector <Log_Collector> deviceconfig system configuration mode CLI commands. These commands enable connectivity with separate appliances. With this fix, the command displays an error message when you specify the IP address of the appliance on which you run the command instead of the appliance to which it must connect. The correct IP address depends on the type of appliance on which you run the command:
|
||||||
|
|
||||||
|
- **Panorama management server** in an HA configuration—Specify the IP address of the Panorama HA peer.
|
||||||
|
- **Dedicated Log Collector**—Specify the IP addresses of the Panorama management servers, where panorama-server specifies the primary HA Panorama (or the only Panorama in a non-HA configuration) and panorama-server-2 specifies the secondary HA Panorama: set log-collector <Log_Collector> deviceconfig system {panorama-server | panorama-server-2} <IP_address>.
|
||||||
|
|
||||||
|
## PAN-92944
|
||||||
|
|
||||||
|
Fixed an issue where the firewall assigned the wrong URL filtering category to traffic that contained a malformed host header. With this fix, the firewall enables the blocking of any traffic with a malformed URL.
|
||||||
|
|
||||||
|
## PAN-92916
|
||||||
|
|
||||||
|
Fixed an issue where firewalls configured for User-ID redistribution failed to redistribute IP address-to-username mappings due to a memory leak.
|
||||||
|
|
||||||
|
## PAN-92858
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server could not generate reports and the ACC page became unresponsive when too many heartbeats were missed because Panorama never cleared reportIDs greater than 65535.
|
||||||
|
|
||||||
|
## PAN-92789
|
||||||
|
|
||||||
|
Fixed an issue where VM-Series firewalls deleted logs by reinitializing the logging disk when the periodic file system integrity check (FSCK) took over 30 minutes during bootup.
|
||||||
|
|
||||||
|
## PAN-92788
|
||||||
|
|
||||||
|
Fixed an issue where the PAN-OS XML API returned the same job IDs for all report jobs on the firewall. With this fix, the PAN-OS XML API returns the correct job ID for each report job.
|
||||||
|
|
||||||
|
## PAN-92738
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where administrators with read-only privileges couldn’t view deployment **Schedules** for content updates (**Panorama** > **Device Deployment** > **Dynamic Updates**).
|
||||||
|
|
||||||
|
## PAN-92678
|
||||||
|
|
||||||
|
Fixed an issue on Panorama management servers in an HA configuration where, after failover caused the secondary HA peer to become active, it failed to deploy scheduled dynamic updates to Log Collectors and firewalls.
|
||||||
|
|
||||||
|
## PAN-92604
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama Collector Group didn’t forward logs to some external servers after you configured multiple server profiles (**Panorama** > **Collector Groups** > **<Collector_Group>** > **Collector Log Forwarding**).
|
||||||
|
|
||||||
|
## PAN-92564
|
||||||
|
|
||||||
|
Fixed an issue where a small percentage of writable third-party SFP transceivers (not purchased from Palo Alto Networks®) stopped working or experienced other issues after you upgraded the firewall to which the SFPs are connected to a PAN-OS 8.1 release. With this fix, you must not reboot the firewall after you download and install the PAN-OS 8.1 base image until after you download and install the PAN-OS 8.1.1 release. For additional details, upgrade considerations, and instructions for upgrading your firewalls, refer to the [PAN-OS 8.1 upgrade information](https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features.html).
|
||||||
|
|
||||||
|
## PAN-92560
|
||||||
|
|
||||||
|
Fixed an issue where SSL Forward Proxy decryption didn’t work after you excluded every predefined **Hostname** from decryption (**Device** > **Certificate Management** > **SSL Decryption Exclusion**).
|
||||||
|
|
||||||
|
## PAN-92487
|
||||||
|
|
||||||
|
Fixed an issue where enabling jumbo frames (**Device** > **Setup** > **Session**) reduced throughput because:
|
||||||
|
|
||||||
|
- The firewalls hardcoded the maximum segment size (TCP MSS) within TCP SYN packets and in server-to-client traffic at 1,460 bytes when packets exceed that size. With this fix, the firewalls no longer hardcode the TCP MSS value for TCP sessions.
|
||||||
|
- PA-7000 Series and PA-5200 Series firewalls hardcoded the maximum transmission unit (MTU) at 1,500 bytes for the encapsulation stage when tunneled clear-text traffic and the originating tunnel session were on different dataplanes. With this fix, the firewalls use the MTU configured for the interface (**Network** > **Interfaces** > **<interface>** > **Advanced** > **Other Info**) instead of hardcoding the MTU at 1,500 bytes.
|
||||||
|
|
||||||
|
## PAN-92445
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server didn't display log data in **Monitor** > **Logs**, the **ACC** tab, or reports when Panorama was in a different timezone than the Dedicated Log Collectors because Panorama applied the wrong time filter.
|
||||||
|
|
||||||
|
## PAN-92380
|
||||||
|
|
||||||
|
Fixed an issue where, when you tried to export a custom report, and your Chrome or Firefox browser was configured to block popup windows, the firewall instead downloaded a Tech Support File to your client system.
|
||||||
|
|
||||||
|
## PAN-92256
|
||||||
|
|
||||||
|
Fixed an issue where the firewall didn't **Block sessions with unsupported cipher suites** based on Decryption policy rules for SSL Inbound Inspection when the rules referenced a **Decryption Profile** with a list of allowed ciphers that didn't match the ciphers that the destination server specified (**Objects** > **Decryption** > **Decryption Profile**). With this fix, the firewall checks the ciphers of both the source client and destination server against the cipher list in Decryption profiles when evaluating whether to allow sessions based on Decryption policy.
|
||||||
|
|
||||||
|
## PAN-92251
|
||||||
|
|
||||||
|
Fixed an issue where VM-Series firewalls used the incorrect MAC address in DHCP messages initiated from a subinterface after you configured that subinterface as a **DHCP Client** (**Network** > **Interfaces** > **Ethernet** > **<subinterface>** > **IPv4**) and disabled the **Use Hypervisor Assigned MAC Address** option (**Device** > **Management** > **Setup**).
|
||||||
|
|
||||||
|
## PAN-92163
|
||||||
|
|
||||||
|
Fixed an issue where firewalls in an active/passive HA configuration took longer than expected to fail over after you configured them to redistribute routes between an interior gateway protocol (IGP) and Border Gateway Protocol (BGP).
|
||||||
|
|
||||||
|
## PAN-92152
|
||||||
|
|
||||||
|
Fixed an issue where the firewall web interface displayed a blank **Device** > **Licenses** page when you had 10 x 5 phone support.
|
||||||
|
|
||||||
|
## PAN-92082
|
||||||
|
|
||||||
|
Fixed an issue where the firewall didn't generate URL Filtering logs for user credential submissions associated with a URL that was not a container page after you selected **Log container page only** and set the **User Credential Submission** action to **alert** for the URL category in a URL Filtering profile (**Objects** > **Security Profiles** > **URL Filtering** > **<ULR_Filtering_profile>**). With this fix, the firewall generates URL Filtering logs for user credential submissions regardless of whether you enable **Log container page only** in the URL Filtering profile.
|
||||||
|
|
||||||
|
## PAN-91946
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server intermittently did not refresh health data for managed firewalls (**Panorama** > **Managed Devices** > **Health**) and therefore displayed 0 for session statistics.
|
||||||
|
|
||||||
|
## PAN-91945
|
||||||
|
|
||||||
|
Fixed an issue where the firewall didn't generate a System log to indicate when the reason that end users couldn’t authenticate to a GlobalProtect portal was a DNS resolution failure for the FQDNs in a RADIUS server profile (**Device** > **Server Profiles** > **RADIUS**).
|
||||||
|
|
||||||
|
## PAN-91809
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls for Azure where, after the firewall rebooted, some interfaces configured as DHCP clients intermittently did not receive DHCP-assigned IP addresses.
|
||||||
|
|
||||||
|
## PAN-91776
|
||||||
|
|
||||||
|
Fixed an issue where endpoint users could not authenticate to GlobalProtect when specifying a **User Domain** with Microsoft-supported symbols such as the dollar symbol ($) in the authentication profile (**Device** > **Authentication Profile**).
|
||||||
|
|
||||||
|
## PAN-91597
|
||||||
|
|
||||||
|
As an enhancement to improve security for the firewall, the management (MGT) interface now includes the following HTTP security headers: X-XSS-Protection, X-Content-Type-Options, and Content-Security-Policy.
|
||||||
|
|
||||||
|
## PAN-91591
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect agent failed to establish a TCP connection with the GlobalProtect gateway when TCP SYN packets had unsupported congestion notification flag bits set (ECN or CWR).
|
||||||
|
|
||||||
|
## PAN-91564
|
||||||
|
|
||||||
|
A security-related fix was made to prevent a local privilege escalation vulnerability that allowed administrators to access the password hashes of local users (CVE-2018-9334).
|
||||||
|
|
||||||
|
## PAN-91559
|
||||||
|
|
||||||
|
Fixed an issue where PA-5200 Series firewalls caused slow traffic over IPSec VPN tunnels because the firewalls reordered TCP segments during IPSec encryption.
|
||||||
|
|
||||||
|
## PAN-91370
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped IPv6 traffic while enforcing IPv6 bidirectional NAT policy rules because the firewall incorrectly translated the destination address for a host that resided on a directly attached network.
|
||||||
|
|
||||||
|
## PAN-91360
|
||||||
|
|
||||||
|
Fixed an issue where, in rare cases, the firewall couldn't establish connections with GlobalProtect agents because the rasmgr process stopped responding when hundreds of end users logged in and out of GlobalProtect at the same time.
|
||||||
|
|
||||||
|
## PAN-91254
|
||||||
|
|
||||||
|
Fixed an issue where end user accounts were locked out after you configured authentication based on a RADIUS server profile with multiple servers (**Device** > **Server Profiles** > **RADIUS**) and enabled the gateway to **Retrieve Framed-IP-Address attribute from authentication server** (**Network** > **GlobalProtect** > **Gateways** > **<gateway>** > **Agent** > **Client Settings** > **<client_settings_configuration>** > **IP Pools**). With this fix, instead of requesting framed IP addresses from all the servers in a RADIUS server profile at the same time, the firewall sends the request to only one server at a time until one of the servers responds.
|
||||||
|
|
||||||
|
## PAN-90824
|
||||||
|
|
||||||
|
An enhancement was made to improve compatibility for the [HTTP log forwarding feature](https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/configure-log-forwarding.html) so that you can specify the TLS version that the HTTP log forwarding feature uses to connect to the HTTP server.
|
||||||
|
|
||||||
|
To specify the version, use the debug system https-settings tls-version CLI command. (To view the version that is currently specified, use the debug system https-settings command.)
|
||||||
|
|
||||||
|
## PAN-90753
|
||||||
|
|
||||||
|
Fixed an issue where firewalls in an active/passive HA configuration didn’t synchronize multicast sessions between the firewall HA peers.
|
||||||
|
|
||||||
|
## PAN-90448
|
||||||
|
|
||||||
|
Fixed an issue where PA-7000 Series and PA-5200 Series firewalls didn't properly **Rematch all sessions on config policy change** for offloaded sessions (**Device** > **Setup** > **Session**).
|
||||||
|
|
||||||
|
## PAN-90411
|
||||||
|
|
||||||
|
Fixed an issue where PA-5200 Series firewalls didn’t forward buffered logs to Panorama Log Collectors after connectivity between the firewalls and Log Collectors was disrupted and then restored.
|
||||||
|
|
||||||
|
## PAN-90404
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server intermittently displayed the connections among Log Collectors as disconnected after pushing configurations to a Collector Group (**Panorama** > **Managed Collectors**).
|
||||||
|
|
||||||
|
## PAN-90347
|
||||||
|
|
||||||
|
Fixed an issue on a PA-5000 Series firewall configured to use an IPSec tunnel containing multiple proxy IDs (**Network** > **IPSec Tunnels** > **<tunnel>** > **Proxy IDs**) where the firewall dropped tunneled traffic after clear text sessions were established on a different dataplane than the first dataplane (DP0).
|
||||||
|
|
||||||
|
## PAN-90190
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama virtual appliance on a VMware ESXi server where VMware Tools failed to start after you upgraded to PAN-OS 8.1.
|
||||||
|
|
||||||
|
## PAN-90143
|
||||||
|
|
||||||
|
Fixed an issue where administrators intermittently failed to log in to the firewall because it intermittently restarted processes continuously due to an out-of-memory condition.
|
||||||
|
|
||||||
|
## PAN-90048
|
||||||
|
|
||||||
|
Fixed an issue where automatic commits failed after you configured Security policy rules that referenced region objects for the source or destination and then upgraded the PAN-OS software.
|
||||||
|
|
||||||
|
## PAN-89992
|
||||||
|
|
||||||
|
Fixed an issue where the firewall didn’t efficiently handle traffic in which the number of Address Resolution Protocol (ARP) packets exceeded the processing capacity of the firewall. With this fix, the firewall handles ARP packets more efficiently.
|
||||||
|
|
||||||
|
## PAN-89748
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama virtual appliance for Azure where commit operations failed after you added administrator accounts other than the default admin account, switched from Panorama mode to Log Collector mode, made configuration changes, and then tried to commit your changes. With this fix, Panorama removes all administrator accounts other than the default admin account when you switch to Log Collector mode. Dedicated Log Collectors support only the default admin account.
|
||||||
|
|
||||||
|
## PAN-89715
|
||||||
|
|
||||||
|
Fixed an issue on PA-5200 Series firewalls in an active/passive HA configuration where failover took a few seconds longer than expected when it was triggered after the passive firewall rebooted.
|
||||||
|
|
||||||
|
## PAN-89525
|
||||||
|
|
||||||
|
Fixed a configuration parsing issue where a default setup of the Authentication Profile caused the firewall to reboot during commit. If the administrator configured the Authentication Profile with any allowed values, including the default values, the configuration committed successfully. The issue was observed on a PA-500 firewall in FIPS-CC mode.
|
||||||
|
|
||||||
|
## PAN-89171
|
||||||
|
|
||||||
|
Fixed an issue on firewalls in an HA configuration where an auto-commit failed (the error message was Error:Duplicate user name) after you connected a new suspended-secondary peer to an active-primary peer.
|
||||||
|
|
||||||
|
## PAN-88852
|
||||||
|
|
||||||
|
Fixed an issue where VM-Series firewalls stopped displaying URL Filtering logs after you configured a URL Filtering profile with an alert action (**Objects** > **Security Profiles** > **URL Filtering**).
|
||||||
|
|
||||||
|
## PAN-88752
|
||||||
|
|
||||||
|
Fixed an issue where User-ID agents configured to detect credential phishing didn’t detect passwords that contained a blank space.
|
||||||
|
|
||||||
|
## PAN-88649
|
||||||
|
|
||||||
|
Fixed an issue where, after receiving machine account names in UPN format from a Windows-based User-ID agent, the firewall misidentified them as user accounts and overrode usernames with machine names in IP address-to-username mappings.
|
||||||
|
|
||||||
|
## PAN-87964
|
||||||
|
|
||||||
|
Fixed an issue where the firewall couldn't render URL content for end users after you configured GlobalProtect Clientless VPN with a **Hostname** set to a Layer 3 subinterface or VLAN interface (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **General**).
|
||||||
|
|
||||||
|
## PAN-87309
|
||||||
|
|
||||||
|
Fixed an issue where, after you configured a GlobalProtect gateway to exclude all video streaming traffic from the VPN tunnel, Hulu and Sling TV traffic could not be redirected if you did not configure any security profiles (such as a File Blocking profile) for your firewall Security policies.
|
||||||
|
|
||||||
|
## PAN-86934
|
||||||
|
|
||||||
|
Fixed an issue where the firewall applied case sensitivity to the names of shared user groups that were defined in its local database and, as a result, users who belonged to those groups couldn't access applications through GlobalProtect Clientless VPN even after successful authentication. With this fix, the firewall ignores character case when evaluating the names of user groups in its local database.
|
||||||
|
|
||||||
|
## PAN-86076
|
||||||
|
|
||||||
|
As an enhancement to improve security for GlobalProtect deployments, the GlobalProtect portal now includes the following HTTP security headers in responses to end user login requests: X-XSS-Protection, X-Content-Type-Options, and Content-Security-Policy.
|
||||||
|
|
||||||
|
## PAN-86028
|
||||||
|
|
||||||
|
Fixed an issue in an HA active/active configuration where traffic in a GlobalProtect VPN tunnel in SSL mode failed after Layer 7 processing if asymmetric routing was involved.
|
||||||
|
|
||||||
|
## PAN-85308
|
||||||
|
|
||||||
|
Fixed an issue in the output for on-demand custom reports (select **Monitor** > **Manage Custom Reports** > **<report>** and **Run Now**) where the **<column_heading>** drop-down displayed a **Columns** option even though you couldn't add or remove columns. With this fix, the **<column_heading>** drop-down no longer displays a **Columns** option.
|
||||||
|
|
||||||
|
## PAN-83001
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped packets based on a QoS class even though traffic didn’t exceed the maximum bandwidth for that class.
|
||||||
|
|
||||||
|
## PAN-81495
|
||||||
|
|
||||||
|
Fixed an issue where connections that the firewall handles as an Application Level Gateway (ALG) service were disconnected when destination NAT and decryption were enabled.
|
||||||
|
|
||||||
|
## PAN-80664
|
||||||
|
|
||||||
|
Fixed an issue where, after end users who haven't yet enrolled in Duo failed to authenticate to a GlobalProtect portal that used a RADIUS server integrated with Duo for multi-factor authentication, the portal login page displayed Invalidusername or password as the authentication error instead of displaying a Duo enrollment URL so that the users could enroll.
|
||||||
@@ -0,0 +1,181 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.20
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5568
|
||||||
|
|
||||||
|
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
|
||||||
|
|
||||||
|
## PAN-168921
|
||||||
|
|
||||||
|
Fixed an issue in active/active high availability (HA) configuration where traffic with complete packets was showing up as incomplete and being disconnected due to a non-session owner device closing the session prematurely.
|
||||||
|
|
||||||
|
## PAN-167989
|
||||||
|
|
||||||
|
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
|
||||||
|
|
||||||
|
## PAN-166836
|
||||||
|
|
||||||
|
Fixed an issue where session failed due to resource unavailability.
|
||||||
|
|
||||||
|
## PAN-166299
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where Server Message Block (SMB) sessions failed due to resource unavailability.
|
||||||
|
|
||||||
|
## PAN-166241
|
||||||
|
|
||||||
|
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
|
||||||
|
|
||||||
|
## PAN-164922
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
|
||||||
|
|
||||||
|
## PAN-164846
|
||||||
|
|
||||||
|
Fixed an issue where packet buffers were depleted.
|
||||||
|
|
||||||
|
## PAN-164422
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
A fix was made to address improper access control that enabled an attacker with authenticated access to GlobalProtect portals and GlobalProtect gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon Web Services (AWS) ([CVE-2021-3062](https://security.paloaltonetworks.com/CVE-2021-3062)).
|
||||||
|
|
||||||
|
## PAN-160744
|
||||||
|
|
||||||
|
Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found.
