diff --git a/reference/PAN-OS/addressed/11.1.10.html b/reference/PAN-OS/addressed/11.1.10.html index a2edf51..1839bc2 100644 --- a/reference/PAN-OS/addressed/11.1.10.html +++ b/reference/PAN-OS/addressed/11.1.10.html @@ -2,8 +2,8 @@ - - + + @@ -17,26 +17,171 @@ - + -
PAN-288693
+
PAN-308564
- Fixed an issue where importing a device configuration into Panorama - failed with a validation error if the configuration included a shared - gateway with shared address objects. + Packets are dropped on SD-WAN interfaces if they require fragmentation + for an interface but have the + Don't Fragment (DF) bit set. This + results in unexpected packet drops. This affects client to server + sessions when using SD-WAN for NGFW. +
+
+ Workaround: Allow fragmenting packets with DF bit + set (debug dataplane set ip4-ignore-df yes).
- + -
PAN-286897
+
+ PAN-307795 This issue affects PAN-OS 11.1.10-h7 through 11.1.10-h11. +
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h12 Addressed Issues. +
- Fixed an issue where the + On a standalone Panorama, the system incorrectly generates system logs + indicating a lost connection to its peer even when High Availability + is not configured. You can safely ignore these logs, as they do not + affect operations. +
+ + + + + +
PAN-306502
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h10 Addressed Issues. +
+ + +
+ TLS sessions using version 1.2 or earlier may fail when session + traffic matches a decryption policy rule with the no-decrypt action + under either of the following conditions: +
+
+ +
+
+ If both of these conditions are met, the session is guaranteed to + fail. +
+
+
+ +
+ Workaround: Perform one of the following tasks: +
+ + + + + + +
PAN-305301
+
+ This issue is now resolved. See + PAN-OS 11.1.10-h12 Addressed Issues. +
+ + +
+ The timing of GlobalProtect lifetime expiry or inactivity logout + notifications used for GlobalProtect SSL tunnels may cause the pan_task - process stopped responding when the firewall attempted to forward - files to the WildFire public cloud, which caused the dataplane to - experience heartbeat failures. + process to stop responding and the dataplane to restart.
- - - - - -
PAN-286475
- -
- Fixed an issue where the option to sort sequence numbers was missing - from Filters prefix list in the - advanced routing filters. -
- - - - - -
PAN-285590
- - -
- (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments - only) Fixed an issue where the firewall CPU usage reached 100% after - upgrading to PAN-OS 11.1.6-h1. -
- - - - - -
PAN-284840
- - -
- (PA-5220 firewalls only) Fixed an issue where - custom reports were delayed when sent via email instead of being sent - at the scheduled time. -
- - - - - -
PAN-284116
- - -
- Fixed an issue where mTLS decryption bypass did not work when the - decryption profile was configured with the maximum TLS version as TLS - 1.3. -
- - - - - -
PAN-284066
- - -
- Fixed an issue where, after an upgrade, the SNMP polled values for - IF-MIB::ifInErrors displayed a - high number of errors that did not match the values in the CLI show - interface command. -
- - - - - -
PAN-283789
- - -
- (Firewalls in high availability (HA) configurations only) Fixed an issue where, after an upgrade, the - mac receive error counter in - receive incoming errors increased, - which resulted in SNMP alerts. -
- - - - - -
PAN-283467
- - -
- (PA-3400 Series firewalls only) Fixed an issue - where the firewall unexpectedly rebooted and entered maintenance mode - due to a ctd-agent out-of-memory (OOM) condition. This occurred during - advanced services load testing and a high volume of IoT EAL log - forwarding. -
- - - - - -
PAN-283331
- - -
- Fixed an issue where selective pushes to managed devices failed when - the User ID Master Device was - configured. -
- - - - - -
PAN-282640
- - -
- Fixed an issue where custom reports showed incomplete data when - exported in CSV format from Panorama. -
- - - - - -
PAN-281776
- - -
- Fixed an issue on the Panorama web interface where the error message + Workaround: Select PPPoEv6 Client Interface cannot be enabled with DHCPv6 clientNetwork > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings - was generated when overriding aggregate interfaces even when no DHCPv6 - or PPPoE was configured. -
- - - - - -
PAN-280698
- - -
- Fixed an issue where the firewall removed the TCP timestamp from - client hello messages that did not fit in a single packet, which - resulted in connection issues. -
