Add 8.1 addressed issues

This commit is contained in:
2026-04-01 11:57:01 -05:00
parent 6b9a798266
commit 9999443e7d
23 changed files with 2677 additions and 302 deletions
@@ -1,5 +1,5 @@
---
type: Known
type: Addressed
product: PAN-OS
version: 11.1.10
---
@@ -0,0 +1,481 @@
---
type: Addressed
product: PAN-OS
version: 8.1.11
---
## WF500-5137
Fixed an issue where the `show wildfire global last-device-registration all` CLI command incorrectly returned an error message: `Failed`, even when you registered the firewall correctly.
## PAN-126547
Fixed an issue where a process (configd) stopped responding when an XML API call with `type=config&action=get` triggered during a commit.
## PAN-126354
Fixed an issue where log in and commits took longer than expected when you used XML API calls to create new address objects.
## PAN-125517
An enhancement was made to improve firewall performance for stream control transmission protocol (SCTP) flows. To enable this enhancement, run the `set sctp fast-sack yes` CLI command.
## PAN-125346
An enhancement was made to enable you to configure IPv6 in the web interface and through a CLI command when you added IPv6 virtual addresses to a firewall in a high availability (HA) active/active configuration.
## PAN-125069
An enhancement was made to enable you to delete the GTP-C tunnel with all GTP-U tunnel sessions after the firewall received a Delete Bearer Response message where default bearer ID=5. To enable this enhancement, run the `set gtp ebi5-del-gtpc [yes/no]` CLI command.
## PAN-124996
Fixed an issue where a GlobalProtect™ daemon (rasmgr) stopped responding when you connected with an overlapping IPv6 address, which caused subsequent GlobalProtect connections to fail.
## PAN-124658
Fixed an issue where the timer system call activated more frequently than expected, which caused higher than expected CPU usage.
## PAN-124299
Fixed an issue on VM-Series firewalls in an HA active/passive configuration where the active firewall leaked packet buffers when links were disconnected from the hypervisor.
## PAN-123850
```caveat
PA-5200 and PA-7000 Series firewalls only
```
Fixed an issue where conflicting GTP sessions were installed in short interval, which caused the firewall to queue GTP packets and deplete packet buffers.
## PAN-123446
Fixed an issue where an administrator with a Superuser role could not reset administrator credentials.
## PAN-123371
Fixed an issue where the **Wildfire Analysis Report** incorrectly displayed the following error message: `You are not authorized to access this page on the web interface`.
## PAN-123030
Fixed an issue with a memory leak associated with a process (mgmtsrvr) when you pushed a commit.
## PAN-122662
```caveat
PA-5260 firewalls only
```
Fixed an issue where a process (mpreplay) stopped responding after a commit when you configured the firewall with more than 200 virtual systems (vsys) running on PAN-OS® 8.1.9.
## PAN-122601
Fixed a memory leak issue with a process (configd) when you performed device group related operations.
## PAN-122550
Fixed an issue where VM-Series firewalls on Microsoft Azure experienced traffic latency due to an incompatible driver.
## PAN-121911
Fixed an issue where a process (logrcvr) restarted during commits.
## PAN-121523
Fixed an issue where an API call triggered memory errors, which caused a process (configd) to stop responding and triggered `SIGABRT` logs.
## PAN-121447
Fixed an issue where the BGP did not remove the IPv6 default route from the forwarding table after the route was withdrawn.
## PAN-121133
Fixed an issue on Panorama M-Series and virtual appliances where a validation job triggered a memory leak in a process (configd), which caused context switching between Panorama and the web interface to respond slower than expected.
## PAN-121001
Fixed an issue where the firewall only reported a maximum of two logs when you configured more than two hardware security modules (HSM).
## PAN-120901
Fixed an issue on Panorama M-Series and virtual appliances where partial commits did not apply configuration changes as expected.
## PAN-120662
```caveat
PA-7000 Series firewalls using PA-7000-20G-NPC cards only
```
Fixed an intermittent issue where an out-of-memory (OOM) condition caused the dataplane or internal path monitoring to stop responding.