|
||||||
|
|
||||||
|
## PAN-160708
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted after configuring a a **deny_all** policy.
|
||||||
|
|
||||||
|
## PAN-158723
|
||||||
|
|
||||||
|
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
|
||||||
|
|
||||||
|
## PAN-158262
|
||||||
|
|
||||||
|
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
|
||||||
|
|
||||||
|
A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)).
|
||||||
|
|
||||||
|
## PAN-157834
|
||||||
|
|
||||||
|
Fixed an issue with missing zone entries in CSV or PDF export files.
|
||||||
|
|
||||||
|
## PAN-157730
|
||||||
|
|
||||||
|
Fixed an issue where, after a firewall reboot, a commit or auto-commit operation failed with the following error message: ID population failed. This issue occurred because the Phase1 ID assignment failure did not trigger an idmgr reset.
|
||||||
|
|
||||||
|
## PAN-157632
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall dropped GPRS Tunneling Protocol (GTP-U) traffic with the message TEID=0x00000000.
|
||||||
|
|
||||||
|
## PAN-157346
|
||||||
|
|
||||||
|
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
|
||||||
|
|
||||||
|
## PAN-156225
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to later 9.1 releases and from PAN-OS 10.0.0 to PAN-OS 10.0.4.
|
||||||
|
|
||||||
|
## PAN-155532
|
||||||
|
|
||||||
|
Fixed an issue where the mgmtsrv process restarted due to a missing protective check around access to potentially NULL pointers.
|
||||||
|
|
||||||
|
## PAN-154526
|
||||||
|
|
||||||
|
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting out-of-memory (OOM) condition, multiple processes stopped responding.
|
||||||
|
|
||||||
|
## PAN-154376
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
|
||||||
|
|
||||||
|
## PAN-153908
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the show vpn flow CLI command displayed incorrect details.
|
||||||
|
|
||||||
|
## PAN-153382
|
||||||
|
|
||||||
|
Fixed an issue where the per-minute resource monitor was three minutes behind.
|
||||||
|
|
||||||
|
## PAN-153261
|
||||||
|
|
||||||
|
Fixed an issue where not all fragmented packets were transmitted, which caused increased packet buffer usage.
|
||||||
|
|
||||||
|
## PAN-153107
|
||||||
|
|
||||||
|
Fixed an issue where a dataplane process stopped responding while processing fragmented traffic on GTP-U tunnels.
|
||||||
|
|
||||||
|
## PAN-151120
|
||||||
|
|
||||||
|
Fixed an issue where the SYN-ACK packet matched stale entries in the session flow table and was dropped on the firewall with the following error message: Inactive flow state 0.
|
||||||
|
|
||||||
|
## PAN-150337
|
||||||
|
|
||||||
|
A fix was made to address a reflect cross-site scripting (XSS) vulnerability in the PAN-OS web interface that enabled an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performed arbitrary actions in the web interface as the targeted authenticated administrator ([CVE-2021-3052](https://security.paloaltonetworks.com/CVE-2021-3052)).
|
||||||
|
|
||||||
|
## PAN-149501
|
||||||
|
|
||||||
|
A fix was made to address a memory corruption vulnerability in the GlobalProtect Clientless VPN that enabled an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication ([CVE-2021-3056](https://security.paloaltonetworks.com/CVE-2021-3056)).
|
||||||
|
|
||||||
|
## PAN-147221
|
||||||
|
|
||||||
|
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
|
||||||
|
|
||||||
|
## PAN-146250
|
||||||
|
|
||||||
|
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
|
||||||
|
|
||||||
|
## PAN-146107
|
||||||
|
|
||||||
|
Fixed an issue where memory allocation failure caused a process (pan_comm) to restart several times, which caused the firewall to restart.
|
||||||
|
|
||||||
|
## PAN-143426
|
||||||
|
|
||||||
|
Fixed a memory leak issue where a process (devsrvr) restarted due to the memory limit being exceeded.
|
||||||
|
|
||||||
|
## PAN-138727
|
||||||
|
|
||||||
|
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
|
||||||
|
|
||||||
|
## PAN-128634
|
||||||
|
|
||||||
|
A debug command was added to provide more verbose output when troubleshooting packet processing on the firewall.
|
||||||
|
|
||||||
|
## PAN-120013
|
||||||
|
|
||||||
|
Fixed an issue where secure communication settings were incorrectly synchronized between Panorama appliances in an HA configuration.
|
||||||
|
|
||||||
|
## PAN-119922
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where the show config diff command was not working correctly and produced unexpected output.
|
||||||
|
|
||||||
|
## PAN-118667
|
||||||
|
|
||||||
|
Fixed an issue where firewall policy configurations displayed **[object Object]** instead of the object names.
|
||||||
|
|
||||||
|
## PAN-115541
|
||||||
|
|
||||||
|
Fixed an issue where removing a cipher from an SSL/TLS profile did not take effect if it was attached to the management interface.
|
||||||
|
|
||||||
|
## PAN-110429
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in an HA configuration where multiple all_pktproc processes stopped responding due to missing heartbeats, which caused service outages.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.21-h3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.21
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Fixed a Denial-of-Service (DoS) vulnerability in the GlobalProtect portal and gateway ([CVE-2021-3063](https://security.paloaltonetworks.com/CVE-2021-3063)).
|
||||||
|
|
||||||
|
## PAN-170466
|
||||||
|
|
||||||
|
Fixed an memory reference issue related to the devsrvr process that caused the process to stop responding.
|
||||||
|
|
||||||
|
## PAN-149911
|
||||||
|
|
||||||
|
Fixed an issue where URL filtering logs for credential phishing displayed a slash character ( / ) in the URL field.
|
||||||
|
|
||||||
|
## PAN-141454
|
||||||
|
|
||||||
|
Fixed an issue where the output of the CLI command show running resource-monitor ingress-backlogs displayed an incorrect total utilization value.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.23-h1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-192999
|
||||||
|
|
||||||
|
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
|
||||||
|
|
||||||
|
## PAN-140736
|
||||||
|
|
||||||
|
Fixed an issue where configuration synchronization failed in a high availability (HA) configuration.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.25-h1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.25-h3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.25.2
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237871
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
WF-500 appliances and PAN-DB private cloud deployments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.25
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
This release includes bug and performance fixes.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.26-h1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-239241
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-237935
|
||||||
|
|
||||||
|
Extended the root certificate for WildFire appliances to December 31, 2032.
|
||||||
@@ -0,0 +1,405 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.2
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-4625
|
||||||
|
|
||||||
|
Fixed an issue where the WF-500 appliance provided no option to configure the master key. With this fix, you can use the request master-key new-master-key <key> lifetime <lifetime> CLI command to configure the master key.
|
||||||
|
|
||||||
|
## PAN-97531
|
||||||
|
|
||||||
|
Fixed an issue on PA-3200 Series firewalls where powering down a copper interface disrupted the operations of other interfaces that were grouped with it at the hardware level.
|
||||||
|
|
||||||
|
## PAN-97283
|
||||||
|
|
||||||
|
Fixed an issue on PA-3200 Series firewalls where SFP/SFP+ ports intermittently failed to come up after a reboot.
|
||||||
|
|
||||||
|
## PAN-97003
|
||||||
|
|
||||||
|
Fixed an issue on offline VM-Series firewalls where the web interface and CLI did not display license information after you activated licenses.
|
||||||
|
|
||||||
|
## PAN-96938
|
||||||
|
|
||||||
|
Fixed an issue with dataplane restarts when the mix of network traffic included a high ratio of RTP and RTP Control Protocol (RTCP) traffic.
|
||||||
|
|
||||||
|
## PAN-96734
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) stopped responding during a partial revert operation when reverting an interface configuration.
|
||||||
|
|
||||||
|
## PAN-96622
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect™ portal landing page did not return the HTTP Strict Transport Security (HSTS) header in the error response page when sending the response to an endpoint.
|
||||||
|
|
||||||
|
## PAN-96587
|
||||||
|
|
||||||
|
Fixed an issue where PA-7000 Series and PA-5200 Series firewalls intermittently failed to forward logs to Log Collectors or the Logging Service due to DNS resolution failure for the FQDNs of those log receivers.
|
||||||
|
|
||||||
|
## PAN-96572
|
||||||
|
|
||||||
|
Fixed an issue where, after end users successfully authenticated for access to a service or application, their web browsers briefly displayed a page indicating authentication completed and then they were redirected to an unknown URL that the user did not specify.
|
||||||
|
|
||||||
|
## PAN-96490
|
||||||
|
|
||||||
|
Fixed an issue where syslog servers misrepresented HIP Match, Authentication, and User-ID™ logs received from the firewall because the order changed in the first seven syslog fields for those log types. With this fix, the first seven syslog fields are the same for all log types.
|
||||||
|
|
||||||
|
## PAN-96102
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama™ management server where partial revert operations failed with the following error after you used the PAN-OS® XML API to create template stacks: template-stack-> is missing 'settings' template-stack is invalid.
|
||||||
|
|
||||||
|
## PAN-96088
|
||||||
|
|
||||||
|
Fixed an issue where the active firewall in a high availability (HA) configuration did not synchronize the GlobalProtect data file to the passive firewall.
|
||||||
|
|
||||||
|
## PAN-95895
|
||||||
|
|
||||||
|
Fixed an issue on firewalls that collect port-to-username mappings from Terminal Services agents where the firewalls didn't enforce user-based policies correctly because the dataplane had incorrect primary-to-alternative-username mappings even after you cleared the User-ID cache.
|
||||||
|
|
||||||
|
## PAN-95736
|
||||||
|
|
||||||
|
Fixed an issue where the mprelay process stopped responding when a commit occurred while the firewall was identifying flows that needed a NetFlow update.
|
||||||
|
|
||||||
|
## PAN-95683
|
||||||
|
|
||||||
|
Fixed an issue where, after you upgraded the firewall to PAN-OS 8.1, a 500 Internal Server error occurred for traffic that matched a Security policy rule with a URL Filtering profile that specified a continue action (**Objects** > **Security Profiles** > **URL Filtering**) because the firewall did not correctly apply AES encryption or synchronize the associated API key between the management plane and dataplane.
|
||||||
|
|
||||||
|
## PAN-95513
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where selecting additional target firewalls for a shared policy rule cleared any existing firewall selections for that rule (**Panorama** > **Policies** > **<policy_type>** > **{Pre Rules | Post Rules | Default Rules}** > **Target**).
|
||||||
|
|
||||||
|
## PAN-95486
|
||||||
|
|
||||||
|
Fixed an issue with VM-Series firewalls on Azure where dynamic updates failed for the GlobalProtect Data File when you scheduled the updates using the management interface.
|
||||||
|
|
||||||
|
## PAN-95445
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This fix requires the VMware NSX 2.0.4 or a later plugin.
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where VM-Series firewalls for NSX and firewalls in an NSX notify group (**Panorama** > **VMware NSX** > **Notify Group**) briefly dropped traffic while receiving dynamic address updates after the primary Panorama in a high availability (HA) configuration failed over.
|
||||||
|
|
||||||
|
## PAN-95443
|
||||||
|
|
||||||
|
Fixed an issue where a VM-Series firewall on KVM in DPDK mode didn't receive traffic after you configured it to use the i40e single-root input/output virtualization (SR-IOV) virtual function (VF). This fix requires that you install i40e driver version 2.1.16 or later, and that you set the VF to be trusted by running the following CLI command on the KVM host:
|
||||||
|
|
||||||
|
ip link set dev eth0 vf 1 trust on
|
||||||
|
|
||||||
|
## PAN-95197
|
||||||
|
|
||||||
|
Fixed an issue where mobile endpoints that used GPRS Tunneling Protocol (GTP) lost traffic and had to reconnect because the firewall dropped the response message that a Gateway GPRS support node (GGSN) sent for a second Packet Data Protocol (PDP) context update.
|
||||||
|
|
||||||
|
## PAN-95163
|
||||||
|
|
||||||
|
Fixed an issue where, after you added group mapping configurations, an out-of-memory condition developed that intermittently caused the User-ID process (useridd) to restart and temporarily prevented the firewall from receiving updates to user mappings and group mappings.
|
||||||
|
|
||||||
|
## PAN-95130
|
||||||
|
|
||||||
|
Fixed an issue on the firewall and Panorama management server where you could not assign tags that contained a colon ( : ) to service or service group objects.
|
||||||
|
|
||||||
|
## PAN-95124
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not correctly modify the Configuration XML file (by removing ctd skip-block-http-range) when you upgraded from PAN-OS 8.0 to PAN-OS 8.1.
|
||||||
|
|
||||||
|
## PAN-95056
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where the configd process restarted when an external health monitoring script (such as GoldenGate) executed against Panorama, which became unusable until configd finished restarting.
|
||||||
|
|
||||||
|
## PAN-94917
|
||||||
|
|
||||||
|
Fixed an issue on Panorama Log Collectors where the show system masterkey-properties CLI command did not display the master key lifetime and reminder settings.
|
||||||
|
|
||||||
|
## PAN-94912
|
||||||
|
|
||||||
|
Fixed an issue where PA-5200 Series and PA-3200 Series firewalls in an active/active high availability (HA) configuration sent packets in the wrong direction in a virtual wire deployment.
|
||||||
|
|
||||||
|
## PAN-94853
|
||||||
|
|
||||||
|
Fixed an issue where mobile endpoints that use GPRS Tunneling Protocol (GTP) lose GTP-U traffic because the firewall dropped all GTP-U packets as packets without sessions after receiving two GTP requests with the same tunnel endpoint identifiers (TEIDs) and IP addresses.
|
||||||
|
|
||||||
|
## PAN-94697
|
||||||
|
|
||||||
|
Fixed an issue where commit failures occurred after you configured a DHCP-enabled subinterface as the local Interface for an IKE gateway configuration (**Network** > **Network Profiles** > **IKE Gateways** > **<IKE_gateway>** > **General**).
|
||||||
|
|
||||||
|
## PAN-94586
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server exported reports slowly or not at all due to DNS resolution failures.
|
||||||
|
|
||||||
|
## PAN-94582
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not correctly re-learn a User-ID mapping after that mapping was temporarily lost and recovered through successful WMI probing.
|
||||||
|
|
||||||
|
## PAN-94578
|
||||||
|
|
||||||
|
Fixed an issue where WildFire submissions with a filename that contained %20n or a subject that contained %n caused the management server (mgmtsrvr) process to stop responding.
|
||||||
|
|
||||||
|
## PAN-94575
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama management server running PAN-OS 8.1 failed to push host information profile (HIP) objects that specified Encrypted Locations with State values to firewalls running PAN-OS 8.0 or an earlier release (**Objects** > **GlobalProtect** > **HIP Objects** > **<HIP_object>** > **Disk Encryption** > **Criteria** > **<encrypted_location>**).
|
||||||
|
|
||||||
|
## PAN-94516
|
||||||
|
|
||||||
|
Fixed an issue on PA-500, PA-220, PA-220-R, and PA-200 firewalls where commits failed after the Panorama management server pushed a Decryption profile that you configured to **Block sessions if HSM not available** to firewalls that did not support a hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-94510
|
||||||
|
|
||||||
|
Fixed an issue where the total log storage utilization that the firewall displayed did not account for **IP Tag** storage that was set to less than two per cent (**Device** > **Setup** > **Management** > **Logging and Reporting Settings** > **Log Storage**).
|
||||||
|
|
||||||
|
## PAN-94450
|
||||||
|
|
||||||
|
Fixed an issue where QSFP+ interfaces (13 and 14) on a PA-7000-20GQ-NPC Network Processing Card (NPC) unexpectedly flapped when the card was booting up.
|
||||||
|
|
||||||
|
## PAN-94413
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the hash of the shared policy was incorrectly calculated, which caused an in-sync shared policy status to display as out-of-sync.
|
||||||
|
|
||||||
|
## PAN-94382
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where the Task Manager displayed Completed status immediately after you initiated a push operation to firewalls (**Commit all** job) even though the push operation was still in progress.
|
||||||
|
|
||||||
|
## PAN-94318
|
||||||
|
|
||||||
|
Fixed an issue where the VM-Series firewall for Azure intermittently failed to resolve URLs and generated the following error because Azure prematurely timed out the connection to the PAN-DB cloud after four minutes: Failed tosend Update Request to the Cloud.
|
||||||
|
|
||||||
|
## PAN-94278
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama Collector Group forwarded Threat and WildFire® Submission logs to the wrong external server after you configured match list profiles with the same name for both log types (**Panorama** > **Collector Groups** > **<Collector_Group>** > **Collector Log Forwarding** > **{Threat | WildFire}** > **<match_list_profile>**).
|
||||||
|
|
||||||
|
## PAN-94239
|
||||||
|
|
||||||
|
Fixed an issue where the firewall routed Open Shortest Path First (OSPF) unicast hello messages (P2MP non-broadcast) using a forwarding information base (FIB) instead of sending the messages over the interface to which the OSPF neighbor connected.
|
||||||
|
|
||||||
|
## PAN-94187
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not apply tag-based matching rules for dynamic address groups unless you enclosed the tag names with single quotes ('<tag_name>') in the matching rules (**Objects** > **Address Groups** > **<address_group>**).
|
||||||
|
|
||||||
|
## PAN-94167
|
||||||
|
|
||||||
|
Fixed an issue where a firewall forwarded a deleted or expired IP address-to-username mapping to another firewall through User-ID Redistribution but the receiving firewall still displayed the mapping as an active IP address-to-username mapping.
|
||||||
|
|
||||||
|
## PAN-94165
|
||||||
|
|
||||||
|
Fixed an issue where the firewall used an incorrect next hop in the Border Gateway Protocol (BGP) route that it advertised to External BGP (eBGP) peers in the BGP peer group.
|
||||||
|
|
||||||
|
## PAN-94163
|
||||||
|
|
||||||
|
Fixed an issue on firewalls deployed in virtual wire mode where SSL decryption failed due to a memory pool allocation failure.
|
||||||
|
|
||||||
|
## PAN-94122
|
||||||
|
|
||||||
|
Fixed an issue where firewalls intermittently blocked SSL traffic due to a certificate timeout error after you enabled SSL Forward Proxy decryption and configured the firewall to **Block sessions on certificate status check timeout** (**Objects** > **Decryption** > **Decryption Profile** > **<Decryption_profile>** > **SSL Decryption** > **SSL Forward Proxy**).
|
||||||
|
|
||||||
|
## PAN-94070
|
||||||
|
|
||||||
|
Fixed an issue where Bidirectional Forwarding Detection (BFD) sessions were active in only one virtual router when two or more virtual routers had active BGP sessions (with BFD enabled) using the same peer IP address.
|
||||||
|
|
||||||
|
## PAN-94058
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
GlobalProtect configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a configured Layer 3 interface erroneously opened ports 28869/tcp and 28870/tcp on the IP address assigned to that Layer 3 interface.
|
||||||
|
|
||||||
|
## PAN-94023
|
||||||
|
|
||||||
|
Fixed an issue where the request system external-list show type ip name <EDL_name> CLI command did not display external dynamic list entries after you restarted the management server (mgmtsrvr) process.