- - - - - -
PAN-280532
- - -
- Fixed an issue where, after disabling and re-enabling the external - syslog server, the TCP session was not resumed, which caused all logs - that were forwarded to the syslog server to be dropped. -
- - - - - -
PAN-280335
- - -
- Fixed an issue with an SNMPv3 EngineBoots value discrepancy that - prevented to SNMP server from logging. -
- - - - - -
PAN-278981
- - -
- Fixed an issue where DNS domain resolutions experienced intermittent - delays due to the firewall not connecting to the DNS Security cloud. -
-
- To use this fix, enable DNS monitoring on the dataplane via the CLI - command - debug dnsproxyd enable-rtsig-health-monitor yes. -
-
- To show the current setting, run the CLI command - debug dnsproxyd enable-rtsig-health-monitor show. If the - cfg.general.dns-rtsig-monitor-intervalNotify Before Lifetime Expires (min) + and + Notify Before Inactivity Logout (min) - shows a non-zero value, DNS monitoring is enabled. -
- - - - - -
PAN-276276
- - -
- (PA-450 firewalls only) Fixed an issue where, - after an upgrade, data that was excluded using the query builder in a - custom report was still visible in the report, and the logs displayed - errors related to invalid threat names being queried. + to 0.
-
PAN-275601
- - +
PAN-304756
- Fixed an issue where, when Panorama was not internet connected and you - attempted to upload images to managed firewalls using the - Validate option, the upload failed - with the error - Failed to create multi-upload job. No valid software deploy targets - found. -
- - - - - -
PAN-274806
- - -
- (PA-5250 firewalls only) Fixed an issue where - IPv6 pings experienced a high number of dropped packets when forwarded - to another dataplane, which resulted in ping failures. This occurred - when initiating a ping to the link local address of the firewall and - the packet drop percentage depended on the number of dataplanes. -
- - - - - -
PAN-274496
- - -
- Fixed an issue where the root partition reached 100% which caused the - system to become non-functional and fail over even when aggressive - cleaning was enabled. -
- - - - - -
PAN-272812
- - -
- Fixed an issue where SNMP monitoring of tunnel interfaces displayed - zero values for received bytes and packets. -
- - - - - -
PAN-271560
- - -
- Fixed an issue where DNS requests to malware sites were not blocked as - expected, and the - dns-security-categories log-level - and action displayed default values instead of - unavailable. -
- - - - - -
PAN-271215
- - -
- A fix was made to address + This issue is now resolved. See CVE-2025-4230PAN-OS 11.1.13-h1 Addressed Issues.
- - - - -
PAN-270379
-
- Fixed an issue where socket files created in the /tmp directory were - not cleared. + After you disable the shared optimization feature in Panorama, ensure + that you perform a full configuration push to all managed multi-vsys + devices to re-establish a baseline. Failure to include every device + group associated with the multi-vsys device during this push might + result in incomplete or inconsistent configurations across virtual + systems.
- + -
PAN-269155
+
PAN-304576
- Fixed an issue where an OOM condition occurred, which caused processes - to stop responding. + Traffic interruption may occur when inspection of HTTP/2 traffic is + enabled. +
+
+ Workaround: Disable HTTP/2 server push using the + set deviceconfig setting http2 server-push no + CLI command.
- + -
PAN-269139
+
PAN-303959
- (Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM - environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the - mac receive error counter increased - without an error even though traffic was not impacted. + Traffic that is incorrectly identified as unknown-tcp/unknown-udp + eventually drops due to an App-ID resource limitation issue.
- + -
PAN-268922
+
PAN-303051
+ This issue is now resolved. See + PAN-OS 11.1.13 Addressed Issues
- (PA-3220 firewalls in HA configurations only) - Fixed an intermittent issue where the firewalls went out of sync after - a configuration push from Panorama. + The reportd process experiences a + memory leak because it retains memory that was temporarily used for + report generation. Once a task is complete, the process fails to + release this memory for reuse, leading to continuous accumulation and + eventual memory exhaustion on the Panorama device.