## PAN-120361
Fixed an issue on Panorama M-Series and virtual appliances where objects were not compressed, which caused higher than expected CPU and memory usage.
## PAN-120287
Fixed a JavaScript error due to an incorrect HTTP response, which prevented GlobalProtect Clientless VPN applications to load.
## PAN-120151
Fixed an issue where the DNS packet parser incorrectly processed DNS packet headers when the QD count is 0, which caused the DNS server to stop responding.
## PAN-119862
```caveat
PA-5050 firewalls only
```
Fixed an intermittent issue where an out-of-memory (OOM) condition caused the dataplane or internal path monitoring to stop responding. With this fix, session capacity is reduced by 400,000.
## PAN-119765
Fixed an intermittent issue where the firewall dropped sessions that used a large number of predict sessions.
## PAN-119680
Fixed a rare issue where the `show running` CLI commands for policy addresses caused file descriptor leaks.
## PAN-119647
Fixed an issue where a process (mgmtsrvr) stopped responding due to an out-of-memory (OOM) condition.
## PAN-119225
Fixed an issue where an inaccurate sequence number check for an RST packet caused the packet to drop.
## PAN-119172
Fixed an issue where the firewall incorrectly enforced URL category policies and erroneously triggered **alert** instead of **block**.
## PAN-118985
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) experienced high memory utilization and a memory leak condition, which caused slower than expected performance.
## PAN-118720
Fixed an issue on a firewall in an HA active/active configuration where Oracle traffic SYN packets dropped intermittently with the `flow_fpp_owner_err_no_predict` counter.
## PAN-118583
Fixed a memory allocation issue that prevented URL filtering logs from displaying the full URL.
## PAN-118509
Fixed an issue on Panorama M-Series and virtual appliances where shared policies were out of sync due to an empty stream control transmission protocol (SCTP) after you upgraded the firewall from PAN-OS 8.0.16 to PAN-OS 8.1.8.
## PAN-118180
Fixed an issue on firewalls configured with authentication policies where UDP and ICMP packets matching an authentication policy did not generate traffic logs as defined in the Security policy when sessions were redirected or denied.
## PAN-118057
Fixed an issue on a firewall in an HA active/passive configuration where a process (all_pkts) stopped responding and the dataplane restarted due to an internal path monitoring failure and an HA failover event.
## PAN-118055
Fixed an issue where administrators were unable to export Security Assertion Markup Language (SAML) metadata files from virtual system (vsys) specific authentication profiles.
## PAN-117959
Fixed an issue where LDAP authentication failed when you configured the authentication server with an FQDN.
## PAN-117900
Fixed an issue where commits failed when you moved an object referenced in a policy to a shared group.
## PAN-117888
Fixed an issue where the firewall was unable to detect the hardware security module (HSM), which caused the firewall to drop SSL traffic.
## PAN-117738
```caveat
PA-3050 and PA-3060 firewalls only
```
Fixed an issue where a higher than expected number of `flow_fpga_flow_update` messages occurred when you configured QoS.
## PAN-117727
Fixed an issue where job threads were deadlocked, which prevented log in attempts and displayed the following error message: `CONFIG_LOCK: write lock TIMEDOUT for cmd`.
## PAN-117303
Fixed an issue where the BGP aggregate prefix, which is advertised to multiple BGP peers was removed from RIB OUT when you disabled one of the BGP peers.
## PAN-117120
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) restarted due to virtual memory issues.
## PAN-117086
Fixed an issue where community attributes to BGP routes had a character limit of 31 characters, which caused expressions to take longer than expected to process.
## PAN-117026
Fixed an issue where eBGP peers connected by a VPN tunnel failed to come up when you configured eBGP **Multi Hop** to **0**.
## PAN-116949
Fixed a memory leak issue with a process (mprelay), which caused the dataplane to restart.
## PAN-116903
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to configure **Enable X-Auth Support** (**Network** > **GlobalProtect** > **Gateways** > **Template** > **<Template-stack>** > **Agent** > **Tunnel Settings**) at the Template-stack level.