|
||||||
|
|
||||||
|
## PAN-93937
|
||||||
|
|
||||||
|
Fixed an issue where the management server (mgmtsrvr) process on the firewall restarted when you pushed configurations from the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-93889
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server generated high-severity System logs with the Syslogconnection established to server message after you configured Traps log ingestion (**Panorama** > **Log Ingestion Profile**) for forwarding to a syslog server (**Panorama** > **Server Profiles** > **Syslog**) and committed configuration changes (**Commit** > **Commit to Panorama**).
|
||||||
|
|
||||||
|
## PAN-93755
|
||||||
|
|
||||||
|
Fixed an issue where SSL decrypted traffic failed after you configured the firewall to **Enforce Symmetric Return** in Policy Based Forwarding (PBF) policy rules (**Policies** > **Policy Based Forwarding**).
|
||||||
|
|
||||||
|
## PAN-93722
|
||||||
|
|
||||||
|
Fixed an issue where the firewall failed to perform decryption because endpoints tried to resume decrypted inbound perfect forward secrecy (PFS) sessions.
|
||||||
|
|
||||||
|
## PAN-93715
|
||||||
|
|
||||||
|
In certain customer environments, enhancements in PAN-OS 8.1.2 to change fan speeds may help reduce rare cases of drive communication failure in PA-5200 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-93705
|
||||||
|
|
||||||
|
Fixed an issue where configuring additional interfaces (such as ethernet1/1 or ethernet1/2) on the Panorama management server in Management Only mode caused an attempt to create a local Log Collector when you committed the configuration (**Panorama** > **Setup** > **Interfaces**), which caused the commit to fail because a local Log Collector is not supported on a Panorama management sever in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-93522
|
||||||
|
|
||||||
|
Fixed an issue on firewalls in a high availability (HA) configuration where traffic was disrupted because the dataplane restarted unexpectedly when the firewall concurrently processed HA messages and packets for the same session. This issue occurred on all firewall models except the PA-200 and VM-50 firewalls.
|
||||||
|
|
||||||
|
## PAN-93412
|
||||||
|
|
||||||
|
Fixed an issue where the Security policy rules pushed from Panorama to a firewall did not display in the list of available rules in the global filters list in the Application Command Center (ACC).
|
||||||
|
|
||||||
|
## PAN-93411
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls for KVM where applications that relied on multicasting failed because the firewalls filtered multicast traffic by the physical function (PF) after you configured them to use single root I/O virtualization (SR-IOV) virtual function (VF) devices.
|
||||||
|
|
||||||
|
## PAN-93410
|
||||||
|
|
||||||
|
Fixed an issue where PA-5200 Series firewalls sent logs to the passive or suspended Panorama virtual appliance in Legacy mode in a high availability (HA) configuration. With this fix, the firewalls send logs only to the active Panorama.
|
||||||
|
|
||||||
|
## PAN-93318
|
||||||
|
|
||||||
|
Fixed an issue where firewall CPU usage reached 100 per cent due to SNMP polling for logical interfaces based on updates to the Link Layer Discovery Protocol (LLDP) MIB (LLDP-V2-MIB.my).
|
||||||
|
|
||||||
|
## PAN-93244
|
||||||
|
|
||||||
|
A security-related fix was made to prevent a Cross-Site Scripting (XSS) attack through the PAN-OS session browser (CVE-2018-9335).
|
||||||
|
|
||||||
|
## PAN-93242
|
||||||
|
|
||||||
|
A security-related fix was made to prevent a Cross-Site Scripting (XSS) vulnerability in a PAN-OS web interface administration page (CVE-2018-9337).
|
||||||
|
|
||||||
|
## PAN-93233
|
||||||
|
|
||||||
|
Fixed an issue where PA-7000 Series firewalls caused slow traffic over IPSec VPN tunnels because the firewalls reordered TCP segments during IPSec encryption when the tunnel session and inner traffic session were on different dataplanes.
|
||||||
|
|
||||||
|
## PAN-93207
|
||||||
|
|
||||||
|
Fixed an issue where the firewall reported the incorrect hostname when responding to SNMP get requests.
|
||||||
|
|
||||||
|
## PAN-93046
|
||||||
|
|
||||||
|
Fixed an issue where administrators whose roles have the **Privacy** privilege disabled (**Device** > **Admin Roles** > **<role>** > **Web UI**) can view details about source IP addresses and usernames in the PDF reports exported from the firewall.
|
||||||
|
|
||||||
|
## PAN-92958
|
||||||
|
|
||||||
|
Fixed an issue where disk utilization increased unnecessarily because the firewall did not archive and rotate the /var/on file, which therefore grew to over 40MB.
|
||||||
|
|
||||||
|
## PAN-92892
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-50 Lite firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where Failed to back up PAN-DB errors were reported in the system log due to management plane out-of-memory errors when a process (devsrvr) attempted to run an md5 checksum.
|
||||||
|
|
||||||
|
## PAN-92821
|
||||||
|
|
||||||
|
Fixed an issue where WildFire Submission logs did not correctly display the subject fields of emails because the firewall did not remove white spaces between encoded chunks in those fields.
|
||||||
|
|
||||||
|
## PAN-92676
|
||||||
|
|
||||||
|
Fixed an issue where an administrator whose Admin Role profile had the **Command Line** privileges set to **superuser** (**Device** > **Admin Roles** > **<role>** > **Command Line**) could not request tech-support dump from the CLI.
|
||||||
|
|
||||||
|
## PAN-92569
|
||||||
|
|
||||||
|
Fixed an issue where the firewall displayed a continue-and-override response page when users tried to access a URL that the firewall incorrectly categorized as unknown because it learned the URL field as an IP address.
|
||||||
|
|
||||||
|
## PAN-92456
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where administrators couldn't log in to the web interface because disk space utilization reached 100 per cent due to the continuous growth of cmserror log files.
|
||||||
|
|
||||||
|
## PAN-92366
|
||||||
|
|
||||||
|
Fixed an issue where PA-5200 Series firewalls in an active/passive high availability (HA) configuration dropped Bidirectional Forwarding Detection (BFD) sessions when the passive firewall was in an initialization state after you rebooted it.
|
||||||
|
|
||||||
|
## PAN-92149
|
||||||
|
|
||||||
|
Fixed an issue on PA-3250 and PA-3260 firewalls where the hardware signature match engine was disabled and the PAN-OS software performed signature matching instead, resulting in a ten percent degradation in threat detection performance.
|
||||||
|
|
||||||
|
## PAN-91689
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server removed address objects and—in the **Network** tab settings and NAT policy rules—used the associated IP address values without reference to the address objects before pushing configurations to firewalls.
|
||||||
|
|
||||||
|
## PAN-91421
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dataplane restarted and resulted in temporary traffic loss when any process stopped responding while system resource usage was running high.
|
||||||
|
|
||||||
|
## PAN-91238
|
||||||
|
|
||||||
|
Fixed an issue where an Aggregate Ethernet (AE) interface with Link Aggregation Control Protocol (LACP) enabled on the firewall went down after a cisco-nexus primary virtual port channel (vPC) switch LACP peer rebooted and came back up.
|
||||||
|
|
||||||
|
## PAN-91088
|
||||||
|
|
||||||
|
Fixed an issue on PA-7000 Series firewalls in a high availability (HA) configuration where the HA3 link did not come up after you upgraded to PAN-OS 8.1.0 or a later PAN-OS 8.1 release.
|
||||||
|
|
||||||
|
## PAN-90920
|
||||||
|
|
||||||
|
Fixed an issue on PA-5200 Series firewalls where the dataplane restarted due to an internal path monitoring failure.
|
||||||
|
|
||||||
|
## PAN-90692
|
||||||
|
|
||||||
|
Fixed an issue where PA-5200 Series firewalls dropped offloaded traffic after you enabled session offloading (enabled by default), configured subinterfaces on the second aggregate Ethernet (AE) interface group (ae2), and configured QoS on a non-AE interface.
|
||||||
|
|
||||||
|
## PAN-90690
|
||||||
|
|
||||||
|
Fixed an issue where Panorama appliances ignored the time-zone offset in logs sent from the Traps Endpoint Security Manager (ESM).
|
||||||
|
|
||||||
|
## PAN-90623
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server displayed template configurations as Out of Sync for firewalls with multiple virtual systems even though the template configurations were in sync.
|
||||||
|
|
||||||
|
## PAN-90418
|
||||||
|
|
||||||
|
Fixed an issue where PA-7000 Series, PA-5200 Series, PA-5000 Series, PA-3200 Series, and PA-3000 Series firewalls dropped packets because their dataplanes restarted due to QoS queue corruption.
|
||||||
|
|
||||||
|
## PAN-89988
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dataplane intermittently restarted, causing traffic loss, after you attached a NetFlow server profile to an interface for which the firewall assigned an invalid identifier.
|
||||||
|
|
||||||
|
## PAN-89794
|
||||||
|
|
||||||
|
Fixed an issue on PA-3050, PA-3060, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls in a high availability (HA) configuration where multicast sessions intermittently stopped forwarding traffic after HA failover on firewalls with hardware offloading enabled (default).
|
||||||
|
|
||||||
|
## PAN-88674
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where administrators with the superuser read-only role could view the Password Hash used to access a Log Collector CLI after another superuser used browser developer tools to modify the input type for that field (**Panorama** > **Managed Collectors** > **<Log_Collector>** > **Authentication**).
|
||||||
|
|
||||||
|
## PAN-88428
|
||||||
|
|
||||||
|
Fixed an issue where the VM-Series firewall incorrectly displayed network interfaces as having a Link Speed of 1000 and a Link Duplex set to half when the actual values were different (**Network** > **Interfaces** > **<interface>** > **Advanced**).
|
||||||
|
|
||||||
|
## PAN-87265
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server displayed no output for the User Activity Report (**Monitor** > **PDF Reports** > **User Activity Report**).
|
||||||
|
|
||||||
|
## PAN-87079
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3060, PA-3050, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where Threat logs displayed an Other IP Flood message instead of identifying the threat name of the correct protocol (such as TCP Flood) when traffic reached the configured SYN flood max-rate threshold (**Objects** > **Security Profiles** > **DoS Protection** > **<DoS_Protection_profile>** > **Flood Protection** > **SYN Flood**).
|
||||||
|
|
||||||
|
## PAN-86672
|
||||||
|
|
||||||
|
Fixed an issue where in rare cases a commit caused the disk to become full due to an incorrect disk quota size value, and as a result the firewall behaved unpredictably (for example, the web interface and CLI became unresponsive).
|
||||||
|
|
||||||
|
## PAN-86647
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where editing the **Description** of a shared policy rule and clicking **OK** caused the **Target** setting to revert to Any firewalls instead of the selected firewalls.
|
||||||
|
|
||||||
|
## PAN-84647
|
||||||
|
|
||||||
|
Fixed an issue with scheduled log exports that prevented firewalls running in FIPS-CC mode from successfully exporting the logs using Secure Copy (SCP).
|
||||||
|
|
||||||
|
## PAN-84238
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama management server failed to push configurations to firewalls running a PAN-OS 7.1 release and displayed the following error:
|
||||||
|
|
||||||
|
wins-server-> primary is invalid
|
||||||
|
|
||||||
|
## PAN-80922
|
||||||
|
|
||||||
|
Fixed an issue where the firewall failed to parse the merged configuration file after you changed the master key; it parsed only the running configuration file. With this fix, the firewall parses both files as expected after you change the master key.
|
||||||
|
|
||||||
|
## PAN-68256
|
||||||
|
|
||||||
|
Fixed an issue on PA-7000 Series firewalls in a high availability (HA) configuration where the HA data link (HSCI) interfaces intermittently failed to initialize properly during bootup.
|
||||||
|
|
||||||
|
## PAN-48553
|
||||||
|
|
||||||
|
Fixed an issue where, after pushing the high availability (HA) Group ID from a Panorama management server to a firewall and overriding the value on the firewall (**Device** > **High Availability** > **General** > **Setup**), the following error displayed even though the value was within the permitted range:
|
||||||
|
|
||||||
|
deviceconfig -> high-availability-> group -> should be equal to or between 1 and 63.
|
||||||
@@ -0,0 +1,547 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-4645
|
||||||
|
|
||||||
|
Fixed an issue where RAID rebuilding after disk replacement either failed or took longer than expected.
|
||||||
|
|
||||||
|
## PAN-101101
|
||||||
|
|
||||||
|
Fixed an issue with inconsistencies in the IP address-to-username mappings after upgrading the User-ID agent to a User-ID agent 8.1 release.
|
||||||
|
|
||||||
|
## PAN-100896
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted multiple times when multiple processes stopped responding when accessing invalid memory.
|
||||||
|
|
||||||
|
## PAN-100870
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app incorrectly displays a warning (Password Warning:Password expires in 0 days) even though the password has not, yet, expired.
|
||||||
|
|
||||||
|
## PAN-100312
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the dataplane restarted when processing Clientless VPN traffic.
|
||||||
|
|
||||||
|
## PAN-100015
|
||||||
|
|
||||||
|
Fixed an issue where a PA-7000 Series firewall with a 20GQ Network Processing Card (NPC) failed to properly initiate all QSFP modules.
|
||||||
|
|
||||||
|
## PAN-99968
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly dropped GTPv2-C Modify Bearer Response packets due to a sequence-number mismatch.
|
||||||
|
|
||||||
|
## PAN-99896
|
||||||
|
|
||||||
|
Fixed an issue where the route (routed) process on a passive firewall in a high availability (HA) cluster restarted when receiving an update from the active peer for a multicast route destined for a multicast group that does not exist on the firewall.
|
||||||
|
|
||||||
|
## PAN-99624
|
||||||
|
|
||||||
|
Fixed an issue where emails were not sent using the configured email service route as expected.
|
||||||
|
|
||||||
|
## PAN-99585
|
||||||
|
|
||||||
|
Fixed an issue where a PA-3200 Series firewall processed traffic that was in suspended mode
|
||||||
|
|
||||||
|
## PAN-99584
|
||||||
|
|
||||||
|
Fixed an issue where a PA-5200 Series firewall processed traffic that was in suspended mode.
|
||||||
|
|
||||||
|
## PAN-99380
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane stopped responding when a tunnel interface on the firewall received fragmented packets.
|
||||||
|
|
||||||
|
## PAN-99362
|
||||||
|
|
||||||
|
Fixed an issue on a VM-Series firewall on Azure where a process (logrcvr) stopped responding.
|
||||||
|
|
||||||
|
## PAN-99316
|
||||||
|
|
||||||
|
Fixed an issue where the SAP Success Factor app failed to load because the Cipher-cloud was configuring cookies with the at ( @ ) character in the cookie name but Palo Alto Networks firewalls used the @ character as a separator for storing cookies locally, which caused the firewall to misinterpret the cookies.
|
||||||
|
|
||||||
|
## PAN-99263
|
||||||
|
|
||||||
|
Fixed an issue where NetFlow caused an invalid memory-access issue that caused the pan_task process to stop responding.
|
||||||
|
|
||||||
|
## PAN-99212
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly dropped ARP packets and increased the flow_arp_throttle counter.
|
||||||
|
|
||||||
|
## PAN-99067
|
||||||
|
|
||||||
|
Fixed an issue where a firewall frequently flapped a BGP session when the firewall did not receive any response from the BFD peer or when BFD was configured only on the firewall.
|
||||||
|
|
||||||
|
## PAN-98735
|
||||||
|
|
||||||
|
Fixed an issue where upgrading a Panorama management server on Microsoft Azure from PAN-OS 8.1.0 to PAN-OS 8.1.1 or PAN-OS 8.1.2 resulted in an autocommit failure.
|
||||||
|
|
||||||
|
## PAN-98624
|
||||||
|
|
||||||
|
Fixed an issue where an administrator who has all administrative rights is unable to add a device to Panorama from the web interface.
|
||||||
|
|
||||||
|
## PAN-98530
|
||||||
|
|
||||||
|
Fixed a memory leak associated with the logrcvr process when using custom syslog filters in a syslog profile.
|
||||||
|
|
||||||
|
## PAN-98470
|
||||||
|
|
||||||
|
Fixed an issue on a firewall with GTP stateful inspection enabled where the firewall incorrectly identified GTP echo packets as GTP-U application packets.
|
||||||
|
|
||||||
|
## PAN-98397
|
||||||
|
|
||||||
|
Fixed an issue on PA-3200 series firewalls where the offload processor did not process route-deletion update messages , which left behind stale route entries and caused sessions to become unresponsive during the session-offload stage.
|
||||||
|
|
||||||
|
## PAN-98329
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where an SFP+ (10Gbps PAN-SFP-PLUS-CU-5M) transceiver was incorrectly identified as an SFP (1Gbps) transceiver.
|
||||||
|
|
||||||
|
## PAN-98217
|
||||||
|
|
||||||
|
Fixed an issue where user-account group members in subgroups (n+1) were unnecessarily queried when nested level was set to n.
|
||||||
|
|
||||||
|
## PAN-98116
|
||||||
|
|
||||||
|
Fixed an issue where PA-3000 Series firewalls passed file descriptors in a dataplane process (pan_comm) during content (apps and threats) installation and FQDNRefresh job execution, which caused the hardware Layer 7 engine to identify applications incorrectly.
|
||||||
|
|
||||||
|
## PAN-98097
|
||||||
|
|
||||||
|
Fixed an issue on PA-3000 Series, PA-3200 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls where Captive Portal was inaccessible for traffic on Secure HTTP (https) websites when SSL decryption was enabled and users were behind a proxy server.
|
||||||
|
|
||||||
|
## PAN-98088
|
||||||
|
|
||||||
|
Fixed an issue where an error (mailsend: failed to get stat of file) appeared in the System log due to an incorrect condition check even though there were no issues with the firewall sending PDF reports.
|
||||||
|
|
||||||
|
## PAN-97905
|
||||||
|
|
||||||
|
Fixed an issue where device-group operations were discarded when a concurrent commit was triggered by a different administrator.
|
||||||
|
|
||||||
|
## PAN-97810
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading to PAN-OS 8.1.1, User-ID usernames were not populated in traffic logs as expected even though User-ID mappings were present on the dataplane.
|
||||||
|
|
||||||
|
## PAN-97724
|
||||||
|
|
||||||
|
Fixed an issue with the Japanese language mode where a firewall displayed garbled characters when an administrator was logging in to the web interface.
|
||||||
|
|
||||||
|
## PAN-97634
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rebooted when the management (MGT) interface was connected to a network that contained a network loop, which caused excessive traffic flow on the interface. This issue was observed only on a PA-220 firewall.
|
||||||
|
|
||||||
|
## PAN-97594
|
||||||
|
|
||||||
|
Fixed an issue where administrators could not use the new colors that were introduced in PAN-OS 8.1 for creating and modifying banners and messages; these colors were unavailable from the CLI and, though available from the web interface (**Device** > **Setup** > **Management** > **Banners and Messages** > **Banners**), administrators received an Operation Failed error when attempting to use them.
|
||||||
|
|
||||||
|
## PAN-97561
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama appliance running PAN-OS 8.1.2 was unable to connect to the Logging Service.