- + -
PAN-268680
+
PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.1.10-h7 Addressed Issuesand + PAN-OS 11.1.12 Addressed Issues +
- Fixed an issue where the + After upgrading multi-vsys firewalls, the sequence of the virtual + system IDs (vsys ID) changes causing auto-commit failures with + validation errors. This occurs when the multi-vsys firewall has + virtual systems managed by Panorama, and the vsys ID sequence breaks + when unused virtual systems are deleted and the changes are pushed to + the firewall. +
+ + + + + +
PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.1.13 Addressed Issues +
+ + + (VM-Series firewalls on Microsoft Azure environments only) +
+ After upgrading to an affected release, the firewall restarts + continuously because the + brdagent process restarts multiple + times and exhausts its restart limit, resulting in a segfault error. + This issue occurs when a high burst of traffic is sent to the Azure + PA-VM (Palo Alto Networks Virtual Machine), and impacts production + environments due to the regular reboots. +
+
+ Workaround: Migrate the VM instance to Dv5 + instance type. On these instance types, SYN packets are not routed to + the synthetic path, avoiding this condition. Suggested direct resizing + paths are: + +
+ +
+
+ Azure VMs with ephemeral storage can only be resized to another + type with ephemeral storage. +
+
+
+
+ + + + + +
PAN-296977
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+ + +
+ When you apply a filter in + Network > Interfaces and then try + to view Ethernet interface details + using the web interface, the web interface becomes unresponsive. +
+ + + + + +
PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues. +
+ + + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + + + + + +
PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
+ + + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + + + + + +
PAN-292202
+ + +
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due + to log overflow` due to the SNMP counters rolling over. This is a + benign message and does not impact device functionality. +
+ + + + + +
PAN-289432
+ + +
+ Generating a certificate with the + block-private-key yes command on + Panorama fails with the error: +
+
+ Could not get parameters for double encryption. + This occurred when the certificate was signed by an external + Certificate Authority (CA). +
+ + + + + +
PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues + and + PAN-OS 11.1.11 Addressed Issues. +
+ + +
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+ + + + + +
PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues. +
+ + +
+ The configddscd - process stopped responding when a configuration merge operation - changed. + process crashes continuously on MIPS platforms (for example, PA-850 + firewalls) due to a runtime error related to an invalid memory address + or nil pointer dereference. This occurs when the golang library + upgrade in CIE is not compatible with the MIPS platform.
- + -
PAN-268032
+
PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
- Fixed an issue where importing a device configuration into Panorama - failed with a validation error if the configuration included a shared - gateways containing NAT/PBF rules. + When pushing configurations from Panorama to a firewall, a memory leak + might occur in the firewall's + configd process, particularly when the + configurations contain shared policies. Each configuration push causes + the configd process to consume + additional memory that is not released after the commit completes.