## PAN-116772
Fixed an issue where the firewall sent empty attributes in the LDAP query when you did not configure **Alternate Username 1 - 3** (**Device** > **User Identification** > **Group Mapping Settings** > **<group-name>** > **User and Group Attributes**) in the User Attributes web interface.
## PAN-116729
Fixed an issue where you were unable to deploy bootstrapped content in offline environments due to content validity checks.
## PAN-116611
Fixed an issue where an API call for correlated events did not return any events.
## PAN-116473
Fixed an issue where the firewall logged URL categories configured for Allow in the URL filtering logs.
## PAN-116384
An enhancement was made to enable firewalls, Panorama management servers, and log collectors running a PAN-OS 8.1 release to receive new App-ID™ signatures in the new ID signature range (7,020,001 to 7,040,000). To enable this enhancement, you must reinstall the current content update or install a later content update.
## PAN-116334
Fixed an issue where a process (mgmtsrvr) leaked memory caused by SNMP traps.
## PAN-116286
Fixed an issue where commits failed after you upgraded from PAN-OS 8.0.16 to PAN-OS 8.1.6 due to an invalid encryption state for a host information profile (HIP) object.
## PAN-116274
Fixed an issue where the firewall was unable to authenticate when you pushed a public key from Panorama.
## PAN-116123
Fixed an issue where a process (devsrvr) stopped responding when you performed a commit or a configuration validation when the proxy ID contained 24 or more characters.
## PAN-115990
Fixed an issue where the FQDN address object (**Policy** > **Security** > **<address-object>** > **Value**) displayed the following unrelated error: `<FQDN-name> Not used`.
## PAN-115959
Fixed an issue where DNS names with more than 63 characters did not resolve FQDN address objects during an FQDN refresh.
## PAN-115890
Fixed an issue where the `show system info` CLI command incorrectly displayed `VMware ESXi` as `VMWare ESXi`.
## PAN-115879
Fixed an issue on a firewall where a bypass switch sent heartbeat messages to the firewall, which triggered non-stop link status change interrupts through a Marvell switch.
## PAN-115738
Fixed an issue where data logs were generated but the firewall did not forward the logs to the syslog server.
## PAN-115697
Fixed CVE-2019-17437, see [PAN-SA-2019-0038](https://securityadvisories.paloaltonetworks.com/Home/Detail/201) for details.
## PAN-115549
Fixed an issue where predict sessions were incorrectly created with a `captive-portal zone`, which caused the firewall to drop RTP traffic.
## PAN-115349
Fixed an issue where an incorrect predict session was created when a policy-based forwarding (PBF) policy was used without a NAT in the parent session, which caused the firewall to drop RTP and RTCP packets.
## PAN-115344
Fixed an issue where the Username Modifier **%USERDOMAIN%\%USERINPUT%** enabled you to log in to a locked out user account.
## PAN-115287
Fixed an issue where commits failed and displayed the following error message: `Commit job was not queued. All daemons are not available`.
## PAN-115282
Fixed an issue where temporary download files were deleted before a download job was completed, which caused the progress bar to remain at 0% and prevented a timeout when downloads fail.
## PAN-115281
Fixed an issue where the firewall did not resolve an external dynamic list server address when the DNS proxy configured it as a static entry.
## PAN-115108
Fixed an issue on Panorama M-Series and virtual appliances where scheduled uploading and installation of WildFire® content meta files to WF-500 appliances failed and displayed the following error message: `device not supported`.
## PAN-114880
Fixed an issue where the `debug management-server summary-logs flush-options max-keys` CLI command did not persist through a system reboot.
## PAN-114856
A change was made to limit debug log visibility to superusers only.
## PAN-114771
Fixed an issue on Panorama M-Series and virtual appliances where **Decrypt Mirror** (**Objects** > **Decryption** > **Decryption Profile** > **<Device Group-name>**) did not appear in the **Interface** drop-down menu when you tried to configure a Decryption Profile.
## PAN-114667
Fixed an issue on a firewall in an HA active/passive configuration where a split-brain condition occurred after you upgraded from PAN-OS 8.1.3 to PAN-OS 8.1.6.
## PAN-114628
Fixed an issue where Panorama was unable to query logs forwarded from the firewall to the log collector.