|
||||||
|
|
||||||
|
## PAN-97497
|
||||||
|
|
||||||
|
Fixed an issue where the default for newly added cloned security rules was **Move Top**, which placed the new rule at the top of the list. With this fix, the default is **After Rule** as it was in PAN-OS 8.0 and earlier releases.
|
||||||
|
|
||||||
|
## PAN-97282
|
||||||
|
|
||||||
|
Fixed an issue where Inbound inspection failed when a cipher was cleared from the TLS structure during session resumption.
|
||||||
|
|
||||||
|
## PAN-97225
|
||||||
|
|
||||||
|
Fixed an issue where new Vendor names for the HIP check were not included when Panorama pushed the configuration to firewalls.
|
||||||
|
|
||||||
|
## PAN-97208
|
||||||
|
|
||||||
|
Fixed an issue where a firewall in a high availability (HA) active/active virtual wire (vwire) configuration with SSL decryption enabled passed traffic through the wrong firewall.
|
||||||
|
|
||||||
|
## PAN-97082
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly blocked SSL sessions subjected to Inbound decryption due to UnsupportedVersion when the Decryption rule referenced a decryption profile with **Min - Max TLS Version**, even though **Block sessions with unsupported versions** was disabled (**Objects** > **Decryption** > **Decryption Profile**). With this fix, the firewall checks the TLS version that the server accepted and compares it with the decryption profile settings when evaluating whether to allow or bypass sessions based on Decryption rules.
|
||||||
|
|
||||||
|
## PAN-97060
|
||||||
|
|
||||||
|
Fixed an issue where the User-ID (useridd) process stopped responding due to an out-of-memory issue related to User-ID group mapping.
|
||||||
|
|
||||||
|
## PAN-97045
|
||||||
|
|
||||||
|
Fixed an issue on PA-850 firewalls where the session rematch option failed to execute when you added an IP address to the External Dynamic List (EDL) block list.
|
||||||
|
|
||||||
|
## PAN-96997
|
||||||
|
|
||||||
|
Fixed an intermittent issue where detecting an unreachable WF-500 node took longer than expected.
|
||||||
|
|
||||||
|
## PAN-96978
|
||||||
|
|
||||||
|
Fixed an issue where the **GlobalProtect Clientless VPN** and **GlobalProtect Data** options did not display as expected on Panorama (**Template** > **Device** > **Dynamic Updates**).
|
||||||
|
|
||||||
|
## PAN-96918
|
||||||
|
|
||||||
|
Fixed an issue where an unreachable DNS server due to aggressive timers increased the time of PPPoE negotiation and, in some cases, caused negotiation to fail.
|
||||||
|
|
||||||
|
## PAN-96909
|
||||||
|
|
||||||
|
A security-related fix was made to address a Denial of Service (DoS) that existed in the PAN-OS management web interface and allowed an authenticated user to shut down all management sessions, which causes the firewall to redirect all logged-in users to the login page (CVE-2018-10140).
|
||||||
|
|
||||||
|
## PAN-96889
|
||||||
|
|
||||||
|
Fixed an issue where administrators were required to perform a commit force before pushing a partial or regular commit operation to managed appliances when the management server (mgmtsrvr) or configuration (configd) process encountered a virtual memory leak and restarted.
|
||||||
|
|
||||||
|
## PAN-96779
|
||||||
|
|
||||||
|
Fixed an issue where using the the XML API to retrieve Hit Count on a security rule returned an error message: Anerror occurred. See dagger.log for information.
|
||||||
|
|
||||||
|
## PAN-96737
|
||||||
|
|
||||||
|
Fixed an issue with an incorrect policy match because google-docs-base was incorrectly identified as SSL.
|
||||||
|
|
||||||
|
## PAN-96388
|
||||||
|
|
||||||
|
Fixed an issue in a non-vsys configuration where a firewall dropped the Client Hello packet from tunneled traffic when inbound decryption was enabled because the firewall considered that packet to be an inter-vsys inbound packet.
|
||||||
|
|
||||||
|
## PAN-96326
|
||||||
|
|
||||||
|
Fixed an issue where endpoints could not authenticate to a GlobalProtect portal or gateway through client certificate authentication due to an OCSP status of Unknown when the portal or the gateway used a Certificate profile that specified Online Certificate Status Protocol (OCSP) to validate certificates (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Authentication**).
|
||||||
|
|
||||||
|
## PAN-96200
|
||||||
|
|
||||||
|
Fixed an issue where PA-220 firewalls that were bootstrapped with a configuration that enabled jumbo frames did not change the packet buffer size as expected, which resulted in a dataplane restart.
|
||||||
|
|
||||||
|
## PAN-96150
|
||||||
|
|
||||||
|
Fixed a memory corruption error that caused the dataplane to restart when content decode length was zero.
|
||||||
|
|
||||||
|
## PAN-96113
|
||||||
|
|
||||||
|
Fixed an issue where the show routing protocol bgp rib-out CLI command did not display advertised routes that the firewall sent to the BGP peer. This issue was observed only in a deployment where a firewall is connected to a Border Gateway Protocol (BGP) peer that advertised a route for which the next hop is not in the same subnetwork as the BGP peer interface.
|
||||||
|
|
||||||
|
## PAN-96003
|
||||||
|
|
||||||
|
Fixed an issue where the GTP Protection profile name did not appear in the **Global Find** and **Filter** options in the Profile column of the security rule to which the GTP profile was attached.
|
||||||
|
|
||||||
|
## PAN-95996
|
||||||
|
|
||||||
|
Fixed an issue where Panorama virtual appliances converted from legacy mode to Panorama mode did not properly purge logs, which caused low disk space issues in /opt/panlogs partition.
|
||||||
|
|
||||||
|
## PAN-95993
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not properly identify the google-translate application.
|
||||||
|
|
||||||
|
## PAN-95955
|
||||||
|
|
||||||
|
Fixed an issue on PA-3200 Series firewalls where incorrect internal memory allocation reduced the number of simultaneous SSL decryption sessions that the firewall could support.
|
||||||
|
|
||||||
|
## PAN-95884
|
||||||
|
|
||||||
|
Fixed an issue where routing FIB entries that were learned from a BGP peer were not deleted when BGP Peering went down.
|
||||||
|
|
||||||
|
## PAN-95854
|
||||||
|
|
||||||
|
Fixed an issue where the Filter drop-down did not display properly when you keep the default Target for a Policy rule set to **Any**.
|
||||||
|
|
||||||
|
## PAN-95766
|
||||||
|
|
||||||
|
Fixed an issue where Q-in-Q-tagged packets passed through a firewall without inspection or session creation.
|
||||||
|
|
||||||
|
## PAN-95740
|
||||||
|
|
||||||
|
Fixed an issue where multicast FIB entries were inconsistent across dataplanes, which caused the firewall to intermittently drop multicast packets.
|
||||||
|
|
||||||
|
## PAN-95730
|
||||||
|
|
||||||
|
Fixed an issue where a firewall dropped SIP-RTP packets flowing through a GRE tunnel when a Tunnel Inspection Policy was configured with Security Options (Tunnel Inspection zones).
|
||||||
|
|
||||||
|
## PAN-95712
|
||||||
|
|
||||||
|
Fixed an issue where browsers failed to load custom response pages on decrypted websites when those pages were larger than 8,191 bytes. With this fix, the firewall supports decryption of custom response pages up to 17,999 bytes.
|
||||||
|
|
||||||
|
## PAN-95509
|
||||||
|
|
||||||
|
Fixed an issue where the parent device group in the hierarchy did not automatically acquire read-only access for a URL Profile as expected after you assigned write access to a child device group of that parent.
|
||||||
|
|
||||||
|
## PAN-95476
|
||||||
|
|
||||||
|
Fixed an issue where a certificate failed to load when the certificate public key exceeded the supported number of characters (2,048).
|
||||||
|
|
||||||
|
## PAN-95439
|
||||||
|
|
||||||
|
Fixed an issue where using the test nat-policy-match command from the XML API does not result in any matches when the matching policy is a destination NAT policy.
|
||||||
|
|
||||||
|
## PAN-95339
|
||||||
|
|
||||||
|
Fixed an issue where a firewall sent packets out of order when the sending rate was too high.
|
||||||
|
|
||||||
|
## PAN-95192
|
||||||
|
|
||||||
|
Fixed an issue where the SSL Certificate Error Notify page didn't display the <certname/> <issuer/> variables in the SSL-cert-status-page.
|
||||||
|
|
||||||
|
## PAN-95120
|
||||||
|
|
||||||
|
Fixed an issue where VM-Series firewall bootstrapping failed when you transferred the bootstrap package using a base64 encoded user-data file.
|
||||||
|
|
||||||
|
## PAN-95114
|
||||||
|
|
||||||
|
Fixed an issue where TACACS+ authorization responded with Illegal packet version because a firewall was incorrectly sending minor version 1, which impacts TACACS+ servers and causes a failed authorization.
|
||||||
|
|
||||||
|
## PAN-95113
|
||||||
|
|
||||||
|
Fixed an where issue where non-local administrators using TACACS were unable to log in to the CLI.
|
||||||
|
|
||||||
|
## PAN-95090
|
||||||
|
|
||||||
|
Fixed an issue where imported custom applications did not display in Security Policies that were created through the web interface.
|
||||||
|
|
||||||
|
## PAN-95061
|
||||||
|
|
||||||
|
Fixed an issue on PA-220 firewalls where either a commit or an EDLRefresh job failed with the following error message: failed to handle CONFIG_UPDATE_START. This issue occurred after an increase in the number of type URL entries in an external dynamic list.
|
||||||
|
|
||||||
|
## PAN-95046
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted on a VM-Series firewall on KVM.
|
||||||
|
|
||||||
|
## PAN-94920
|
||||||
|
|
||||||
|
Fixed an issue where PA-5200 Series firewalls in a high availability (HA) active/active configuration experienced internal packet corruption that caused the firewalls to stop passing traffic when the active member of a cluster came back up as passive after being either suspended or rebooted (moving from tentative to passive state).
|
||||||
|
|
||||||
|
## PAN-94864
|
||||||
|
|
||||||
|
Fixed an issue where firewalls receiving IP addresses via DHCP failed to resolve FQDN objects to an IP address.
|
||||||
|
|
||||||
|
## PAN-94777
|
||||||
|
|
||||||
|
Fixed an issue where a 500Internal Server error occurred for traffic that matched a Security policy rule with a URL Filtering profile that specified a continue action (**Objects** > **Security Profiles** > **URL Filtering**) because the firewall did not treat the API keys as binary strings.
|
||||||
|
|
||||||
|
## PAN-94698
|
||||||
|
|
||||||
|
Fixed an issue on PA-5000 Series firewalls where a process (all_pktproc) on the dataplane stopped responding if you enabled the **send icmp unreachable** Action Setting (**Policies** > **<rule>** > **Actions**).
|
||||||
|
|
||||||
|
## PAN-94646
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in a high availability (HA) configuration where a an HA sync initiated from the active peer caused a race condition while processing the previous request.
|
||||||
|
|
||||||
|
## PAN-94637
|
||||||
|
|
||||||
|
Fixed an issue where an XML API call to execute the request system external-list show command did not escape the ampersand ( & ) character in the Source section of the XML output, which resulted in a parse error.
|
||||||
|
|
||||||
|
## PAN-94571
|
||||||
|
|
||||||
|
Fixed an issue on PA-800 Series, PA-3200 Series, and PA-5200 Series firewalls where tunnel-bound traffic was incorrectly routed through an ECMP route instead of a PBF route as expected.
|
||||||
|
|
||||||
|
## PAN-94497
|
||||||
|
|
||||||
|
Fixed an issue where the default static route was not present in the routing table after you removed the DHCP-provided default gateway when you configured a default static route and DHCP provided the same default route.
|
||||||
|
|
||||||
|
## PAN-94452
|
||||||
|
|
||||||
|
Fixed an issue where the firewall recorded GPRS Tunneling Protocol (GTP) packets multiple times in firewall-stage packet captures (pcaps).
|
||||||
|
|
||||||
|
## PAN-94447
|
||||||
|
|
||||||
|
Fixed an issue where deleting all FQDN objects that are no longer in use did not remove them from the FQDN refresh table, which caused firewalls to continue resolving these old objects per the schedule.
|
||||||
|
|
||||||
|
## PAN-94409
|
||||||
|
|
||||||
|
Fixed an issue where FTP traffic failed and hit an incorrect security policy due to missing predict sessions.
|
||||||
|
|
||||||
|
## PAN-94291
|
||||||
|
|
||||||
|
Fixed an issue where a firewall failed to process packets if the previous session was cleared (either from the CLI or web interface), the client uses the same source port, and when the new session is installed on dataplane1 (dp1).
|
||||||
|
|
||||||
|
## PAN-94290
|
||||||
|
|
||||||
|
Fixed an issue where fragmented packets were dropped when traversing a firewall in an HA active/active configuration.
|
||||||
|
|
||||||
|
## PAN-94221
|
||||||
|
|
||||||
|
Fixed an issue when QoS was configured where the dataplane restarted due to a packet process failure.
|
||||||
|
|
||||||
|
## PAN-94124
|
||||||
|
|
||||||
|
Fixed an issue where a PA-800 Series firewall dropped UDP packets traversing port 0.
|
||||||
|
|
||||||
|
## PAN-94062
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane stopped responding due to a failed packet buffer initialization after the firewall rebooted.
|
||||||
|
|
||||||
|
## PAN-94043
|
||||||
|
|
||||||
|
Fixed an issue where, when an administrator made and committed partial changes, the disabled address objects used in a disabled security policy were pushed from Panorama and retained on the firewall but were deleted when an administrator performed a full commit from Panorama.
|
||||||
|
|
||||||
|
## PAN-93990
|
||||||
|
|
||||||
|
Fixed an issue where a VM-Series firewall was unable to ping the gateway in a multiple virtual router configuration when interfaces received IP address through DHCP.
|
||||||
|
|
||||||
|
## PAN-93973
|
||||||
|
|
||||||
|
Fixed an issue on an M-100 appliance where logging stopped when a process (vldmgr) stopped responding.
|
||||||
|
|
||||||
|
## PAN-93864
|
||||||
|
|
||||||
|
Fixed an issue where the password field did not display in the GlobalProtect portal login dialog if you attached the certificate profile to the portal configuration.
|
||||||
|
|
||||||
|
## PAN-93811
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama task manager view on the web interface stopped responding after multiple appliances reported multiple errors and warnings in commit job details.
|
||||||
|
|
||||||
|
## PAN-93754
|
||||||
|
|
||||||
|
A security-related fix was made to address vulnerabilities related to some SAML implementations (CVE-2018-0486 and CVE-2018-0489). Refer to [www.kb.cert.org/vuls/id/475445](https://www.kb.cert.org/vuls/id/475445) for details.
|
||||||
|
|
||||||
|
## PAN-93753
|
||||||
|
|
||||||
|
Fixed an issue on PA-200 firewalls where disk space usage was constantly running high and often reaching maximum capacity. With this fix, the PA-200 firewall purges logs more quickly and it no longer requires as much space for monitor daemons.
|
||||||
|
|
||||||
|
## PAN-93609
|
||||||
|
|
||||||
|
Fixed an issue where the firewall silently dropped the first packet of a session when that packet was received as a fragmented packet (typically with UDP traffic).
|
||||||
|
|
||||||
|
## PAN-93457
|
||||||
|
|
||||||
|
Fixed an issue where continuous renewal for a session that went into DISCARD state when the firewall reached its resource limit prevented the creation of new sessions that matched that DISCARD session.
|
||||||
|
|
||||||
|
## PAN-93331
|
||||||
|
|
||||||
|
Fixed an issue where the firewall applied the wrong checksum when a re-transmitted packet in a NAT session had different TCP flags, which caused the recipient to drop those packets.
|
||||||
|
|
||||||
|
## PAN-93329
|
||||||
|
|
||||||
|
Fixed an issue where the non-session-owner firewall in a high availability (HA) active/active configuration with asymmetric traffic flow dropped TCP traffic when TCP reassembly failed.
|
||||||
|
|
||||||
|
## PAN-93152
|
||||||
|
|
||||||
|
Fixed an intermittent Panorama issue where, after upgrading to PAN-OS 8.0 or a later release and when connected to a WF-500 appliance, commit validations failed due to a mismatched threat ID range on the WildFire private cloud.
|
||||||
|
|
||||||
|
## PAN-93005
|
||||||
|
|
||||||
|
Fixed an issue where the firewall generated System logs with high severity for Dataplane undersevere load conditions that did not affect traffic. With this fix, the System logs have low severity for Dataplaneunder severe load conditions that do not affect traffic.
|
||||||
|
|
||||||
|
## PAN-92745
|
||||||
|
|
||||||
|
Fixed an issue where the Vulnerability Protection profile exceptions view included threat IDs that were disabled or not supported for the PAN-OS release version. Now, only IDs for signatures that are included in the currently-installed content package are displayed.
|
||||||
|
|
||||||
|
## PAN-92740
|
||||||
|
|
||||||
|
Fixed an issue in an NSX environment where the Panorama management server displayed an incorrect number of tags under Dynamic Address Groups when you configured a static tag in one or more address groups.
|
||||||
|
|
||||||
|
## PAN-92609
|
||||||
|
|
||||||
|
Fixed an issue where the firewall could not forward full information for a Protocol-Independent Multicast (PIM) group to a peer PIM router when the PIM bootstrap message was larger than the maximum transmission unit (MTU) of the firewall interface.
|
||||||
|
|
||||||
|
## PAN-92548
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a race condition caused the Logging Service or WF-500 appliances to disconnect from or become unresponsive to firewalls or the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-92257
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was intermittently sending incorrect bytes-per-packet values for some flows to the NetFlow collector.
|
||||||
|
|
||||||
|
## PAN-92105
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama Log Collectors did not receive some firewall logs and took longer than expected to receive all logs when a Collector Group had spaces in its name.
|
||||||
|
|
||||||
|
## PAN-92033
|
||||||
|
|
||||||
|
Fixed an issue during the software download process that prevented some firewalls and appliances from properly receiving these images.
|
||||||
|
|
||||||
|
## PAN-92017
|
||||||
|
|
||||||
|
Fixed an issue where Log Collectors that belonged to a collector group with a space in its name failed to fully connect to one another, which affected log visibility and logging performance.
|
||||||
|
|
||||||
|
## PAN-91926
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect users could not access some websites decrypted by the firewall due to an issue with premature deletion of proxy sessions.
|
||||||
|
|
||||||
|
## PAN-91662
|
||||||
|
|
||||||
|
Fixed an issue where a certificate was loaded without a digital signature, which caused the configuration (configd) daemon to stop responding.
|
||||||
|
|
||||||
|
## PAN-91316
|
||||||
|
|
||||||
|
Fixed an issue where you couldn't unlock administrator accounts with expired passwords because the firewall didn't display a lock icon for their accounts in the Locked User column (**Device** > **Administrators**).
|
||||||
|
|
||||||
|
## PAN-91259
|
||||||
|
|
||||||
|
Fixed an issue where the predict session for the rmi-iiop application was not created correctly, which caused server-to-client initiated sessions to traverse slow-path inspection and, eventually, policy rules denied the traffic associated with these sessions.
