diff --git a/reference/PAN-OS/addressed/11.1.10.html b/reference/PAN-OS/addressed/11.1.10.html
index a2edf51..1839bc2 100644
--- a/reference/PAN-OS/addressed/11.1.10.html
+++ b/reference/PAN-OS/addressed/11.1.10.html
@@ -2,8 +2,8 @@
-
+
|
- PAN-288693
+ PAN-308564
|
- Fixed an issue where importing a device configuration into Panorama
- failed with a validation error if the configuration included a shared
- gateway with shared address objects.
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
|
-
+
|
- PAN-286897
+
+ PAN-307795 This issue affects PAN-OS 11.1.10-h7 through 11.1.10-h11.
+
+
|
- Fixed an issue where the
+ On a standalone Panorama, the system incorrectly generates system logs
+ indicating a lost connection to its peer even when High Availability
+ is not configured. You can safely ignore these logs, as they do not
+ affect operations.
+
+ |
+
+
+
+ |
+ PAN-306502
+
+ |
+
+
+ TLS sessions using version 1.2 or earlier may fail when session
+ traffic matches a decryption policy rule with the no-decrypt action
+ under either of the following conditions:
+
+
+
+
+
+ If both of these conditions are met, the session is guaranteed to
+ fail.
+
+
+
+
+ -
+
+ Both HTTP header insertion () and SSL/TLS handshake inspection () are enabled.
+
+
+ -
+
+ Log Successful SSL Handshake
+ is not enabled in the decryption policy rule and neither
+ Block sessions with expired certificates
+ nor
+ Block sessions with untrusted issuers
+ is enabled in the attached decryption profile.
+
+
+
+
+ Workaround: Perform one of the following tasks:
+
+
+ |
+
+
+
+ |
+ PAN-305301
+
+ |
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout
+ notifications used for GlobalProtect SSL tunnels may cause the
pan_task
- process stopped responding when the firewall attempted to forward
- files to the WildFire public cloud, which caused the dataplane to
- experience heartbeat failures.
+ process to stop responding and the dataplane to restart.
- |
-
-
-
- |
- PAN-286475
- |
-
- Fixed an issue where the option to sort sequence numbers was missing
- from Filters prefix list in the
- advanced routing filters.
-
- |
-
-
-
- |
- PAN-285590
- |
-
-
- (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
- only) Fixed an issue where the firewall CPU usage reached 100% after
- upgrading to PAN-OS 11.1.6-h1.
-
- |
-
-
-
- |
- PAN-284840
- |
-
-
- (PA-5220 firewalls only) Fixed an issue where
- custom reports were delayed when sent via email instead of being sent
- at the scheduled time.
-
- |
-
-
-
- |
- PAN-284116
- |
-
-
- Fixed an issue where mTLS decryption bypass did not work when the
- decryption profile was configured with the maximum TLS version as TLS
- 1.3.
-
- |
-
-
-
- |
- PAN-284066
- |
-
-
- Fixed an issue where, after an upgrade, the SNMP polled values for
- IF-MIB::ifInErrors displayed a
- high number of errors that did not match the values in the CLI show
- interface command.
-
- |
-
-
-
- |
- PAN-283789
- |
-
-
- (Firewalls in high availability (HA) configurations only) Fixed an issue where, after an upgrade, the
- mac receive error counter in
- receive incoming errors increased,
- which resulted in SNMP alerts.
-
- |
-
-
-
- |
- PAN-283467
- |
-
-
- (PA-3400 Series firewalls only) Fixed an issue
- where the firewall unexpectedly rebooted and entered maintenance mode
- due to a ctd-agent out-of-memory (OOM) condition. This occurred during
- advanced services load testing and a high volume of IoT EAL log
- forwarding.
-
- |
-
-
-
- |
- PAN-283331
- |
-
-
- Fixed an issue where selective pushes to managed devices failed when
- the User ID Master Device was
- configured.