-
To use this fix:
-
    + + + + + +
    PAN-289383
    + + +
    + (PA-800 series firewalls only) Upgrading + firewalls to PAN-OS 11.0 or later causes SFP ports to go + non-operational when the firewall uses forced port mode and the + connected peer device operates without auto-negotiation. +
    +
    + Workaround: Enable auto-negotiation on the + connected peer firewall. +
    + + + + + +
    PAN-288097
    +
    + This issue is now resolved. See + PAN-OS 11.1.11 Addressed Issues +
    + + +
    + Routed process may stop responding after changing MTU or any link + parameters when OSPF and PIM are enabled on the same interface. +
    + + + + + +
    PAN-287056
    +
    + This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues + and + PAN-OS 11.1.11 Addressed Issues. +
    + + +
    + A BGP export policy rule that matches on a next hop fails to block the + advertisement of static routes, and the firewall incorrectly matches + the egress interface IP address instead of the original next-hop IP + address of the static route, which causes the deny rule to fail. +
    + + + + + +
    PAN-286848
    + + +
    + ECMP incorrectly balances sessions across links based on the + configured metric, which leads to an imbalance in traffic distribution + and results in traffic assignment shifting disproportionately to + routes with lower metrics. +
    + + + + + +
    PAN-286496
    + + +
    + (NGFW Clusters) URL-continue and override + continue selections will function like a general URL-block action. +
    + + + + + +
    PAN-286306
    +
    + This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues + and + PAN-OS 11.1.11 Addressed Issues. +
    + + +
    + When getting transceiver information from ESCC for SFP 25G modules, + the transceiver code incorrectly displays + Unknown instead of + 25GBase-SR. +
    + + + + + +
    PAN-286231
    +
    + This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
    + + +
    + When performing a partial Commit and Push on + Panorama, there is a risk that unintended configuration changes might + be pushed to a firewall. +
    +
    + This issue is more likely to occur in the following scenarios: + +
    +
    + Workaround: Perform one of the following steps: +
    + + + + + + +
    PAN-285894
    + + +
    + If the Preserve Pre-NAT feature is enabled, dataplane crashes may + occur, which could result in firewall reboots. +
    +
    + Workaround: Disable the Preserve Pre-NAT feature + using the + set deviceconfig setting preserve-prenat-feature no + CLI command. +
    + + + + + +
    PAN-283429
    + + +
    + When you use custom certificates for the connection between Panorama + and a log collector, the automated renewal for the predefined + ElasticSearch certificates gets disrupted. +
    +
    + Workaround: Remove the custom certificates before + the ElasticSearch certificates expire. This allows the system to + correctly identify and renew the predefined ElasticSearch + certificates. After the renewal is complete, re-install the custom + certificates. +
    + + + + + +
    PAN-282854
    +
    + This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
    + + +
    + The Elasticsearch cluster fails to start after deploying dedicated log + collectors in a multi-collector environment. +
    + Workaround: Restart all the involved log collectors. + + + + + +
    PAN-279901
    + + +
    + When decryption is enabled, segmented Client Hello packets can cause + website access issues and memory leaks under the following conditions: +
    + +
    + To enable this fix, run the CLI command + bug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
    + + + + + +
    PAN-279415
    +
    + This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues +
    + + +
    + Service routes configured for a data plane interface might incorrectly + route traffic through the management plane interface instead. This + issue impacts Syslog and CRL status traffic when the service route + lacks a specific destination custom service route. +
    + + + + + +
    PAN-277034
    +
    + This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues +
    + + + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + + + + + +
    PAN-276920
    + + +
    + URL filtering response pages may load slowly or fail to display when + users request websites that are blocked in the URL Filtering profile + (site access for the corresponding URL category is + block, + continue, or + override) attached to the matching + Security policy rule. This occurs on an intermittent basis. +
    + + + + + +
    PAN-275047
    + + +
    + (VM-Series firewalls only) After an upgrade, + the firewall is unable to send logs to the Strata Logging Service + (SLS) when using a specific proxy server, and the SSL connection + status displays as failed when attempting to forward logs through the + web proxy. +
    + + + + + +
    PAN-262556
    + + +
    + The ElasticSearch cluster health status might continue to remain + yellow for an extended period after upgrading to PAN-OS 11.1 +
    + + + + + +
    PAN-260851
    + + +
    + From the NGFW or Panorama CLI, you can override the existing + application tag even if Disable Override is enabled for the + application (ObjectsApplications) tag. +