|
||||||
|
|
||||||
|
## PAN-91021
|
||||||
|
|
||||||
|
Fixed an issue where, in a multiple virtual system (vsys) configuration on Panorama, you could not add a certificate defined in vsys to a certificate profile in the same vsys unless the vsys was defined using the default name.
|
||||||
|
|
||||||
|
## PAN-90952
|
||||||
|
|
||||||
|
Fixed an issue on PA-5000 Series firewalls where multicast traffic failed because PAN-OS did not remove stale sessions from the hardware session offload processor.
|
||||||
|
|
||||||
|
## PAN-90752
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the Last Commit State column (**Panorama** > **Managed Devices**) did not get updated after a Template-Only configuration push to firewalls.
|
||||||
|
|
||||||
|
## PAN-90535
|
||||||
|
|
||||||
|
Fixed an issue where the firewall unnecessarily sent an Authorize-only request to the RADIUS server which was denied during the login process if you disabled the **Retrieve Framed-IP-Address attribute from authentication server** (**Network** > **GlobalProtect** > **Gateways** > **<gateway>** > **Agent** > **Client Settings** > **<clients_configuration>** > **IP Pools**) in the GlobalProtect gateway configuration.
|
||||||
|
|
||||||
|
## PAN-89620
|
||||||
|
|
||||||
|
Fixed an intermittent issue where traffic stopped flowing through the IPSec tunnel in a hub-and-spoke multiple-vendor configuration.
|
||||||
|
|
||||||
|
## PAN-89346
|
||||||
|
|
||||||
|
Fixed an issue where an XML API call to execute the show system raid detail command returned an error.
|
||||||
|
|
||||||
|
## PAN-88473
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was sending incorrect bytes-per-packet values to the NetFlow collector when two servers were configured in the same NetFlow profile.
|
||||||
|
|
||||||
|
## PAN-88048
|
||||||
|
|
||||||
|
Fixed an issue where a VM-Series firewall on KVM in MMAP mode didn't receive traffic after you enabled the i40e single-root input/output virtualization (SR-IOV) virtual function (VF).
|
||||||
|
|
||||||
|
## PAN-87855
|
||||||
|
|
||||||
|
Fixed an issue where some ICMP Type 4 traffic was not blocked as expected after you created a deny Security policy rule with custom App-ID for ICMP Type 4 traffic.
|
||||||
|
|
||||||
|
## PAN-87166
|
||||||
|
|
||||||
|
Fixed a rare issue on PA-7000 Series firewalls where 20GQ NPC QSFP+ ports didn't link up (during online insertion and removal (OIR), link-state change, or boot up events) and became unrecoverable until the NPC was restarted.
|
||||||
|
|
||||||
|
## PAN-86769
|
||||||
|
|
||||||
|
Fixed an issue where a firewall did not forward logs when using the category eq command-and-control filter.
|
||||||
|
|
||||||
|
## PAN-86630
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped H.323 gatekeeper-assisted calls after failing to perform NAT translation of third-party addresses in H.323 messages.
|
||||||
|
|
||||||
|
## PAN-86327
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rebooted into maintenance mode.
|
||||||
|
|
||||||
|
## PAN-85522
|
||||||
|
|
||||||
|
Fixed an issue on PA-5200 Series firewalls where an SFP+ (10Gbps) transceiver (PAN-SFP-PLUS-CU-5M) was incorrectly identified as an SFP (1Gbps) transceiver.
|
||||||
|
|
||||||
|
## PAN-83153
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama virtual appliance in Legacy mode that was deployed in a high availability (HA) configuration did not receive logs forwarded from PA-7000 Series and PA-5200 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-83047
|
||||||
|
|
||||||
|
Fixed an issue where the firewall displayed the following commit warning when you configured a GlobalProtect gateway with a **Tunnel Interface** set to the default **tunnel** interface (**Network** > **GlobalProtect** > **Gateways** > **<gateway>** > **General**) even after you enabled IPv6: Warning: tunnel tunnel ipv6 is not enabled. IPv6 address will be ignored!
|
||||||
|
|
||||||
|
## PAN-80091
|
||||||
|
|
||||||
|
Fixed an issue where no results were returned for a Global Find request when using the short name domain\group format.
|
||||||
|
|
||||||
|
## PAN-79291
|
||||||
|
|
||||||
|
Fixed an intermittent issue with ZIP hardware offloading where firewalls identified ZIP files as threats when they were sent over Simple Mail Transfer Protocol (SMTP).
|
||||||
|
|
||||||
|
## PAN-42036
|
||||||
|
|
||||||
|
Fixed a rare intermittent issue on PA-800 Series, PA-2000 Series, PA-3000 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls where the firewall unexpectedly rebooted due to memory page allocation failure, which generated a non-maskable interrupt (NMI) watchdog error on the serial console.
|
||||||
|
|
||||||
|
## PAN-33746
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped IKE traffic when another IKE session was in the discard state on the firewall because the the new session matched the discard session. This issue persisted because the discard sessions remained on the firewall longer than expected because the firewall refreshed the discard-session timeout each time the 5-tuple on a new session matched the 5-tuple on the discard session.
|
||||||
@@ -0,0 +1,483 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-4739
|
||||||
|
|
||||||
|
Fixed an issue where WF-500 appliances failed to analyze Excel files because the files contained links and required a manual response to a popup dialog about whether to update those links before opening the file.
|
||||||
|
|
||||||
|
## WF500-4738
|
||||||
|
|
||||||
|
Fixed an issue where the WF-500 appliance factory reset failed.
|
||||||
|
|
||||||
|
## WF500-4737
|
||||||
|
|
||||||
|
Fixed an issue on a WF-500 appliance where in maintenance mode, network activity did not occur.
|
||||||
|
|
||||||
|
## WF500-4690
|
||||||
|
|
||||||
|
Fixed an issue where the WF-500 appliance reported incorrect memory utilization values through SNMP (hrStorageUsed).
|
||||||
|
|
||||||
|
## WF500-4664
|
||||||
|
|
||||||
|
Fixed an issue where the WF-500 appliance SNMP notifications did not provide information for the eth2 and eth3 interfaces.
|
||||||
|
|
||||||
|
## WF500-4466
|
||||||
|
|
||||||
|
Fixed an issue on WF-500 passive cluster members where file forwarding was incorrectly disabled, which prevented the passive firewall from uploading samples.
|
||||||
|
|
||||||
|
## WF500-4362
|
||||||
|
|
||||||
|
Fixed an issue on WF-500 appliances that caused a compliance scan to incorrectly report two vulnerabilities: SSL Server Supports DES Ciphers (Sweet32 Exposure) and NGINX Log Escape Sequence Injection Vulnerability.
|
||||||
|
|
||||||
|
## PAN-105724
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not generate a new random value in the TLS Server Hello message, which breaks TLSv1.3 connections when SSL Forward Proxy decryption is enabled.
|
||||||
|
|
||||||
|
## PAN-104920
|
||||||
|
|
||||||
|
Fixed an issue where administrators were not able to create a WF-500 cluster unless they first configured an HA1 backup.
|
||||||
|
|
||||||
|
## PAN-104293
|
||||||
|
|
||||||
|
Fixed a rare issue where PA-3200 Series firewalls started dropping offloaded traffic.
|
||||||
|
|
||||||
|
## PAN-104131
|
||||||
|
|
||||||
|
Fixed an issue with the Panorama Interconnect plugin where Panorama Node child jobs were not displayed under Panorama Controller Tasks (**Panorama** > **Interconnect** > **Tasks**) as expected when you tried to **Push Common Config** (**Panorama** > **Interconnect** > **Panorama Nodes**).
|
||||||
|
|
||||||
|
## PAN-104116
|
||||||
|
|
||||||
|
Fixed an issue where a hardware packet buffer leak caused firewall performance to degrade.
|
||||||
|
|
||||||
|
## PAN-103921
|
||||||
|
|
||||||
|
Fixed an issue on a PA 3200 Series firewall where the dataplane failed due to an internal path monitoring failure.
|
||||||
|
|
||||||
|
## PAN-103442
|
||||||
|
|
||||||
|
Fixed an intermittent issue on a PA-3200 Series firewall where the forwarding information base (FIB) did not update correctly, which prevented successful forwarding of offloaded traffic.
|
||||||
|
|
||||||
|
## PAN-102943
|
||||||
|
|
||||||
|
Fixed an Issue where a process (mgmtsrvr) failed on EDL refresh when configured over a Secured Socket Layer (SSL) connection.
|
||||||
|
|
||||||
|
## PAN-102750
|
||||||
|
|
||||||
|
Fixed an issue on a PA-5000 Series firewall where the dataplane restarts when multicast traffic matched a stale session on the offload processor that was not cleared as expected.
|
||||||
|
|
||||||
|
## PAN-102664
|
||||||
|
|
||||||
|
Fixed an issue where a process (rasmgr) restarted when a satellite tunnel tear down command and a get user config command occurred simultaneously.
|
||||||
|
|
||||||
|
## PAN-102631
|
||||||
|
|
||||||
|
Fixed an issue where a process (rasmgr) restarted multiple times, which caused the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-102168
|
||||||
|
|
||||||
|
Fixed an issue where a PA-5200 Series firewall processed the tunnel-monitoring with profile-failover as having the tunnel status up and peers as down during initial configuration.
|
||||||
|
|
||||||
|
## PAN-102140
|
||||||
|
|
||||||
|
Fixed an issue where Extended Authentication (X-Auth) clients intermittently failed to establish an IPSec tunnel to GlobalProtect™ gateways.
|
||||||
|
|
||||||
|
## PAN-101955
|
||||||
|
|
||||||
|
Fixed an issue on an M-100 appliance in a high availability (HA) configuration where administrators could not reestablish access to the appliance after a session ended unexpectedly.
|
||||||
|
|
||||||
|
## PAN-101704
|
||||||
|
|
||||||
|
Fixed an issue where a configured Layer 3 interface erroneously opened ports 28869/tcp and 28870/tcp on the IP address assigned to that Layer 3 interface.
|
||||||
|
|
||||||
|
## PAN-101289
|
||||||
|
|
||||||
|
Fixed an issue where simultaneous management access allowed only one user to log in at a time.
|
||||||
|
|
||||||
|
## PAN-101182
|
||||||
|
|
||||||
|
Fixed an issue where a system failure occurred due to packet size exceeding the hardware limit.
|
||||||
|
|
||||||
|
## PAN-100985
|
||||||
|
|
||||||
|
Fixed an issue with PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls where the firewall fails to clear cache for refreshing the FQDN list, which periodically results in an out of memory condition that forces the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-100794
|
||||||
|
|
||||||
|
Fixed an issue where SNMP fan trays did not initialize as expected and prevented the SNMP manager from receiving fan tray information.
|
||||||
|
|
||||||
|
## PAN-100715
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where the dataplane stops processing traffic when attempting to transmit packets larger than the firewall maximum transmission unit (MTU).
|
||||||
|
|
||||||
|
## PAN-100345
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-200, PA-220, PA-220R, PA-500, and PA-800 Series firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a large number of group mappings caused the firewall to display out-of-memory (OOM) errors and restart.
|
||||||
|
|
||||||
|
## PAN-100031
|
||||||
|
|
||||||
|
Fixed an issue where the content rewriter module failed to properly handle simultaneous chunked and zipped responses, and did not send end of response.
|
||||||
|
|
||||||
|
## PAN-99964
|
||||||
|
|
||||||
|
Fixed an issue on an M-100 appliance where a bulk set of commands timed out causing config locks and, while running any subsequent show commands, responded with the following message: Server error: Timed out while getting config lock. Please try again.
|
||||||
|
|
||||||
|
## PAN-99936
|
||||||
|
|
||||||
|
Fixed an issue where access to Panorama™ accounts failed due to the removal of IPv4 address and exclusive use of IPv6 on the management (MGT) port.
|
||||||
|
|
||||||
|
## PAN-99897
|
||||||
|
|
||||||
|
Fixed an issue where a configuration change commit was accepted when only one virtual wire (vwire) interface was defined in a vwire pair. With this fix, a commit for a change where only one vwire interface is defined for a vwire pair is rejected and an error message is displayed.
|
||||||
|
|
||||||
|
## PAN-99830
|
||||||
|
|
||||||
|
A security-related fix was made to address a cross-site scripting (XSS) vulnerability in the GlobalProtect Portal login page.
|
||||||
|
|
||||||
|
## PAN-99780
|
||||||
|
|
||||||
|
Fixed an issue where the second virtual system (vsys) dropped TCP traffic that was out-of-order when that second vsys controlled the proxy session in a multi-vsys configuration.
|
||||||
|
|
||||||
|
## PAN-99590
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not return Captive Portal response pages as expected due to depletion of file descriptors.
|
||||||
|
|
||||||
|
## PAN-99392
|
||||||
|
|
||||||
|
Fixed an issue where RADIUS VSA administrators were able to login for one hour after their VSA administrator role was removed on the RADIUS server.
|
||||||
|
|
||||||
|
## PAN-99310
|
||||||
|
|
||||||
|
Fixed an issue where the firewall attempted to reconnect to the LDAP server when an empty Distinguished Name (DN) returned for an invalid user.
|
||||||
|
|
||||||
|
## PAN-99260
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dataplane restarted due to missing SIP parent information after an HA failover event.
|
||||||
|
|
||||||
|
## PAN-99141
|
||||||
|
|
||||||
|
Fixed an issue in an HA active/active virtual wire configuration where a race condition caused the firewall to intermittently drop First SYN packets when they traversed the HA3 link.
|
||||||
|
|
||||||
|
## PAN-99110
|
||||||
|
|
||||||
|
Fixed an issue where a library (libpam_pan.so) did not handle incorrect passwords as expected.
|
||||||
|
|
||||||
|
## PAN-99095
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where a commit failed message appeared in the Template Last Commit column in the device management summary after a Panorama reboot or upgrade.
|
||||||
|
|
||||||
|
## PAN-99060
|
||||||
|
|
||||||
|
Fixed an issue where searching through pcaps from a Log Collector in a configuration with multiple Log Collectors took longer than expected.
|
||||||
|
|
||||||
|
## PAN-98976
|
||||||
|
|
||||||
|
Fixed an intermittent issue where Captive Portal multi-factor authentication (MFA) failed and discarded new MFA requests.
|
||||||
|
|
||||||
|
## PAN-98949
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where generating a threat pcap from the web interface (**Monitor** tab) took longer than expected and caused the web interface and CLI to become inaccessible.
|
||||||
|
|
||||||
|
## PAN-98885
|
||||||
|
|
||||||
|
Fixed an issue where high elastic search memory load caused the firewall not to display logs and reboot
|
||||||
|
|
||||||
|
## PAN-98694
|
||||||
|
|
||||||
|
Fixed an issue on a PA-5200 Series firewall in an HA active/passive configuration where the firewall dropped TCP-FIN packets after a failover.
|
||||||
|
|
||||||
|
## PAN-98635
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama centralized management server where the logs related to the clear-log system were not forwarded to the Syslog server.
|
||||||
|
|
||||||
|
## PAN-98632
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where administrators could not log in to a firewall with an AMI image created from a virtual machine (VM).
|
||||||
|
|
||||||
|
## PAN-98504
|
||||||
|
|
||||||
|
A security-related fix was made to address three OpenSSL vulnerabilities: CVE-2018-0732, CVE-2018-0737, and CVE-2018-0739.
|
||||||
|
|
||||||
|
## PAN-98479
|
||||||
|
|
||||||
|
Fixed an issue where Panorama displayed a File not found error when you attempted to view or download Threat pcaps from the **Monitor** tab.
|
||||||
|
|
||||||
|
## PAN-98392
|
||||||
|
|
||||||
|
Fixed an issue where the commit failed and the device server log displayed the following message: failed to handle CONFIG_UPDATE_START.
|
||||||
|
|
||||||
|
## PAN-98320
|
||||||
|
|
||||||
|
Fixed an issue where after you exit a process, a fixed amount of memory did not release which caused memory leaks.
|
||||||
|
|
||||||
|
## PAN-98195
|
||||||
|
|
||||||
|
Fixed an issue on a PA-220 firewall in an HA active/passive configuration and with jumbo frames enabled (**Device** > **Setup** > **Session**) where configuration and dynamic updates failed to synchronize.
|
||||||
|
|
||||||
|
## PAN-98189
|
||||||
|
|
||||||
|
Fixed an issue where firewall overrides configuration to not validate first ASN, resulting in multi-lateral BGP connection flaps peering over an internet exchange.
|
||||||
|
|
||||||
|
## PAN-98101
|
||||||
|
|
||||||
|
Fixed an issue where a log record in the JSON query caused a process (reportd) to fail.
|
||||||
|
|
||||||
|
## PAN-97881
|
||||||
|
|
||||||
|
Fixed an issue where an administrator with the CLI Device Read privilege was able to discard a session that was revoked.
|
||||||
|
|
||||||
|
## PAN-97832
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where the virtual machine (VM) information source made incorrect calls in FIPS-CC mode.
|
||||||
|
|
||||||
|
## PAN-97831
|
||||||
|
|
||||||
|
Fixed an issue where the set ssh service-restart mgmt CLI command did not respond correctly.
|
||||||
|
|
||||||
|
## PAN-97572
|
||||||
|
|
||||||
|
Fixed an issue in an HA active/passive configuration where URL request messages were not prioritized from the dataplane to the management plane and where a high rate of log generation in the dataplane caused inconsistent URL categorization.
|
||||||
|
|
||||||
|
## PAN-97547
|
||||||
|
|
||||||
|
Fixed an issue where the log in banner did not display properly when configured to single long-line.
|
||||||
|
|
||||||
|
## PAN-97358
|
||||||
|
|
||||||
|
Fixed an issue in an HA active/passive configuration where an HA sync job executed while a commit all job was processing.
|
||||||
|
|
||||||
|
## PAN-97355
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect connection failed with the following dataplane ICMPv6 message: Packet too big due to the firewall MTU value set lower than normal.
|
||||||
|
|
||||||
|
## PAN-97324
|
||||||
|
|
||||||
|
Fixed an issue where values were missing in the URL field in the Data Filtering logs.
|
||||||
|
|
||||||
|
## PAN-97315
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the configuration (configd) process stopped responding after you entered a filter string and tried to **Add Match Criteria** for any **Dynamic** address group type (**Objects** > **Address Groups**).
|
||||||
|
|
||||||
|
## PAN-97296
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama web interface **Group Mapping Setting** took longer to load than expected when there were multiple device groups and each group reported to a different master device.
|
||||||
|
|
||||||
|
## PAN-97253
|
||||||
|
|
||||||
|
Fixed an issue where audio failed for long-lived session initiated protocol (SIP) sessions subjected to six content updates.
|
||||||
|
|
||||||
|
## PAN-97084
|
||||||
|
|
||||||
|
Fixed a rare issue where the task manager failed to load in the web interface when a pending job caused subsequent completed jobs to be inappropriately held in memory.
|
||||||
|
|
||||||
|
## PAN-97077
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the report-generation process stopped responding due to a corrupt log record in the JSON query.