## PAN-114540
Fixed an issue where renaming a template stack did not change the value and reset to the original value after you commit the change.
## PAN-114456
Fixed an issue where extended packet capture (pcap) for threat logs caused a process (mgmtsrvr) to stop responding.
## PAN-114427
Fixed an issue where an empty host name in the HTTP header caused a web server process (websrvr) to stop responding when you accessed the captive portal redirect page.
## PAN-114270
Fixed an issue where the firewall dropped TCP trace route traffic after you upgraded to PAN-OS 8.1.5. To leverage this fix, run the `set session tcp-reject-diff-syn no` CLI command.
## PAN-114247
Fixed an issue where a larger than expected number of `Could not find entry for interface ethernet1/<interface>.<subinterface> in CPS table` filled the snmpd.log, which caused the log file to rotate more frequently than expected.
## PAN-113610
Fixed an issue where Panorama incorrectly deleted valid device group directories and was unable to generate reports.
## PAN-113606
Fixed an issue where the Throughput column (**Panorama** > **Managed Devices** > **Health**) was incorrectly labeled.
## PAN-113261
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the total entries for the URL filtering allow list, block list, and custom categories was incorrectly changed to a 100,000 entries limit.
## PAN-112661
Fixed an issue where you were unable to access a firewall due to a defective small form-factor pluggable (SFP)/SFP+ module inserted into the firewall.
## PAN-112321
Fixed an issue where a daemon (sslmgr) caused an out-of-memory condition.
## PAN-111850
Fixed an issue where the firewall did not capture the number of packets in the threat packet capture (pcap) as configured in the extended packet capture length setting.
## PAN-111544
Fixed an issue on Panorama M-Series and virtual appliances configured as log collectors where SSH did not respond after you enabled SSH on ethernet1/1.
## PAN-110685
Fixed a rare issue where an incorrect User-ID™ match to the respective LDAP group caused a security policy mismatch.
## PAN-110098
Fixed an issue on a firewall in an HA active/passive configuration where you were unable to synchronize configurations or dynamic updates between HA pairs.
## PAN-109874
Fixed a memory leak issue on a firewall during a commit, which prevented the firewall from generating GlobalProtect client configurations.
## PAN-108876
Fixed an issue where the firewall dropped Session Initiation Protocol (SIP) registration packets, which caused SIP sessions to fail.
## PAN-108488
Fixed an issue where a typo in the MIB definition file caused an error message: `ERROR: Cannot find symbol panSctpDIamAvpCode` when you loaded a PAN-TRAPS.my file.
## PAN-108234
Fixed an issue on a firewall configured with a GlobalProtect gateway where after you upgraded from a PAN-OS 7.1 release to a PAN-OS 8.0 or later release and committed the configuration, the following error message displayed: `SSLVPN: Invalid access-routess (null) in tunnel GPgateway-N`.
## PAN-107330
Fixed an issue where when you configured the **URL Filtering Profile** (**Objects** > **URL Filtering** > **<filter-name>** > **Categories**) to **Shared** all custom URL categories pushed displayed on the web interface and returned the following error message: `test -> credential-enforcement -> allow 'Blocked-Category-Exceptions' is not valid reference test -> credential-enforcement -> allow is invalid`.
## PAN-107207
Fixed an issue where the VPN tunnel operational status incorrectly displayed “`up`" even though the VPN tunnel is down.
## PAN-106889
Fixed a rare issue on a firewall in an HA active/passive configuration running in FIPS-CC mode where the passive firewall rebooted in to maintenance mode.
## PAN-106434
Fixed an issue where a process (keymgr) stopped responding due to missed heartbeats, which caused IPSec tunnels to stop responding.
## PAN-105806
Fixed an issue where the firewall did not detect duplicate Destination/Source IP Addresses entered into the **Security Policy Rule**.
## PAN-105437
Fixed an issue where a process (useridd) ran out of file descriptors and stopped responding due to the rate of concurrent Security Assertion Markup Language (SAML) requests initiated by Authentication policy rules.
## PAN-104178
Fixed an issue on Panorama M-Series and virtual appliances where CLI commands returned the following error message: `Error: Timed out while getting config lock. Please try again` when a commit job was not pending.