    + + + + + +
    PAN-254240
    + + +
    + In the event of an HSCI flap on an NGFW cluster node, traffic + reconvergence takes three to four seconds. +
    + + + + + +
    PAN-253963
    + + +
    + The auto commit job may take longer than expected to complete when the + Panorama management server is in Panorama or Log Collector mode. +
    + + + + + +
    PAN-251551
    + + +
    + When an NGFW cluster agent crashes and doesn't recover, leader + election will take approximately 45 seconds to begin and traffic + failover will occur during that time. +
    + + + + + +
    PAN-250903
    + + +
    + In a congestion scenario on an HSCI port of an NGFW cluster node, the + QoS priorities of cross node traffic streams might be reversed if + you're using the default QoS profile with class1 to class8 set as high + to low. +
    + + + + + +
    PAN-247974
    + + +
    + LACP flap is expected during a device failover in an NGFW cluster due + to an L2 ctrld restart on the new leader node. +
    + + + + + +
    PAN-234015
    + + +
    + The X-Forwarded-For (XFF) value is not displayed in traffic logs. +
    + + + + + +
    PAN-224502
    + + +
    + The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 + might take longer than expected. +
    + + + + + +
    PAN-220180
    + + +
    + Configured botnet reports (MonitorBotnet) are not generated. +
    + + + + + +
    PAN-207733
    + + +
    + When a DHCPv6 client is configured on HA Active/Passive firewalls, if + the DHCPv6 server goes down, after the lease time expires, the DHCPv6 + client should enter SOLICIT state on both the Active and Passive + firewalls. Instead, the client is stuck in BOUND state with an IPv6 + address having lease time 0 on the Passive firewall. +
    + + + + + +
    PAN-207611
    + + +
    + When a DHCPv6 client is configured on HA Active/Passive firewalls, the + Passive firewall sometimes crashes. +
    + + + + + +
    PAN-207442
    + + +
    + For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the + active-primary HA peer + configuration sync to the + secondary-passive HA peer may + fail. When the config sync fails, the job Results is + Successful + (Tasks), however the sync status on + the Dashboard displays as + Out of Sync for both HA peers. +
    +
    + Workaround: Perform a local commit on the + active-primary HA peer and then + synchronize the HA configuration. +
    +
      +
    1. +
      + Log in to the Panorama web interface + of the active-primary HA + peer. +
      +
    2. +
    3. +
      + Select Commit and + Commit to Panorama. +
      +
    4. +
    5. +
      + In the active-primary HA peer + Dashboard, click + Sync to Peer in the High + Availability widget. +
    6. -
    7. Export and push the device group only.
    8. -
    9. Push the template.
    + + + + + +
    PAN-207040
    + +
    - Note: This fix is supported on PAN-OS 10.2 and later releases. + If you disable Advanced Routing, remove logical routers, and downgrade + from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent + commits fail and SD-WAN devices on Panorama have no Virtual Router + name.
    -
    PAN-264982
    +
    PAN-206913
    - (VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the firewall entered maintenance mode after an - auto-commit when sending an ARP packet through the loopback interface - using an IPv6 address. + When a DHCPv6 client is configured on HA Active/Passive firewalls, + releasing the IPv6 address from the client (using Release in the UI or + using the + request dhcp client ipv6 release all + CLI command) releases the IPv6 address from the Active firewall, but + not the Passive firewall.
    -
    PAN-263504
    +
    PAN-206909
    - Fixed an issue where exporting managed device information from - Panorama in CSV format included extraneous characters. + The Dedicated Log Collector is unable to reconnect to the Panorama + management server if the configd + process crashes. This results in the Dedicated Log Collector losing + connectivity to Panorama despite the managed collector connection + Status (PanoramaManaged Collector) displaying connected and the + managed colletor Health status + displaying as healthy. +
    +
    + This results in the local Panorama config and system logs not being + forwarded to the Dedicated Log Collector. Firewall log forwarding to + the disconnected Dedicated Log Collector is not impacted. +
    +
    + Workaround: Restart the + mgmtsrvr process on the Dedicated + Log Collector. +
    +
      +
    1. + +
    2. +
    3. +
      + Confirm the Dedicated Log Collector is disconnected from Panorama. +
      + +
      +
      admin> show panorama-status
      +
      + Verify the Connected status + is no. +
      +
      +
    4. +
    5. +
      + Restart the mgmtsrvr process. +
      + +
      +
      admin> debug software restart process management-server
      +
      +
    6. +
    + + + + + +
    PAN-197588
    + + +
    + The PAN-OS ACC (Application Command Center) does not display a widget + detailing statistics and data associated with vulnerability exploits + that have been detected using inline cloud analysis.