|
||||||
|
|
||||||
|
## PAN-96796
|
||||||
|
|
||||||
|
Fixed an intermittent issue where session BIND messages were dropped in a Dynamic IP configuration.
|
||||||
|
|
||||||
|
## PAN-96780
|
||||||
|
|
||||||
|
Fixed an issue on a PA-3220 firewall where the external dynamic list refresh and commit, failed after an increase in the number of external dynamic list objects in the firewall.
|
||||||
|
|
||||||
|
## PAN-96678
|
||||||
|
|
||||||
|
Fixed an issue on PA-800 Series firewalls where the web interface did not display or allow you to configure the bandwidth setting any higher than 1Gbps.
|
||||||
|
|
||||||
|
## PAN-96645
|
||||||
|
|
||||||
|
Fixed an issue where generation of extraneous data filtering logs for SMB protocol traffic occurred without data filtering or file blocking securities rules in place.
|
||||||
|
|
||||||
|
## PAN-96579
|
||||||
|
|
||||||
|
Fixed an issue where the Syslog server received an incorrect vsys/port log message when multiple vsys systems, with the same profile name and different port numbers, are connected to a single syslog server.
|
||||||
|
|
||||||
|
## PAN-96565
|
||||||
|
|
||||||
|
Fixed an issue where the DNS proxy process failed due to a DNS response packet containing a TXT resource record with length = 0.
|
||||||
|
|
||||||
|
## PAN-96477
|
||||||
|
|
||||||
|
Fixed an issue where PA-5000 Series firewalls did not send an IGMP query immediately after an HA failover.
|
||||||
|
|
||||||
|
## PAN-96461
|
||||||
|
|
||||||
|
Fixed an issue where software deployment from Panorama to a managed firewall failed.
|
||||||
|
|
||||||
|
## PAN-96431
|
||||||
|
|
||||||
|
A security-related fix was made to prevent HTTP Header Injection in the Captive Portal.
|
||||||
|
|
||||||
|
## PAN-96316
|
||||||
|
|
||||||
|
Fixed an issue during a decrypted session on an L3 Aggregate Ethernet (AE) interface, where an incorrectly formatted threat packet capture (pcap) caused malformed packet captures during an inspection.
|
||||||
|
|
||||||
|
## PAN-96231
|
||||||
|
|
||||||
|
Fixed an issue where a commit took significantly longer than expected when cloning a rule compared to when configuring a new rule when the configuration contained a large number of rules.
|
||||||
|
|
||||||
|
## PAN-96183
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where logs failed to purge from the log-disks when /opt/pancfg partition usage reached 100%.
|
||||||
|
|
||||||
|
## PAN-96109
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama appliance returned the following error: mgmtsrvr: User restart reason - Virtual memory limit exceeded (8204808 > 8192000).
|
||||||
|
|
||||||
|
## PAN-95999
|
||||||
|
|
||||||
|
Fixed an issue where firewalls in an HA active/active configuration with a default session setup and owner configuration dropped packets in a GlobalProtect VPN tunnel that used a floating IP address.
|
||||||
|
|
||||||
|
## PAN-95970
|
||||||
|
|
||||||
|
Fixed an issue on a PA-500 firewall where the dataplane tunnel content pointer entered a NULL state and caused dataplane processes (pan_comm and tund) to stop responding, which caused the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-95958
|
||||||
|
|
||||||
|
Fixed an issue where a PA-220 firewall did not recognize the panDeviceLogging SNMP object identifier.
|
||||||
|
|
||||||
|
## PAN-95931
|
||||||
|
|
||||||
|
Fixed an issue where some fields did not populate the template when logs are forwarded to the HTTP Server.
|
||||||
|
|
||||||
|
## PAN-95902
|
||||||
|
|
||||||
|
Fixed an issue where the header captions you configured for PDF Summary Reports or for Custom Reports were not used for the report name as expected.
|
||||||
|
|
||||||
|
## PAN-95815
|
||||||
|
|
||||||
|
Fixed an issue where the firewall returns an empty response for the API call show user ip-user-mapping.
|
||||||
|
|
||||||
|
## PAN-95765
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where **Collector Groups** and **WildFire Appliances and Clusters** (**Commit** > **Push to Devices** > **Edit Selections**) that were already in sync with the current configuration were incorrectly selected and, thus, included when you attempted to push a configuration only to appliances that were not in sync.
|
||||||
|
|
||||||
|
## PAN-95698
|
||||||
|
|
||||||
|
Fixed an issue where the firewall revealed part of a password in cleartext on the command-line interface (CLI) and management server (mgmtsrvr) log when an administrator attempted to set a password that exceeded the maximum number of characters (31) using the CLI. With this fix, the firewall reports an error when an administrator attempts to set a password that contains more than 31 characters without revealing any part of the actual password.
|
||||||
|
|
||||||
|
## PAN-95438
|
||||||
|
|
||||||
|
Fixed an issue where Panorama M-Series and virtual appliances did not resolve the FQDN list because a bootstrap setting (cfg.product.bootstrap) was set to **factory_reset**.
|
||||||
|
|
||||||
|
## PAN-95407
|
||||||
|
|
||||||
|
Fixed an issue where an API call resulted in an incorrect response.
|
||||||
|
|
||||||
|
## PAN-95331
|
||||||
|
|
||||||
|
Fixed an issue where a temporary flap on configured Aggregate Ethernet (AE) interfaces cleared the dataplane debug logs.
|
||||||
|
|
||||||
|
## PAN-95265
|
||||||
|
|
||||||
|
Fixed an issue on a PA-220 firewall where exporting the device state from Panorama command-line interface (CLI) included the default bidirectional forwarding detection (BFD) configuration, which caused a commit to fail on the firewall when uploading the device state.
|
||||||
|
|
||||||
|
## PAN-95200
|
||||||
|
|
||||||
|
Fixed an issue on an M-100 appliance where reports did not generate in user groups.
|
||||||
|
|
||||||
|
## PAN-95119
|
||||||
|
|
||||||
|
Fixed an issue where TCP segments with large sequence numbers caused the dataplane to fail while large file sizes are transferred.
|
||||||
|
|
||||||
|
## PAN-95054
|
||||||
|
|
||||||
|
Fixed an issue where temporary files not properly cleaned caused disk space issues.
|
||||||
|
|
||||||
|
## PAN-95045
|
||||||
|
|
||||||
|
Fixed an issue where the syslog messages that terminated with 0 prevented the firewall from identifying matching patterns in the message.
|
||||||
|
|
||||||
|
## PAN-94559
|
||||||
|
|
||||||
|
Fixed an issue on an M-500 appliance where a bootstrapped firewall automatically added to Panorama did not commit the changes.
|
||||||
|
|
||||||
|
## PAN-94385
|
||||||
|
|
||||||
|
Fixed an issue on Log Collectors where the show log-collector serial-number <LC_serial_number> CLI command displayed log ages that exceeded log expiration periods.
|
||||||
|
|
||||||
|
## PAN-94236
|
||||||
|
|
||||||
|
Fixed an issue where files failed to upload to the WildFire cloud when file-forwarding queue limit was reached on the dataplane. When this occurred, the WildFire upload log included the file with a status of offset mismatch.
|
||||||
|
|
||||||
|
## PAN-93847
|
||||||
|
|
||||||
|
Fixed an issue where a null-pointer exception caused the device server (devsrv) process on the management plane to restart.
|
||||||
|
|
||||||
|
## PAN-93127
|
||||||
|
|
||||||
|
Fixed an intermittent issue where NAT traffic was dropped when NAT parameters were introduced or changed in the path between the LSVPN GlobalProtect gateway and the GlobalProtect satellite. To leverage this fix in your network, you must also enable Tunnel Monitoring on the GlobalProtect Gateway (**Network** > **GlobalProtect** > **Gateways** > **<gp-gateway>** > **Satellite** > **Tunnel Settings**).
|
||||||
|
|
||||||
|
## PAN-92955
|
||||||
|
|
||||||
|
Fixed an issue on PA-5200 Series firewalls in an HA active/active configuration where session timeouts occurred when TCP timers did not update as expected for asymmetric flows.
|
||||||
|
|
||||||
|
## PAN-92596
|
||||||
|
|
||||||
|
Fixed an issue where the output of the show neighbor ndp-monitor all command-line interface (CLI) command was missing a space between the Interface and IPv6 address columns, which decreased readability.
|
||||||
|
|
||||||
|
## PAN-92334
|
||||||
|
|
||||||
|
Fixed an issue where the process (cord) stopped responding when trying to forward correlation events if there was no log forwarding profile configured for correlated events.
|
||||||
|
|
||||||
|
## PAN-91874
|
||||||
|
|
||||||
|
Fixed an issue where the log receiver failed due to the logging certificate server name indication (SNI) value.
|
||||||
|
|
||||||
|
## PAN-91835
|
||||||
|
|
||||||
|
Fixed an issue where PA-7000 Series firewalls did not send logs to Panorama.
|
||||||
|
|
||||||
|
## PAN-91715
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the destination interface configured for a QoS profile rule did not match traffic as expected.
|
||||||
|
|
||||||
|
## PAN-90967
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the Bidirectional Forwarding Detection (BFD) up time displayed negative values.
|
||||||
|
|
||||||
|
## PAN-89849
|
||||||
|
|
||||||
|
Fixed an issue where the antivirus/anti-spyware block page did not display.
|
||||||
|
|
||||||
|
## PAN-89402
|
||||||
|
|
||||||
|
Fixed an issue on PA-3200 Series firewalls where Ethernet ports 2, 3, 4, 6, 7, 8, and 10 were functioning only at 1,000Mbps (1Gbps).
|
||||||
|
|
||||||
|
## PAN-87867
|
||||||
|
|
||||||
|
Fixed an issue on an M-100 appliance where, when the interface and snapshot length (snaplen) options were enabled, the tcpdump command failed to execute with the following message: Unsupported number of arguments.
|
||||||
|
|
||||||
|
## PAN-86759
|
||||||
|
|
||||||
|
Fixed an issue where the URL session information WildFire® report displayed Unknown for sample files uploaded from firewalls running a PAN-OS 8.0 release.
|
||||||
|
|
||||||
|
## PAN-84199
|
||||||
|
|
||||||
|
Fixed an issue where, after you disabled the **Skip Auth on IKE Rekey** option in the GlobalProtect gateway, the firewall still applied the option: end users with endpoints that used Extended Authentication (X-Auth) did not have to re-authenticate when the key for establishing the IPSec tunnel expired (**Network** > **GlobalProtect** > **Gateways** > **<gateway>** > **Agent** > **Tunnel Settings**).
|
||||||
|
|
||||||
|
## PAN-83946
|
||||||
|
|
||||||
|
Fixed an issue where the default QoS profile limited the available bandwidth to 10Gbps when you specifically applied the profile to the ae2 interface; this issue occurred regardless of the bandwidth setting you configured specifically for that profile.
|
||||||
|
|
||||||
|
## PAN-82987
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama web interface intermittently became unresponsive during ACC queries.
|
||||||
|
|
||||||
|
## PAN-81553
|
||||||
|
|
||||||
|
Fixed an issue where the M-100 appliance used the default value of 1,000 because the maximum number of user groups was not defined in the system configuration.
|
||||||
@@ -0,0 +1,443 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.5
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-4811
|
||||||
|
|
||||||
|
Fixed an issue where WF-500 appliances displayed the wrong WildFire® content version show system info after a WildFire content update.
|
||||||
|
|
||||||
|
## PAN-108805
|
||||||
|
|
||||||
|
Fixed an intermittent issue on PA-3200 Series firewalls where a process (all_pktproc_11) failed, which caused an out of memory condition and the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-107791
|
||||||
|
|
||||||
|
Fixed an issue where after upgrading from PAN-OS® 8.1.3 to 8.1.4 the CLI two-factor administrator authentication failed.
|
||||||
|
|
||||||
|
## PAN-107449
|
||||||
|
|
||||||
|
Fixed an issue where firewalls failed to establish IKE phase 1 or phase 2 when you specified Diffie-Hellman (DH) group1.
|
||||||
|
|
||||||
|
## PAN-107365
|
||||||
|
|
||||||
|
Fixed an issue on Panorama™ M-Series and virtual appliances where after you make a change to a template and attempt to push to a target device, the device does not appear in the Push Scope Selection list (**Commit** > **Push to Devices** > **Edit Selections** > **Device Groups**).
|
||||||
|
|
||||||
|
## PAN-107005
|
||||||
|
|
||||||
|
Fixed an issue on PA-3200 Series firewalls where packets dropped when a VSS-Monitoring Ethernet trailer was being appended by an external device.
|
||||||
|
|
||||||
|
## PAN-106936
|
||||||
|
|
||||||
|
Fixed an issue where PA-800 Series firewalls intermittently restarted due to a kernel error.
|
||||||
|
|
||||||
|
## PAN-106829
|
||||||
|
|
||||||
|
Fixed an issue on a PA-3200 Series firewall where the dataplane failed due to an internal path monitoring failure.
|
||||||
|
|
||||||
|
## PAN-106502
|
||||||
|
|
||||||
|
Fixed an issue where hardware packet buffers gradually depleted when LLDP packets created locally were sent to a down interface within an Aggregate Ethernet (AE) interface.
|
||||||
|
|
||||||
|
## PAN-106231
|
||||||
|
|
||||||
|
Fixed an intermittent issue where newly created IPSec Tunnels (**Network** > **IPSec Tunnels** > **Add**) did not activate.
|
||||||
|
|
||||||
|
## PAN-106016
|
||||||
|
|
||||||
|
Fixed an issue on PA-800 Series firewalls where a kernel memory spike caused the firewall to restart.
|
||||||
|
|
||||||
|
## PAN-105926
|
||||||
|
|
||||||
|
Fixed an intermittent issue on Panorama M-Series and virtual appliances where an address object referenced in the address group was allowed to be deleted without a reference error which caused commits to fail.
|
||||||
|
|
||||||
|
## PAN-105921
|
||||||
|
|
||||||
|
Fixed an issue with Panorama where administrators were unable to use the web interface to acquire a commit or configuration lock for device groups.
|
||||||
|
|
||||||
|
## PAN-105842
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the Dynamic Address Group lists did not display and displayed the following error message: Command failed with no output.
|
||||||
|
|
||||||
|
## PAN-105695
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the dataplane restarted while processing SMTP traffic.
|
||||||
|
|
||||||
|
## PAN-104876
|
||||||
|
|
||||||
|
Fixed an issue on Panorama managed devices where the green Template Values Exist indicator incorrectly displayed after you closed any interface settings (**Device** > **Setup** > **Interfaces**) even when you did not make any changes.
|
||||||
|
|
||||||
|
## PAN-104771
|
||||||
|
|
||||||
|
Fixed an issue where the HTTP header insertion entries caused the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-104764
|
||||||
|
|
||||||
|
Fixed an issue on Panorama management server when using Microsoft Azure or Amazon AWS where the management interface settings (**Device** > **Setup** > **Interface** > **Management**) is disabled.
|
||||||
|
|
||||||
|
## PAN-104668
|
||||||
|
|
||||||
|
Fixed an issue where a GTP PDP update did not update the GTP-U session which caused subsequent GTP traffic to drop.
|
||||||
|
|
||||||
|
## PAN-104524
|
||||||
|
|
||||||
|
Fixed an issue where the firewall logged data in the packet-diag log for IP addresses that you did not specify in the packet-capture filters when you enabled the tunnel:flow log feature.
|
||||||
|
|
||||||
|
## PAN-104406
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the replace device CLI command caused the configuration lock to stop responding.
|
||||||
|
|
||||||
|
## PAN-104163
|
||||||
|
|
||||||
|
Fixed an issue where the show config audit base-version command continuously increased the number of file descriptors and caused the management server (mgmtsrvr) to exit and restart.
|
||||||
|
|
||||||
|
## PAN-104073
|
||||||
|
|
||||||
|
Fixed an issue where the replace device old <serial number> new <serial number> command caused the configuration process (configd) to stop responding.
|
||||||
|
|
||||||
|
## PAN-103820
|
||||||
|
|
||||||
|
Fixed and issue where the template stack retains the dynamic update schedule information after you remove it.
|
||||||
|
|
||||||
|
## PAN-103383
|
||||||
|
|
||||||
|
Fixed an issue where a firewall blocked SMTP traffic when processing ZIP files due to too many packet-process loops.
|
||||||
|
|
||||||
|
## PAN-103346
|
||||||
|
|
||||||
|
Fixed an issue where the LDAP Service Route Configuration (**Device** > **Setup** > **Services** > **Service Route Configuration**) did not respond when **Customize** was selected and **non-management interfaces** were enabled.
|
||||||
|
|
||||||
|
## PAN-103248
|
||||||
|
|
||||||
|
Fixed an issue where the process (routed) infinitely looped due to a corrupt internal OSPF database (DB) which caused OSPF adjacencies to be dropped.
|
||||||
|
|
||||||
|
## PAN-103132
|
||||||
|
|
||||||
|
A security-related fix was made to address the FragmentSmack vulnerability (CVE-2018-5391 / PAN-SA-2018-0012).
|
||||||
|
|
||||||
|
## PAN-102975
|
||||||
|
|
||||||
|
Fixed an issue where SSL enabled applications accessed through a GlobalProtect™ Clientless VPN caused buffer leaks.
|
||||||
|
|
||||||
|
## PAN-102743
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5250, PA-5260, “PA-5280-8.1-only”, PA-5000 Series, and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where GlobalProtect SSL sessions that were enforcing client certificate authentication failed to resume and caused an authentication failure.
|
||||||
|
|
||||||
|
## PAN-102337
|
||||||
|
|
||||||
|
Fixed an issue on Panorama virtual appliances in a high availability (HA) configuration where the elastic search script failed to identify the master node due to case sensitivity in the serial number that caused log-replication failures when you enabled log redundancy.
|
||||||
|
|
||||||
|
## PAN-101981
|
||||||
|
|
||||||
|
Fixed an issue where installing path monitoring for static route on a satellite in a Large Scale VPN (LSVPN) infrastructure failed.
|
||||||
|
|
||||||
|
## PAN-101819
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama Controller did not display all commit-all jobs for Panorama Nodes (**Panorama** > **Interconnect** > **Tasks**) and the Panorama Controller did not push those missing jobs during a Push to Devices action when the associated Panorama Node was running a PAN-OS 8.1 release.
|
||||||
|
|
||||||
|
## PAN-101604
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not correctly process OSPF link-state updates which caused the firewall to send incorrect updates externally, which resulted in ARP broadcasts that contained incorrect source MAC and source IP addresses.
|
||||||
|
|
||||||
|
## PAN-101585
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
The following PA-7000 Series NPCs only: PA-7000-20G-NPC, PA-7000-20GQ-NPC, PA-7000-20GXM-NPC, PA-7000-20GQXM-NPC
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where an egress buffer overflow that impacted internal packet path monitoring caused a high availability (HA) failover. Additionally, enhancements were made to flow control communication between the traffic manager and flow engine components to improve system stability during periods of heavy traffic.
|
||||||
|
|
||||||
|
## PAN-101525
|
||||||
|
|
||||||
|
Fixed an issue where the EDL and FQDN address objects in the security and NAT policies displayed 0.0.0.0, which caused traffic to fail to match the policy.