-
- |
-
-
-
- |
- PAN-282640
- |
-
-
- Fixed an issue where custom reports showed incomplete data when
- exported in CSV format from Panorama.
-
- |
-
-
-
- |
- PAN-281776
- |
-
-
- Fixed an issue on the Panorama web interface where the error message
+ Workaround: Select
PPPoEv6 Client Interface cannot be enabled with DHCPv6 clientNetwork > GlobalProtect > Gateways > < gateway-config> > Agent > < agent-config> > Connection Settings
- was generated when overriding aggregate interfaces even when no DHCPv6
- or PPPoE was configured.
-
- |
-
-
-
- |
- PAN-280698
- |
-
-
- Fixed an issue where the firewall removed the TCP timestamp from
- client hello messages that did not fit in a single packet, which
- resulted in connection issues.
-
- |
-
-
-
- |
- PAN-280532
- |
-
-
- Fixed an issue where, after disabling and re-enabling the external
- syslog server, the TCP session was not resumed, which caused all logs
- that were forwarded to the syslog server to be dropped.
-
- |
-
-
-
- |
- PAN-280335
- |
-
-
- Fixed an issue with an SNMPv3 EngineBoots value discrepancy that
- prevented to SNMP server from logging.
-
- |
-
-
-
- |
- PAN-278981
- |
-
-
- Fixed an issue where DNS domain resolutions experienced intermittent
- delays due to the firewall not connecting to the DNS Security cloud.
-
-
- To use this fix, enable DNS monitoring on the dataplane via the CLI
- command
- debug dnsproxyd enable-rtsig-health-monitor yes.
-
-
- To show the current setting, run the CLI command
- debug dnsproxyd enable-rtsig-health-monitor show. If the
- cfg.general.dns-rtsig-monitor-intervalNotify Before Lifetime Expires (min)
+ and
+ Notify Before Inactivity Logout (min)
- shows a non-zero value, DNS monitoring is enabled.
-
- |
-
-
-
- |
- PAN-276276
- |
-
-
- (PA-450 firewalls only) Fixed an issue where,
- after an upgrade, data that was excluded using the query builder in a
- custom report was still visible in the report, and the logs displayed
- errors related to invalid threat names being queried.
+ to 0.
|
|
- PAN-275601
- |
-
+ PAN-304756
- Fixed an issue where, when Panorama was not internet connected and you
- attempted to upload images to managed firewalls using the
- Validate option, the upload failed
- with the error
- Failed to create multi-upload job. No valid software deploy targets
- found.
-
- |
-
-
-
- |
- PAN-274806
- |
-
-
- (PA-5250 firewalls only) Fixed an issue where
- IPv6 pings experienced a high number of dropped packets when forwarded
- to another dataplane, which resulted in ping failures. This occurred
- when initiating a ping to the link local address of the firewall and
- the packet drop percentage depended on the number of dataplanes.
-
- |
-
-
-
- |
- PAN-274496
- |
-
-
- Fixed an issue where the root partition reached 100% which caused the
- system to become non-functional and fail over even when aggressive
- cleaning was enabled.
-
- |
-
-
-
- |
- PAN-272812
- |
-
-
- Fixed an issue where SNMP monitoring of tunnel interfaces displayed
- zero values for received bytes and packets.
-
- |
-
-
-
- |
- PAN-271560
- |
-
-
- Fixed an issue where DNS requests to malware sites were not blocked as
- expected, and the
- dns-security-categories log-level
- and action displayed default values instead of
- unavailable.
-
- |
-
-
-
- |
- PAN-271215
- |
-
-
- A fix was made to address
+ This issue is now resolved. See
CVE-2025-4230PAN-OS 11.1.13-h1 Addressed Issues.
|
-
-
-
- |
- PAN-270379
- |
- Fixed an issue where socket files created in the /tmp directory were
- not cleared.
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
|
-
+
|
- PAN-269155
+ PAN-304576
|
- Fixed an issue where an OOM condition occurred, which caused processes
- to stop responding.