## PAN-103500
An enhancement was made to enable the firewalls and Panorama M-Series and virtual appliances to set the SameSite attribute to **Strict** and the GlobalProtect portal to set the SameSite attribute to **Lax**.
## PAN-102195
Fixed an issue where the firewall did not detect all threat sessions while the App and Threat content installation was processed.
## PAN-100977
```caveat
VM-Series NSX edition firewalls only
```
Fixed an issue where the existing logs for dynamic address updates had insufficient information to debug the root cause of a bug and where the dynamic address update logs were larger than expected, which caused the file to roll over every five minutes and did not provide a sufficient log history to debug issues.
## PAN-98584
```caveat
PA-5200 Series and PA-3200 Series firewalls only
```
Fixed a rare issue where invalid packets caused the firewall to stop responding as expected when you configured the dataplane port to traverse HA3 traffic.
## PAN-97784
Fixed an issue on a firewall where repeated failed validation errors were reported for validated configurations due to a race condition.
## PAN-97232
Fixed an issue on a firewall in an HA active/passive configuration where a process (pan_comm) stopped responding when you configured an external dynamic list, which caused commits to fail and displayed the following error message: `failed to handle CONFIG_UPDATE_START`.
## PAN-95230
Fixed an issue where the Security Assertion Markup Language (SAML) schema size limit (100,000 characters) prevented the SAML Identity Provider Server Profile Import (**Device** > **Server Profiles** > **SAML Identity Provider** > **Import**) from importing SAML metadata.
## PAN-90738
Fixed an issue where a process (configd) exceeded the virtual memory usage limit and caused the firewall to restart. With this fix, you must run the `debug management-server system globalfind disable-db-lookup` and `debug management-server system appweb-thread-count enhance` commands.
## PAN-89649
Fixed an issue where Panorama did not send the preference list to managed firewalls, which caused logs to be forwarded to the CMS instead of the log collector.
@@ -0,0 +1,257 @@
---
type: Addressed
product: PAN-OS
version: 8.1.14
---
## WF500-5185
```caveat
WF-500 appliances only
```
Fixed an issue where inadequate rotation of log files caused unusually high disk usage.
## PAN-140270
Added debugging task to periodically collect output (in the Tech Support File (TSF) from the `debug dataplane internal pdt bcm counters graphical` CLI command.
## PAN-139555
Fixed an issue in a high availability (HA) configuration where, after upgrading the passive firewall, the outer UDP sessions synced from the active firewall did not retain rule information and GPRS tunneling protocol (GTP) inspection failed after failover.
## PAN-137673
Fixed an issue where a memory leak associated with the (devsrvr) process caused an out-of-memory (OOM) condition on the firewall.
## PAN-136820
Fixed an issue where an HA failover occurred after the firewall reported the following error message in the System log: `Dataplane down: controlplane exit failure`.
## PAN-136470
Fixed an issue where a process (all_pktproc) restarted and caused the dataplane to restart after processing packets with 0.0.0.0 and destination protocol 251 that internally mapped to GTP-C traffic.
## PAN-135909
Fixed an issue where connections to the web interface were abruptly interrupted due to a double free condition (gPanUiPhpGlobal_secure_config_reset), which led to unexpected process restarts.
## PAN-135684
Fixed an issue with log collectors on Panorama where large indexes caused higher than expected CPU usage when disk space usage was high.
## PAN-134707
Fixed an issue where a commit took longer than expected after upgrading when **Negate** was enabled for addresses in a rule.
## PAN-134547
Fixed an issue where the passive firewall in an active/passive HA configuration deleted BGP-learned routes that were synchronized from the active firewall when the BGP configuration included the redistribution of the learned routes.
## PAN-134431
Fixed an issue with Security Assertion Markup Language (SAML) authentication where the firewall used old `authd_id` values, which resulted in failed authentication.
## PAN-134370
Fixed an issue where a process (mp-relay) restarted due to missing routes or next hops.
## PAN-133289
Fixed an issue where improper parsing of the URL database caused high device-server CPU usage.