|
||||||
|
|
||||||
|
## PAN-101492
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where after you configured the Authentication fields (**Panorama** > **Authentication Profile** > **Add** > **Authentication**) for the GlobalProtect gateway template stack, the saved configuration did not get applied.
|
||||||
|
|
||||||
|
## PAN-101425
|
||||||
|
|
||||||
|
Fixed an issue where after a redistribution profile was added, the OSPF configured with an authentication profile flapped.
|
||||||
|
|
||||||
|
## PAN-101378
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in a high availability (HA) active/passive configuration where the firewall processed traffic in a suspended state.
|
||||||
|
|
||||||
|
## PAN-101368
|
||||||
|
|
||||||
|
Fixed an issue where SNMP polling displayed incorrect values, which caused authentication failures each time you restarted the firewall.
|
||||||
|
|
||||||
|
## PAN-101328
|
||||||
|
|
||||||
|
Fixed an intermittent issue where SSL decryption caused Content-ID™ to block files received over SMTP.
|
||||||
|
|
||||||
|
## PAN-101124
|
||||||
|
|
||||||
|
Fixed an issue where User Principal Names (UPN) which begin with the "at" ( @ ) character caused User-ID™ to fail.
|
||||||
|
|
||||||
|
## PAN-100862
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a commit error occurred when an Aggregate Ethernet (AE) sub-interface was configured as the destination interface in a QoS policy rule.
|
||||||
|
|
||||||
|
## PAN-100719
|
||||||
|
|
||||||
|
Fixed an issue where Dynamic Updates pushed from Panorama to the Firewall displayed an incorrect None scheduled value.
|
||||||
|
|
||||||
|
## PAN-100613
|
||||||
|
|
||||||
|
Fixed an issue on a PA-5200 Series firewall in a high availability (HA) active/active configuration with a virtual wire (vwire) subinterface where session setup packets sent to peer firewalls were sent back as HA2/HA3 race conditions, which caused an increase in packet descriptors and traffic to stop responding.
|
||||||
|
|
||||||
|
## PAN-100538
|
||||||
|
|
||||||
|
Fixed an issue where exporting a device state (**Device** > **Setup** > **Operations**) from Panorama failed to import to the firewall.
|
||||||
|
|
||||||
|
## PAN-100448
|
||||||
|
|
||||||
|
Fixed an issue where a scheduled external dynamic list refresh displayed incorrect update values.
|
||||||
|
|
||||||
|
## PAN-100447
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in a high availability (HA) configuration only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue when the management interface used DHCP Client-IP assignment where the automatic commits failed after multiple PAN-OS upgrade and downgrade cycles.
|
||||||
|
|
||||||
|
## PAN-100443
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances in a high availability (HA) active/passive configuration where the passive firewall failed to connect to a newly deployed firewall with the following error message:vm-cfg: failed to process registration from svm device. vm-state: active.
|
||||||
|
|
||||||
|
## PAN-100395
|
||||||
|
|
||||||
|
Fixed an intermittent issue on a firewall where Dead Peer Detection (DPD) (**Network** > **IKE Gateways** > **Add**) was enabled and failed during IKE negotiations.
|
||||||
|
|
||||||
|
## PAN-100256
|
||||||
|
|
||||||
|
Fixed and issue on a firewall where a Device Group was selected, the App Scope Network Monitor report (**Monitor** > **App Scope >** > **Network Monitor**) failed to display data.
|
||||||
|
|
||||||
|
## PAN-100244
|
||||||
|
|
||||||
|
Fixed an issue where a failed commit or commit validation followed by a non-user-committed event (such as an FQDN refresh, an external dynamic list refresh, or an antivirus update) resulted in an unexpected change to the configuration that caused the firewall to drop traffic.
|
||||||
|
|
||||||
|
## PAN-100238
|
||||||
|
|
||||||
|
Fixed an issue where obsolete IPv6 host entries were not purged and remained in a REACHABLE state, which caused new entries to fail.
|
||||||
|
|
||||||
|
## PAN-100228
|
||||||
|
|
||||||
|
Fixed an intermittent issue on a PA-7000 Series firewall where auto-commits prematurely executed before all Network Processing Cards (NPCs) were detected and ready.
|
||||||
|
|
||||||
|
## PAN-100144
|
||||||
|
|
||||||
|
Fixed an issue on PA-7000 Series firewalls in a high availability (HA) active/active configuration where after a HA failover event the IP address rule list continuously duplicated entries and resulted in slow response times from the firewall and, eventually, caused the Network Processing Cards (NPCs) to restart.
|
||||||
|
|
||||||
|
## PAN-100049
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where Push Scope Selection (**Commit** > **Push to Devices**) selected firewalls not in the hierarchy of the firewall you selected.
|
||||||
|
|
||||||
|
## PAN-99966
|
||||||
|
|
||||||
|
Fixed an issue where Commit and Push (**Commit** > **Commit and Push**) failed and displayed the following validation error: log-settings profiles match-list send-email is not a valid reference when you attempted to import a firewall configuration to Panorama.
|
||||||
|
|
||||||
|
## PAN-99965
|
||||||
|
|
||||||
|
Fixed an issue where SNMP Object identifier queries for hrStorageAllocationUnits returned negative values.
|
||||||
|
|
||||||
|
## PAN-99861
|
||||||
|
|
||||||
|
Fixed an issue where SaaS application usage reports were empty when you used special characters in naming zones.
|
||||||
|
|
||||||
|
## PAN-99860
|
||||||
|
|
||||||
|
Fixed an issue on a PA-7000 Series firewall where the Network Processing Card (NPC) rebooted due to a memory allocation issue.
|
||||||
|
|
||||||
|
## PAN-99643
|
||||||
|
|
||||||
|
Fixed an issue where a change in user-mapping information prevented the host information profile (HIP) from updating.
|
||||||
|
|
||||||
|
## PAN-99582
|
||||||
|
|
||||||
|
Fixed an issue where a firewall in a high availability (HA) active/passive configuration did not send the Bidirectional Forwarding Detection (BFD) administrator down status after a manual failover.
|
||||||
|
|
||||||
|
## PAN-99525
|
||||||
|
|
||||||
|
Fixed an issue where the destination NAT (DNAT) using a dynamic IP address caused the dataplane to fail.
|
||||||
|
|
||||||
|
## PAN-99483
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5250, PA-5260, and PA-5280 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, when you deployed the firewall in a network that uses Dynamic IP and Port (DIPP) NAT translation with PPTP, client systems were limited to using a translated IP address-and-port pair for only one connection.
|
||||||
|
|
||||||
|
See [Limitations](/content/techdocs/en_US/pan-os/8-1/pan-os-release-notes/pan-os-8-1-release-information/limitations.html#id1787F0E08SZ) for PA-7000 Series firewalls
|
||||||
|
|
||||||
|
## PAN-99211
|
||||||
|
|
||||||
|
Fixed an issue in a high availability (HA) active/passive configuration where the hardware offload feature attempted to reinstall IPSec sessions for individual packets, which caused additional dataplane CPU loads on both the active and passive firewalls.
|
||||||
|
|
||||||
|
## PAN-99204
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where a qualifier configured for a custom application signature displayed the following error message: Unauthorized request.
|
||||||
|
|
||||||
|
## PAN-99161
|
||||||
|
|
||||||
|
Fixed an issue where the Captive Portal configured with RADIUS authentication failed when a username contained the "at" ( @ ) character.
|
||||||
|
|
||||||
|
## PAN-99085
|
||||||
|
|
||||||
|
Fixed an issue where firewalls did not purge files automatically as expected, which caused WildFire updates to fail.
|
||||||
|
|
||||||
|
## PAN-98978
|
||||||
|
|
||||||
|
Fixed an intermittent issue on Panorama M-Series and virtual appliances where GlobalProtect Gateway Configuration (**Network** > **GlobalProtect** > **Gateways** > **Authentication**) responded with the following message: Malformed Request.
|
||||||
|
|
||||||
|
## PAN-98683
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped IPv6 ping packets, which caused high availability (HA) path monitoring to fail.
|
||||||
|
|
||||||
|
## PAN-98475
|
||||||
|
|
||||||
|
Fixed an issue on a firewall configured with RADIUS where the default timeout setting failed after an administrator entered credentials through the web interface.
|
||||||
|
|
||||||
|
## PAN-98375
|
||||||
|
|
||||||
|
Fixed an issue when you configured service objects (**Objects** > **Services**) a process (all_pktproc) failed and caused the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-98332
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly forwarded packets to upstream devices when it had no ARP entry for the destination IP address, which resulted in traffic outages caused by source MAC addresses that did not get updated as expected.
|
||||||
|
|
||||||
|
## PAN-98263
|
||||||
|
|
||||||
|
Fixed an issue on a PA-5000 Series firewall where SNMP values for received and transmitted bytes for Aggregate Ethernet (AE) subinterfaces returned incorrect values.
|
||||||
|
|
||||||
|
## PAN-98249
|
||||||
|
|
||||||
|
Fixed an issue where General Information (Dashboard) did not display the date information for Application Version, Threat Version, and Antivirus Version line items.
|
||||||
|
|
||||||
|
## PAN-98115
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances in a high availability (HA) active/passive configuration where after you delete a plugin from both firewalls the configuration synchronization failed.
|
||||||
|
|
||||||
|
## PAN-98110
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.8 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where administrator setting did not change when appropriate after you imported a configuration.
|
||||||
|
|
||||||
|
## PAN-97928
|
||||||
|
|
||||||
|
Fixed an issue where you could not set the Captive Portal session timeout (**Device** > **Setup** > **Session**) to 60 seconds or longer without causing a browser redirect.
|
||||||
|
|
||||||
|
## PAN-97879
|
||||||
|
|
||||||
|
Fixed an issue on Panorama management server in a high availability (HA) active/passive configuration where a Commit (**Commit** > **Commit to Panorama**) caused the firewalls to restart.
|
||||||
|
|
||||||
|
## PAN-97853
|
||||||
|
|
||||||
|
Fixed an issue Panorama M-Series and virtual appliances with the characteristic **Data Breaches** (**Objects** > **Application Filters**) enabled caused all Device Groups entries not to display.
|
||||||
|
|
||||||
|
## PAN-97698
|
||||||
|
|
||||||
|
Fixed an issue where the firewall took longer than expected to update a URL category.
|
||||||
|
|
||||||
|
## PAN-97495
|
||||||
|
|
||||||
|
Fixed an issue on a PA-5000 Series firewall in a QoS configuration where the setting did not re-apply after the dataplane restarted.
|
||||||
|
|
||||||
|
## PAN-97199
|
||||||
|
|
||||||
|
A security-related fix was made to the way the Linux kernel handles exceptions associated with MOV to SS and POP to SS instructions (CVE-2018-8897).
|
||||||
|
|
||||||
|
## PAN-96877
|
||||||
|
|
||||||
|
Fixed an issue where license keys with special characters caused rebooting to fail.
|
||||||
|
|
||||||
|
## PAN-96696
|
||||||
|
|
||||||
|
A security-related fix was made to prevent modification of attributes in a SAML Response packet.
|
||||||
|
|
||||||
|
## PAN-96548
|
||||||
|
|
||||||
|
Fixed an issue where the command delete report custom scope shared report-name <report name> file-name did not delete the files in the directory and displayed the following error message: Server error : unable to remove directory for <report-name>.
|
||||||
|
|
||||||
|
## PAN-96522
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall did not rotate error logs correctly, which caused disk space issues.
|
||||||
|
|
||||||
|
## PAN-96462
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a null pointer exception caused the configuration (configd) process to stop responding.
|
||||||
|
|
||||||
|
## PAN-96440
|
||||||
|
|
||||||
|
Fixed an issue where the static route was not reinstalled if you modified the path-monitoring hold time while the timer was active.
|
||||||
|
|
||||||
|
## PAN-96391
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where one template is selected to display a list of templates displayed.
|
||||||
|
|
||||||
|
## PAN-96299
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where the bootstrap in GCP failed when a software image was provided, which caused GCP to time out before media availability was provided.
|
||||||
|
|
||||||
|
## PAN-96283
|
||||||
|
|
||||||
|
Fixed an issue where administrators with predefined roles and permission to save configuration changes were not able to save their changes.
|
||||||
|
|
||||||
|
## PAN-95935
|
||||||
|
|
||||||
|
Fixed an intermittent issue on a PA-7000 Series firewall where the GlobalProtect LSVPN tunnel monitoring failed during re-key, which caused satellites to disconnect.
|
||||||
|
|
||||||
|
## PAN-95819
|
||||||
|
|
||||||
|
Fixed an issue where a firewall did not apply the configured NAT policy during a predicted RTSP session.
|
||||||
|
|
||||||
|
## PAN-95613
|
||||||
|
|
||||||
|
Fixed an issue where Commits failed when custom role-based administrators made changes to Managed Collectors (**Panorama**).
|
||||||
|
|
||||||
|
## PAN-95454
|
||||||
|
|
||||||
|
Fixed an intermittent issue on a VM-Series firewall in a VMware NSX environment where the firewall stopped passing traffic.
|
||||||
|
|
||||||
|
## PAN-95131
|
||||||
|
|
||||||
|
Fixed an issue where administrators with Device Group and Template access were not able to modify the QoS interface (**Network** > **QoS**).
|
||||||
|
|
||||||
|
## PAN-95024
|
||||||
|
|
||||||
|
Fixed an issue on a Panorama M-Series and virtual appliances where firewalls redeployed to a NSX environment, the Device State (**Panorama** > **Managed Devices** > **Summary**) displayed a Deactivated status due to the firewalls being deployed with previously assigned authorization codes.
|
||||||
|
|
||||||
|
Firewall gets the same serial number after getting redeployed in NSX environment where Panorama still think that newly deployed firewalls are de-activated because of it has a serial number used in the past.
|
||||||
|
|
||||||
|
## PAN-94532
|
||||||
|
|
||||||
|
Fixed an issue where a memory leak caused an out-of-memory (OOM) error.
|
||||||
|
|
||||||
|
## PAN-93456
|
||||||
|
|
||||||
|
Fixed an intermittent issue where VPN tunnels terminated due to IKE manager failures.
|
||||||
|
|
||||||
|
## PAN-92694
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the threat log displayed unrelated URLs in the file name column.
|
||||||
|
|
||||||
|
## PAN-87152
|
||||||
|
|
||||||
|
Fixed an issue where the show running ippool command stopped responding due to a conflict with packet processing and caused the Aggregate Ethernet (AE) interface to flap.
|
||||||
|
|
||||||
|
## PAN-86426
|
||||||
|
|
||||||
|
A security-related fix was made to SAML authentication.
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.6-h2
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-112148
|
||||||
|
|
||||||
|
An enhancement was made to pattern-matching capabilities to accommodate additional signatures.
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.9-h4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-123700
|
||||||
|
|
||||||
|
A security-related fix was made to prevent a memory corruption vulnerability in PAN-OS® software ([PAN-SA-2019-0023](https://securityadvisories.paloaltonetworks.com/Home/Detail/161) / CVE-2019-1582).
|
||||||
|
|
||||||
|
## PAN-123603
|
||||||
|
|
||||||
|
A security-related fix was made to prevent a memory corruption vulnerability in PAN-OS software ([PAN-SA-2019-0021](https://securityadvisories.paloaltonetworks.com/Home/Detail/159) / CVE-2019-1580).
|
||||||
|
|
||||||
|
## PAN-123564
|
||||||
|
|
||||||
|
Fixed CVE-2019-1581, see [PAN-SA-2019-0022](https://securityadvisories.paloaltonetworks.com/Home/Detail/160) for details.
|
||||||
|
|
||||||
|
## PAN-123371
|
||||||
|
|
||||||
|
Fixed an issue where the **Wildfire Analysis Report** incorrectly displayed the following error message: You are not authorized to access thispage on the web interface.
|
||||||
|
|
||||||
|
## PAN-120194
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Virtual and M-Series Panorama appliances and Log Collectors only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where closed Elasticsearch (ES) indices were continuing to receive and re-queue logs, which resulted in high CPU usage.
|
||||||
|
|
||||||
|
## PAN-118640
|
||||||
|
|
||||||
|
Fixed an issue where the GTP-U session did not match the correct policy, which caused the IMSI and IMEI not to display in the inner session traffic and threat logs.
|
||||||
|
|
||||||
|
## PAN-117720
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
GlobalProtect™ Clientless VPN environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) stopped responding and caused the firewall to restart unexpectedly when processing GlobalProtect Clientless VPN traffic. To leverage this fix, you must first upgrade (**Devices** > **Dynamic Updates**) to GlobalProtect Clientless VPN content release 79 or a later release.
|
||||||
|
|
||||||
|
## PAN-114642
|
||||||
|
|
||||||
|
Fixed an issue where firewall logs incorrectly included the end-user IP address in GTP message logs when you configured PAA IE with IPv4 and IPv6 dual stack in the Create Session Response message.
|
||||||
|
|
||||||
|
## PAN-114275
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped GTPv1 DELETE PDP response packets that had a termination endpoint ID (TEID) value of 0.
|
||||||
|
|
||||||
|
## PAN-105412
|
||||||
|
|
||||||
|
Fixed an issue where forward error correction (FEC) was disabled by default for AOC modules, which caused QSFP ports to flap or remain in the DOWN state. With this fix, FEC is enabled by default for AOC modules.
|
||||||
|
|
||||||
|
## PAN-105091
|
||||||
|
|
||||||
|
Fixed an issue on a firewall where stateful inspection failed, which caused the firewall to drop GTPv2-C Modify Bearer Request packets.
|
||||||
|
|
||||||
|
## PAN-99447
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Virtual and M-Series Panorama appliances and Log Collectors only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a Log Collector received logs destined for closed ES indices, which caused indices to return failure messages and, when the issue persisted for more than a few hours, caused Log Collectors to disconnect and reconnect repeatedly when attempting (and failing) to process the re-queued logs.
|
||||||
|
|
||||||
|
## PAN-98005
|
||||||
|
|
||||||
|
Fixed an issue where adding more than eight Log Collectors to a collector group caused the configuration (configd) process to stop responding.
|
||||||
@@ -0,0 +1,411 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 8.1.9
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-4995
|
||||||
|
|
||||||
|
Fixed an issue on Panorama™ M-Series and WF-500 appliances where administrators were unable to run the debug software disk-usage aggressive-cleaning enable CLI command and resulted in the following error message: Server error : Failed to execute op command.
|
||||||
|
|
||||||
|
## PAN-118949
|
||||||
|
|
||||||
|
Fixed an issue where after you changed the filter configuration in the user.src notin 'cns\proxy full profile the firewall displayed the following error message: Unknown user group cns\Proxy Full.
|
||||||
|
|
||||||
|
## PAN-118407
|
||||||
|
|
||||||
|
Fixed an issue where an internal path monitoring failure due to a buffer leak caused the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-117729
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly displayed application dependency warnings (**Policies** > **Security**) after you initiated a commit.