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
|
-
+
|
- PAN-269139
+ PAN-303959
|
- (Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
- environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
- mac receive error counter increased
- without an error even though traffic was not impacted.
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
|
-
+
|
- PAN-268922
+ PAN-303051
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues
|
- (PA-3220 firewalls in HA configurations only)
- Fixed an intermittent issue where the firewalls went out of sync after
- a configuration push from Panorama.
+ The reportd process experiences a
+ memory leak because it retains memory that was temporarily used for
+ report generation. Once a task is complete, the process fails to
+ release this memory for reuse, leading to continuous accumulation and
+ eventual memory exhaustion on the Panorama device.
|
-
+
|
- PAN-268680
+ PAN-298505
+
|
- Fixed an issue where the
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
+
+
+ |
+ PAN-297295
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+ - D3_v2/DS3_v2 to D8ds_v5
+ - D4_v2/DS4_v2 to D8ds_v5
+ - D5_v2/DS5_v2 to D16ds_v5
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+
+
+
+ |
+
+
+
+ |
+ PAN-296977
+
+ |
+
+
+ When you apply a filter in
+ Network > Interfaces and then try
+ to view Ethernet interface details
+ using the web interface, the web interface becomes unresponsive.
+
+ |
+
+
+
+ |
+ PAN-294179
+
+ |
+
+ On the Panorama Config Audit page,
+ some commit versions might display incorrect or missing data. Fields
+ such as, COMMITTED BY,
+ COMMIT DATE, and
+ OBJECT CHANGES
+ might not be visible for some commit versions. Sometimes, commit
+ versions can disappear after a refresh and the commit description field
+ might display corrupted characters.
+ |
+
+
+
+ |
+ PAN-293673
+
+ |
+
+ When the firewall generates a high volume of logs and attempts to export
+ these logs to an FTP server, it may consume excessive memory leading to
+ all PAN-OS processes crashing.
+ |
+
+
+
+ |
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
+
+
+ |
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
+
+
+ |
+ PAN-290996
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
+
+
+ |
+ PAN-290235
+
+ |
+
+
+ The
configddscd
- process stopped responding when a configuration merge operation
- changed.
+ process crashes continuously on MIPS platforms (for example, PA-850
+ firewalls) due to a runtime error related to an invalid memory address
+ or nil pointer dereference. This occurs when the golang library
+ upgrade in CIE is not compatible with the MIPS platform.
|
-
+
|
- PAN-268032
+ PAN-290088
+
|
- Fixed an issue where importing a device configuration into Panorama
- failed with a validation error if the configuration included a shared
- gateways containing NAT/PBF rules.
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
- To use this fix:
-
+ |
+
+
+
+ |
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
+
+
+ |
+ PAN-288097
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
+
+
+ |
+ PAN-287056
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
+
+
+ |
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
+
+
+ |
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
+
+
+ |
+ PAN-286306
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
+
+
+ |
+ PAN-286231
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+ -
+
+ When you run Commit and Push operations as a
+ single action.
+
+
+ -
+
+ When you trigger multiple parallel commit-all jobs at the same
+ time.
+
+
+ -
+
+ Device groups and templates have different configuration
+ synchronization versions.
+
+
+
+
+
+ Workaround: Perform one of the following steps:
+
+
-
- Enable the configuration. Commit failures may occur if the device is
- not able to support the number of objects.
+ Perform commit and push as two separate, sequential steps.
+
+ - Perform a full push instead of selective push.
+
+ |
+
+
+
+ |
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
+
+
+ |
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
+
+
+ |
+ PAN-282854
+
+ |
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log
+ collectors in a multi-collector environment.
+
+ Workaround: Restart all the involved log collectors.