    -
    PAN-260661
    +
    PAN-197419
    - Fixed an issue where daily email reports generated from the custom - report did not display the report details in PDF or CSV files. + (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a + Tag value.
    -
    PAN-209516
    +
    PAN-196758
    - Fixed an issue where, when creating an interface, an error occurred - when you clicked OK without - providing a value in the Tag field - even though the field was not displayed as mandatory. + On the Panorama management server, pushing a configuration change to + firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP + configurations for SD-WAN as being edited or deleted despite no edits + or deletions being made when you + Preview Changes (CommitPush to DevicesEdit Selections + or + CommitCommit and PushEdit Selections). +
    + + + + + +
    PAN-195968
    + + +
    + (PA-1400 Series firewalls only) When using the + CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI + prints an error depending on whether an interface type was selected on + the non-PoE port or not. If an interface type, such as tap, Layer 2, + or virtual wire, was selected before PoE was configured, the error + message will not include the interface name (eg. ethernet1/4). If an + interface type was not selected before PoE was configured, the error + message will include the interface name. +
    + + + + + +
    PAN-194978
    + + +
    + (PA-1400 Series firewalls only) In + NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) + Link State icon does not display + link speed and link duplex details. +
    + + + + + +
    PAN-187685
    + + +
    + On the Panorama management server, the Template Status displays no + synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. +
    +
    + Workaround: After the bootstrapped firewall is + successfully added to Panorama, + log in to the Panorama web interface + and select + CommitPush to Devices. +
    + + + + + +
    PAN-187407
    + + +
    + The configured Advanced Threat Prevention inline cloud analysis action + for a given model might not be honored under the following condition: + If the firewall is set to + Hold client request for category lookup and the action set to + Reset-Both and the URL cache has + been cleared, the first request for inline cloud analysis will be + bypassed. +
    + + + + + +
    PAN-186283
    + + +
    + Templates appear out-of-sync on Panorama after successfully deploying + the CFT stack using the Panorama plugin for AWS. +
    +
    + Workaround: Use + CommitPush to Devices + to synchronize the templates. +
    + + + + + +
    PAN-184708
    + + +
    + Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: +
    + +
    + Workaround: To receive a scheduled report email + for all other PDF report types: +
    +
      +
    1. + Select + MonitorPDF ReportsReport Groups + and remove all SaaS Application Usage reports from all Report + Groups. +
    2. +
    3. + Select + MonitorPDF ReportsEmail Scheduler + and edit the scheduled report email that contains only a SaaS + Application Usage report. For the Recurrence, select + Disable and click + OK. +
      + Repeat this step for all scheduled report emails that contain only + a SaaS Application Usage report. +
      +
    4. +
    5. + Commit. +
      + (Panorama managed firewalls) Select + CommitCommit and Push +
      +
    6. +
    + + + + + +
    PAN-184406
    + + +
    + Using the CLI to add a RAID disk pair to an M-700 appliance causes the + dmdb process to crash. +
    +
    + Workaround: Contact customer support to stop the + dmdb process before adding a RAID disk pair to a M-700 appliance. +
    + + + + + +
    PAN-183404
    + + +
    + Static IP addresses are not recognized when "and" operators are used + with IP CIDR range. +
    + + + + + +
    PAN-181933
    + + +
    + If you use multiple log forwarding cards (LFCs) on the PA-7000 series, + all of the cards may not receive all of the updates and the mappings + for the clients may become out of sync, which causes the firewall to + not correctly populate the Source User column in the session logs.
    diff --git a/web/data/external_refs.json b/web/data/external_refs.json index 0b15d1c..32a0de1 100644 --- a/web/data/external_refs.json +++ b/web/data/external_refs.json @@ -1,4 +1,9 @@ [ + { + "id": "PAN-307795", + "url": "https://www.reddit.com/r/paloaltonetworks/comments/1q2c3wj/comment/nzfba21/", + "display": "Reddit" + }, { "id": "PAN-290235", "url": "https://www.reddit.com/r/paloaltonetworks/comments/1qi7zoy/pan290235_dscd_and_low_quality_control/",