|
||||||
|
|
||||||
|
## PAN-117149
|
||||||
|
|
||||||
|
Fixed an issue on firewalls configured with authentication policies where sessions matching an authentication policy did not generate traffic logs as defined in the security policy when sessions were redirected or denied.
|
||||||
|
|
||||||
|
## PAN-116851
|
||||||
|
|
||||||
|
Fixed an issue where users were unable to open an app in their browser after they logged in to GlobalProtect™ Clientless VPN until they closed any and all tabs associated with that app and then opened the app a second time. This issue occurred only when an administrator configured a Source User for the Clientless VPN Security policy rule (**Policies** > **Security** > **<GP-VPN-Security-policy-rule>** > **User**).
|
||||||
|
|
||||||
|
## PAN-116848
|
||||||
|
|
||||||
|
Fixed an issue where multiple device group administrators simultaneously enabled configuration locks caused a race condition.
|
||||||
|
|
||||||
|
## PAN-116828
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the management server and a process (configd) used higher than expected CPU and memory when you added or deleted a larger than expected number of Security policy rules with an XML API.
|
||||||
|
|
||||||
|
## PAN-116613
|
||||||
|
|
||||||
|
Fixed an issue on a VM-Series firewall deployed in Microsoft Azure where packets dropped silently due to a kernel error.
|
||||||
|
|
||||||
|
## PAN-116579
|
||||||
|
|
||||||
|
Fixed an issue where the firewall sent truncated URLs to the Captive Portal Redirect message when HTTPS traffic sent through a proxy server was subjected to decryption.
|
||||||
|
|
||||||
|
## PAN-116069
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-200 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the report generation default configuration caused an out-of-memory condition.
|
||||||
|
|
||||||
|
## PAN-116022
|
||||||
|
|
||||||
|
Fixed an issue where the NSX Manager passed a blank string to Panorama, which caused a null entry into the configuration and commits to fail.
|
||||||
|
|
||||||
|
## PAN-115526
|
||||||
|
|
||||||
|
Fixed an issue where a dataplane process (all_pktproc) stops responding due to a packet buffer protection feature.
|
||||||
|
|
||||||
|
## PAN-115494
|
||||||
|
|
||||||
|
Fixed an issue where the "/opt/pancfg/" partition became full due to a configuration preview operation not responding.
|
||||||
|
|
||||||
|
## PAN-115450
|
||||||
|
|
||||||
|
Fixed a rare issue where a race condition occurred between daemons during a tunnel re-key, which caused BGP sessions to drop from Large Scale VPN tunnels. To leverage this fix, you must run the debug rasmgr delay-nh-update CLI command.
|
||||||
|
|
||||||
|
## PAN-115415
|
||||||
|
|
||||||
|
Fixed an issue where a session created from a predict session went into DISCARD state.
|
||||||
|
|
||||||
|
## PAN-115379
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to create a custom log forwarding profile when you configured a filter with the "in" and "not in" configurations (**Objects** > **Log Forwarding** > **Add** > **Add** > **Filter** > **Filter Builder**) and resulted in the following error message: Invalid filter <Log Forwarding profile name> match-list -> <match list profile-name> -> filter is invalid.
|
||||||
|
|
||||||
|
## PAN-115339
|
||||||
|
|
||||||
|
Fixed a rare issue where a commit caused the firewall to stop responding when you enabled flow debug and configured a NAT policy.
|
||||||
|
|
||||||
|
## PAN-114743
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where, after you upgraded the firewall to PAN-OS® 8.1, commits failed when Panorama is configured to manage shared gateway objects for managed firewalls.
|
||||||
|
|
||||||
|
## PAN-114607
|
||||||
|
|
||||||
|
Fixed an issue where all the log collectors did not get queued when you configured more than 32 collector groups.
|
||||||
|
|
||||||
|
## PAN-114548
|
||||||
|
|
||||||
|
Fixed an issue where the firewall discarded external dynamic lists after the list was downloaded and a server authentication attempt failure occurred.
|
||||||
|
|
||||||
|
## PAN-114437
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where, after you upgraded the firewall from PAN-OS 8.0.8 to PAN-OS 8.1.4, commits took longer than expected when you configured the Device Group with large group hierarchies.
|
||||||
|
|
||||||
|
## PAN-114434
|
||||||
|
|
||||||
|
Fixed an issue where the firewall created incorrect predict sessions, which caused flow sessions to fail for applications.
|
||||||
|
|
||||||
|
## PAN-113971
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the High Speed Chasis Interconnect (HSCI) link flapped after you rebooted the firewall.
|
||||||
|
|
||||||
|
## PAN-113795
|
||||||
|
|
||||||
|
Fixed an issue on a firewall configured with GlobalProtect Clientless VPN where a process (all_pkts) stopped responding, which caused the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-113775
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped UpdatePDPContext response packets and displayed the following GTP log event: 122113.
|
||||||
|
|
||||||
|
## PAN-113631
|
||||||
|
|
||||||
|
A security-related fix was made to address a use-after-free (UAF) vulnerability in the Linux kernel ([PAN-SA-2019-0017](https://securityadvisories.paloaltonetworks.com/Home/Detail/155) / CVE-2019-8912).
|
||||||
|
|
||||||
|
## PAN-113619
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect gateway did not assign an IP address when the local IP address was a supernet of the GlobalProtect pool.
|
||||||
|
|
||||||
|
## PAN-113614
|
||||||
|
|
||||||
|
Fixed an issue with a memory leak on Panorama appliances associated with commits that eventually caused an unexpected restart of the configuration (configd) process.
|
||||||
|
|
||||||
|
## PAN-113340
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-200 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the management plane (MP) memory was lower than expected, which caused the MP to restart.
|
||||||
|
|
||||||
|
## PAN-113189
|
||||||
|
|
||||||
|
A security-related fix was made to correct log file string-conversion errors that caused parsing issues, which caused the User-ID (useridd) process to stop running.
|
||||||
|
|
||||||
|
## PAN-113046
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a process (brdagent) stopped responding, which caused the management plane to stop responding.
|
||||||
|
|
||||||
|
## PAN-112674
|
||||||
|
|
||||||
|
Fixed an issue where an escape ( \ ) character was added to HTTP logs when a log contained a comma.
|
||||||
|
|
||||||
|
## PAN-112577
|
||||||
|
|
||||||
|
Fixed an issue on a VM-Series firewall in a high availability (HA) active/passive configuration where the HA1 port flapped and caused a split-brain condition.
|
||||||
|
|
||||||
|
## PAN-112446
|
||||||
|
|
||||||
|
Fixed an issue where a predefined report (blocked credential post) generated reports using the incorrect query builder (flags has credential-builder), which caused the report to incorrectly display logs for alerts.
|
||||||
|
|
||||||
|
## PAN-112319
|
||||||
|
|
||||||
|
Fixed an issue where a race condition caused a process (mgmtsrvr) to restart with an error message: Connecting to management server failed.
|
||||||
|
|
||||||
|
## PAN-112274
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) stopped responding when a role-based user with privacy settings disabled, viewed a scheduled report that required data anonymization.
|
||||||
|
|
||||||
|
## PAN-112167
|
||||||
|
|
||||||
|
Fixed an issue where IPv4 BGP routes were missing from the routing table and FIB after a failover event.
|
||||||
|
|
||||||
|
## PAN-111976
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to generate user activity reports when the username included the colon ( : ), ampersand ( & ), and single parenthesis ( ' ) characters.
|
||||||
|
|
||||||
|
## PAN-111930
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/active configuration where packets looped due to a higher than expected CPU rate.
|
||||||
|
|
||||||
|
## PAN-111708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a rare software issue that caused the dataplane to restart unexpectedly. To leverage this fix, you must run the debug dataplane set pow no-desched yes CLI command (increases CPU utilization).
|
||||||
|
|
||||||
|
## PAN-111553
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where the **Include Device and Network Templates** setting (**Commit** > **Push to Devices** > **Edit Selections** or **Commit** > **Commit and Push** > **Edit Selections**) was disabled by default and caused your push attempts to fail. With this fix, your push will Include Device and Network Templates by default.
|
||||||
|
|
||||||
|
## PAN-111540
|
||||||
|
|
||||||
|
Fixed an issue on PA-5200 Series firewalls where the dataplane stopped responding when the session table was full.
|
||||||
|
|
||||||
|
## PAN-111468
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to save host information profile (HIP) reports due to a folder permission error.
|
||||||
|
|
||||||
|
## PAN-111308
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where you were able to push and commit the log forwarding configuration to firewalls that did not support it.
|
||||||
|
|
||||||
|
## PAN-111286
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to generate a custom report (**Monitor** > **Manage Custom Report** > **<device-name>** > **Report Setting**).
|
||||||
|
|
||||||
|
## PAN-111084
|
||||||
|
|
||||||
|
Fixed an issue where an out-of-memory condition caused all IPSec tunnels (which includes IKEv1, IKEv2, and NAT-T) to stop responding.
|
||||||
|
|
||||||
|
## PAN-110962
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) stopped responding when SSH decryption was enabled, which caused the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-110638
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to establish a GlobalProtect connection on IPv6 and displayed the following error message: Packet too big due to the firewall MTU value set lower than normal on the neighboring firewall.
|
||||||
|
|
||||||
|
## PAN-110548
|
||||||
|
|
||||||
|
Fixed an intermittent issue where heartbeats failed on the management plane (MP), which caused the dataplane to stop responding and displayed the following error message: Dataplane is down: controlplane exit failure.
|
||||||
|
|
||||||
|
## PAN-110168
|
||||||
|
|
||||||
|
Fixed an issue where the firewall and Panorama web interface did not present HSTS headers to your web browser.
|
||||||
|
|
||||||
|
## PAN-109926
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped HTTPS connections to GlobalProtect and did not send an HTTPS redirect, which caused the web browser to timeout.
|
||||||
|
|
||||||
|
## PAN-109853
|
||||||
|
|
||||||
|
Fixed an issue where a log collector settings preference list without an IPv4 address defined, configured an unknown entry and caused connections between log collectors to intermittently bounce.
|
||||||
|
|
||||||
|
## PAN-109746
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the Device Group Syslog server profile template allowed a space between the IP address and URL, which caused pushes to firewalls to fail.
|
||||||
|
|
||||||
|
## PAN-109701
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where the Task Manager web interface did not sort the list of firewalls by name.
|
||||||
|
|
||||||
|
## PAN-109672
|
||||||
|
|
||||||
|
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where the passive firewall received buffered packets while in an idle state when the data plane development kit (DPDK) was enabled.
|
||||||
|
|
||||||
|
## PAN-109663
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall dropped packets when the policy rule was set to allow during a commit or high availability (HA) sync.
|
||||||
|
|
||||||
|
## PAN-109551
|
||||||
|
|
||||||
|
Fixed an issue where group-based policy match stopped responding after a process (useridd) restarted.
|
||||||
|
|
||||||
|
## PAN-109186
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane stopped responding and caused a failover event.
|
||||||
|
|
||||||
|
## PAN-109024
|
||||||
|
|
||||||
|
Fixed an issue where, after you upgrade the firewall from PAN-OS 8.0 to PAN-OS 8.1, firewalls configured with the User-ID™ agent and group mapping incorrectly mapped users to groups.
|
||||||
|
|
||||||
|
## PAN-107677
|
||||||
|
|
||||||
|
Fixed an issue on GlobalProtect where Security Assertion Markup Language (SAML) authentication failed when you used a macOS operating system.
|
||||||
|
|
||||||
|
## PAN-107143
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where a partial commit to the running configuration was successful but did not get applied to the configuration when you added a new address object to an existing address group.
|
||||||
|
|
||||||
|
## PAN-107117
|
||||||
|
|
||||||
|
Fixed an issue where device administrators were unable to manually upload signature files (**Device** > **Dynamic Updates**) and the firewall displayed the following error message: You need superuser privileges to do that.
|
||||||
|
|
||||||
|
## PAN-106914
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where HA1 and HA2 links stopped passing packets, which caused a split-brain condition after an automatic configuration sync.
|
||||||
|
|
||||||
|
## PAN-106543
|
||||||
|
|
||||||
|
Fixed an issue on a firewall in an HA active/active configuration where the show vpn ipsec-sa CLI command incorrectly returned an error message: Server error: An error occurred. See dagger.log for information. when you ran the command on the active secondary firewall.
|
||||||
|
|
||||||
|
## PAN-106141
|
||||||
|
|
||||||
|
Fixed an issue where a firewall was unable to establish an SSH session to a private cloud if you used the M-500 appliance interface configuration ethernet1/1 port.
|
||||||
|
|
||||||
|
## PAN-106019
|
||||||
|
|
||||||
|
Fixed an issue where a process (routed) stopped responding when an incomplete command ran in the XML API.
|
||||||
|
|
||||||
|
## PAN-105737
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.1.7 & 8.1.8 only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where AUX ports remained in Down state after you upgraded to PAN-OS 8.1.7.
|
||||||
|
|
||||||
|
## PAN-104909
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly forwarded traffic when you configured the ingress interface with a QoS policy and the egress interface as a tunnel.
|
||||||
|
|
||||||
|
## PAN-104515
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama web interface took longer than expected to update the Managed Collectors (**Panorama** > **Managed Collectors**) status.
|
||||||
|
|
||||||
|
## PAN-104144
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the management plane (MP) CPU on Panorama and the manged firewall experience higher than expected usage due to the redistribution of User-ID™ and when more than one user was mapped to a single IP address.
|
||||||
|
|
||||||
|
## PAN-103847
|
||||||
|
|
||||||
|
Fixed a memory buffer allocation issue that caused the Session Initiation Protocol (SIP) traffic NAT to stop responding.
|
||||||
|
|
||||||
|
## PAN-103656
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to export threat pcaps generated from Prisma™ Access and the firewall displayed the following error message: File not found.
|
||||||
|
|
||||||
|
## PAN-101598
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Japanese language only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the **Interface Mgmt** (**Network** > **Network Profiles** > **Interface Mgmt**) and **Management Interface Settings** (**Device** > **Setup** > **Interfaces** > **Management**) web interfaces incorrectly displayed Telnet as Temperature.
|
||||||
|
|
||||||
|
## PAN-101215
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to connect to a syslog server over SSL due to a certificate validation error.
|
||||||
|
|
||||||
|
## PAN-100773
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) port on a 20GQ NPC card unexpectedly entered low power mode and did not link up.
|
||||||
|
|
||||||
|
## PAN-99958
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane did not receive enough keep-alive packets as expected, which caused the Syslog server connection to age-out.
|
||||||
|
|
||||||
|
## PAN-99134
|
||||||
|
|
||||||
|
Fixed an issue where temporary files generated during preview changes did not get cleared, which caused disk space issues.
|
||||||
|
|
||||||
|
## PAN-99016
|
||||||
|
|
||||||
|
A security-related fix was made to address the LazyFP state restore vulnerability ([PAN-SA-2019-0017](https://securityadvisories.paloaltonetworks.com/Home/Detail/155) / CVE-2018-3665).
|
||||||
|
|
||||||
|
## PAN-96827
|
||||||
|
|
||||||
|
Fixed an issue where BGP command output formats did not display consistently across different PAN-OS releases.
|
||||||
|
|
||||||
|
## PAN-96790
|
||||||
|
|
||||||
|
Fixed an issue where the FTP data connection was incorrectly matched to the predict session for IPv6 addresses.
|
||||||
|
|
||||||
|
## PAN-96707
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where CRC errors caused traffic issues.
|
||||||
|
|
||||||
|
## PAN-96371
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to connect to GlobalProtect when a certificate did not have a common name.
|
||||||
|
|
||||||
|
## PAN-95534
|
||||||
|
|
||||||
|
Fixed an issue where the firewall could not send syslogs to the syslog server.
|
||||||
|
|
||||||
|
## PAN-95072
|
||||||
|
|
||||||
|
Fixed a log forwarding filter issue where the firewall incorrectly sent logs for policies that were not configured with log forwarding to the syslog server.
|
||||||
|
|
||||||
|
## PAN-94279
|
||||||
|
|
||||||
|
Fixed an issue where a commit with an authentication sequence configured was pushed from Panorama to a firewall and caused the firewall's management server to stop responding.
|
||||||
|
|
||||||
|
## PAN-94059
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not send a complete certificate chain when you configure the Windows User-ID Agent as a Syslog Listener.
|
||||||
|
|
||||||
|
## PAN-91442
|
||||||
|
|
||||||
|
Fixed an issue where an external dynamic list with an invalid IPv6 address range caused commits to fail.
|
||||||
|
|
||||||
|
## PAN-89820
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the Data Filtering (**Monitor** > **Data Filtering**) and Threat Log (**Monitor** > **Threat**) did not display file names when you transferred multiple files into a single session.
|
||||||
|
|
||||||
|
## PAN-88987
|
||||||
|
|
||||||
|
Fixed an issue on the PA-5220 firewall with Dynamic IP and Port (DIPP) NAT where the number of translated IP addresses could not exceed 3,000 or it caused commits to fail.
|
||||||
|
|
||||||
|
## PAN-88487
|
||||||
|
|
||||||
|
Fixed an issue where the firewall stopped enforcing policy after you manually refreshed an External Dynamic List (EDL) that had an invalid IP address or that resided on an unreachable web server.
|
||||||
+28
-1
@@ -475,7 +475,34 @@
|
|||||||
},
|
},
|
||||||
"8": {
|
"8": {
|
||||||
"8.1": {
|
"8.1": {
|
||||||
"addressed": [],
|
"addressed": [
|
||||||
|
"8.1.0_2026-03-16.md",
|
||||||
|
"8.1.1_2026-03-16.md",
|
||||||
|
"8.1.2_2026-03-16.md",
|
||||||
|
"8.1.3_2026-03-16.md",
|
||||||
|
"8.1.4_2026-03-16.md",
|
||||||
|
"8.1.5_2026-03-16.md",
|
||||||
|
"8.1.6-h2_2026-03-16.md",
|
||||||
|
"8.1.9_2026-03-16.md",
|
||||||
|
"8.1.9-h4_2026-03-16.md",
|
||||||
|
"8.1.10_2026-03-16.md",
|
||||||
|
"8.1.12_2026-03-16.md",
|
||||||
|
"8.1.13_2026-03-16.md",
|
||||||
|
"8.1.14-h2_2026-03-16.md",
|
||||||
|
"8.1.15_2026-03-16.md",
|
||||||
|
"8.1.15-h3_2026-03-16.md",
|
||||||
|
"8.1.17_2026-03-16.md",
|
||||||
|
"8.1.19_2026-03-16.md",
|
||||||
|
"8.1.20_2026-03-16.md",
|
||||||
|
"8.1.21_2026-03-16.md",
|
||||||
|
"8.1.21-h3_2026-03-16.md",
|
||||||
|
"8.1.23-h1_2026-03-16.md",
|
||||||
|
"8.1.25_2026-03-16.md",
|
||||||
|
"8.1.25-h1_2026-03-16.md",
|
||||||
|
"8.1.25-h3_2026-03-16.md",
|
||||||
|
"8.1.25.2_2026-03-16.md",
|
||||||
|
"8.1.26-h1_2026-03-16.md"
|
||||||
|
],
|
||||||
"known": []
|
"known": []
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user