+ |
+
+
+
+ |
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
+ -
+
+ The segmented Client Hello packets arrive out-of-order
+
+
+ -
+
+ The segmented Client Hello packets arrive out-of-order and can be
+ reassembled into a complete Client Hello when the first contiguous
+ segment is formed by NGFW
+
+
+ -
+
+ The first segment of the Client Hello packets is less than 5 bytes
+
+
+ -
+
+ A decryption policy rule excludes this traffic from decryption and
+ a Security policy rule (URL filtering) denies this session
+
+
+
+
+ To enable this fix, run the CLI command
+ bug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
+
+
+ |
+ PAN-279415
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
+
+
+ |
+ PAN-277034
+
+ |
+
+ WildFire reports might not fully display or be downloadable because some
+ static resources fail to load.
+ |
+
+
+
+ |
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
+
+
+ |
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
+
+
+ |
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
+
+
+ |
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
+
+
+ |
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
+
+
+ |
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
+
+
+ |
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
+
+
+ |
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
+
+
+ |
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
+
+
+ |
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
+
+
+ |
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
+
+
+ |
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
+
+
+ |
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
+
+
+ |
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
+
+
+ |
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
+ -
+
+
+ -
+
+ Select Commit and
+ Commit to Panorama.
+
+
+ -
+
+ In the active-primary HA peer
+ Dashboard, click
+ Sync to Peer in the High
+ Availability widget.
+
- - Export and push the device group only.
- - Push the template.
+ |
+
+
+
+ |
+ PAN-207040
+ |
+
- Note: This fix is supported on PAN-OS 10.2 and later releases.
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
|
|
- PAN-264982
+ PAN-206913
|
- (VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the firewall entered maintenance mode after an
- auto-commit when sending an ARP packet through the loopback interface
- using an IPv6 address.
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
|
|
- PAN-263504
+ PAN-206909
|
- Fixed an issue where exporting managed device information from
- Panorama in CSV format included extraneous characters.
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
+ -
+
+
+ -
+
+ Confirm the Dedicated Log Collector is disconnected from Panorama.
+
+
+
+ admin> show panorama-status
+
+ Verify the Connected status
+ is no.
+
+
+
+ -
+
+ Restart the mgmtsrvr process.
+
+
+
+ admin> debug software restart process management-server
+
+
+
+ |
+
+
+
+ |
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
|
|
- PAN-260661
+ PAN-197419
|
- Fixed an issue where daily email reports generated from the custom
- report did not display the report details in PDF or CSV files.
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
|
|
- PAN-209516
+ PAN-196758
|
- Fixed an issue where, when creating an interface, an error occurred
- when you clicked OK without
- providing a value in the Tag field
- even though the field was not displayed as mandatory.
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
+
+
+ |
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
+
+
+ |
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
+
+
+ |
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ |
+
+
+
+ |
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
+
+
+ |
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
+
+
+ |
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ -
+ A scheduled report email contains a Report Group () which includes a SaaS Application Usage report.
+
+ -
+ A scheduled report contains only a SaaS Application Usage Report.
+
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
+ -
+ Select
+
+ and remove all SaaS Application Usage reports from all Report
+ Groups.
+
+ -
+ Select
+
+ and edit the scheduled report email that contains only a SaaS
+ Application Usage report. For the Recurrence, select
+ Disable and click
+ OK.
+
+ Repeat this step for all scheduled report emails that contain only
+ a SaaS Application Usage report.
+
+
+ -
+ Commit.
+
+ (Panorama managed firewalls) Select
+
+
+
+
+ |
+
+
+
+ |
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
+
+
+ |
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
+
+
+ |
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
|
diff --git a/web/data/external_refs.json b/web/data/external_refs.json
index 0b15d1c..32a0de1 100644
--- a/web/data/external_refs.json
+++ b/web/data/external_refs.json
@@ -1,4 +1,9 @@
[
+ {
+ "id": "PAN-307795",
+ "url": "https://www.reddit.com/r/paloaltonetworks/comments/1q2c3wj/comment/nzfba21/",
+ "display": "Reddit"
+ },
{
"id": "PAN-290235",
"url": "https://www.reddit.com/r/paloaltonetworks/comments/1qi7zoy/pan290235_dscd_and_low_quality_control/",