## PAN-132898
Fixed an intermittent issue where logs were missing with `log_index` debug messages due to merging of the index.
## PAN-131939
Fixed an issue where the dataplane restarted during file transfer due to one or more content updates being installed at the same time.
## PAN-131922
Fixed an issue where the certificate was not automatically pushed to the firewall until you manually fetched the certificate from the firewall.
## PAN-131517
Fixed an issue with a memory corruption error that caused a process (all_pktproc) to restart.
## PAN-131501
Fixed an issue when configuring Clientless VPN and executing the `portal-getconfig` CLI command where user groups were retrieved but were not freed, which caused a memory leak in the sslvpn process.
## PAN-130750
Fixed an issue where a commit failed on the firewall after disabling **Pre-Defined Reports** from Panorama.
## PAN-130361
A fix was made to address an external control of filename vulnerability in the SD-WAN component of Palo Alto Networks Panorama ([CVE-2020-2009](https://security.paloaltonetworks.com/CVE-2020-2009)).
## PAN-129328
Fixed an issue where packet descriptor (on-chip) usage reached 100% even though buffers, throughput, and session counts were not elevated.
## PAN-129289
Fixed an issue where export failed for a large running-config.xml file using the XML API.
## PAN-128568
Fixed a rare issue where a process (pan_task) restarted due to a NULL pointer exception.
## PAN-128330
Fixed an issue where the response for the XML API call for the `show object registered-ip all` operational CLI command included extra appended content.
## PAN-127614
Fixed an issue where SNMPv3 monitoring of the firewall failed from the Zabbix server after a firewall reboot or SNMP process restart on the firewall.
## PAN-127189
Fixed an issue where images displayed through the Clientless VPN were corrupted.
## PAN-127118
A fix was made to address an OS command line injection vulnerability in the PAN-OS management server where authenticated users were able to inject arbitrary shell commands with root privileges ([CVE-2020-2014](https://security.paloaltonetworks.com/CVE-2020-2014)).
## PAN-127004
Fixed an issue where a process (sysd) restarted due to missing heartbeats.
## PAN-126817
Fixed an issue where Security Assertion Markup Language (SAML) response validation failed with a certificate mismatch error even when the firewall had the same certificate on the identity provider.
## PAN-126362
A fix was made to address a command injection vulnerability in the PAN-OS management interface where an authenticated administrator was able to execute arbitrary OS commands with root privileges ([CVE-2020-2010](https://security.paloaltonetworks.com/CVE-2020-2010)).
## PAN-126205
Fixed an issue where role-based administrators were unable to import certificate private keys onto firewalls.
## PAN-125934
Fixed an issue on Panorama where a commit failed when bootstrapping a firewall to a configuration with a serial number of "unknown." The commit failed with the following error message: `mgt-config -> devices -> unknown unknown is invalid`.
## PAN-125889
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where auto-tagging failed for log forwarding.
## PAN-125794
Fixed an issue where a role-based adminstrator with CLI access was unable to successfully execute the `commit-partial` CLI command to commit only changes made by themselves.
## PAN-125730
Fixed an issue where packets tagged with IP protocol 252 were incorrectly treated as GPRS tunneling protocol (GTP) traffic, which caused the packet processor to terminate.
## PAN-125534
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where firewalls experienced high packet descriptor (on-chip) usage during uploads to the WildFire Cloud or WF-500 appliance.
## PAN-125527
Fixed an issue where multilayer ZIP-file inspection caused software buffer corruption and caused the all_pktproc process to restart.
## PAN-125410
Fixed an issue where a new GPRS tunneling protocol version 2 control plane (GTPv2-C) session reused GTP-C tunnel parameters within two seconds after deleting the old GTP-C session, which caused a session conflict on the firewall.
## PAN-124039
A fix was made to address an issue where the GlobalProtect Portal feature in PAN-OS did not set a new session identifier after a successful user login ([CVE-2020-1993](https://security.paloaltonetworks.com/CVE-2020-1993)).
## PAN-123637
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where configuring 1G small form-factor pluggable (SFP) ports on a firewall with forced speed mode (of 1G) enabled made the link unusable when forced speed mode (of 1G) was also enabled on the peer firewall.
## PAN-122432
Fixed an issue where the firewall failed to correctly read the virtual system (vsys), which eventually resulted in a management server process restart.
## PAN-121626
```caveat
PA-3200 Series firewalls only
```
Fixed an intermittent issue where firewalls dropped packets, which caused issues such as traffic latency, slow file transfers, reduced throughput, internal path monitoring failures, and application failures.
## PAN-119806
Fixed an issue where the dataplane restarted due to internal packet path monitoring failure.
## PAN-118226
A fix was made to address an improper input validation vulnerability in the configuration daemon of Palo Alto Networks Panorama ([CVE-2020-2011](https://security.paloaltonetworks.com/CVE-2020-2011)).
## PAN-117955
A fix was made to address a missing authorization vulnerability in the Panorama management server ([CVE-2020-1996](https://security.paloaltonetworks.com/CVE-2020-1996)).
## PAN-117480
A fix was made to upgrade Nginx software included with PAN-OS ([PAN-SA-2020-0006](https://security.paloaltonetworks.com/PAN-SA-2020-0006) / CVE-2016-4450 and CVE-2013-0337).
## PAN-116480
Fixed an issue in Panorama where the `show system search-engine-quota` CLI command, the `show log-collector serial-number <log-collector_SN>` CLI command, and **Statistics** (**Panorama > Managed Collectors > Statistics**) showed incorrect log retention data.
## PAN-116189
Fixed an issue where Session Initiation Protocol (SIP) calls failed and displayed the following error message: `end-reason : resources-unavailable`.
## PAN-102688
A fix was made to address an OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS ([CVE-2020-2008](https://security.paloaltonetworks.com/CVE-2020-2008)).
## PAN-102682
A fix was made to address an OS command injection vulnerability in the management component of PAN-OS where an authenticated user was able to potentially execute arbitrary commands with root privileges ([CVE-2020-2007](https://security.paloaltonetworks.com/CVE-2020-2007)).
## PAN-100855
A fix was made to address a stack-based buffer overflow vulnerability in the management server component of PAN-OS where an authenticated user was able to execute arbitrary code with root privileges ([CVE-2020-2006](https://security.paloaltonetworks.com/CVE-2020-2006)).
## PAN-100415
A fix was made to address an external control of filename vulnerability in the command processing of PAN-OS ([CVE-2020-2003](https://security.paloaltonetworks.com/CVE-2020-2003)).
## PAN-100006
```caveat
PA-200 firewalls only
```
Fixed an issue where the User-ID™ process caused an out-of-memory (OOM) condition when the number of IP address tags monitored from Amazon Web Services (AWS) VM Monitoring was greater than the maximum supported number.
## PAN-96104
Fixed an issue in the web interface where the language preference reverted to English after logging out from a session that was authenticated by Security Assertion Language Markup (SAML) single sign-on (SSO).
## PAN-88136
Fixed a rare issue where a URL update caused the dataplane to restart.
## PAN-82052
A fix was made to address an open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS ([CVE-2020-1997](https://security.paloaltonetworks.com/CVE-2020-1997)).
## PAN-71148
Fixed an issue on Panorama where the **ACC** tab did not show data for the period before the daylight saving time (DST) change.
@@ -0,0 +1,277 @@
---
type: Addressed
product: PAN-OS
version: 8.1.16
---
## WF500-5466
Fixed an issue where the timeout for downloading a PDF of a WildFire analysis report was too short, which caused missing reports and 404 errors.
## PAN-151978
A fix was made to address an insecure configuration of a daemon (appweb) that allowed a remote unauthenticated user to send a specifically crafted request to the device that caused the Appweb service to crash. Repeated attempts to send this request resulted in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode ([CVE-2020-2041](https://security.paloaltonetworks.com/CVE-2020-2041)).
## PAN-150243
Fixed an issue where after a successful commit, the candidate configuration was not updated to running configuration when initiated by an API-privileges-only custom role based administrator.
## PAN-150172
Fixed an issue where dataplane processes restarted when attempting to access websites that had the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
## PAN-150170
```caveat
and PAN-149822
```
A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)).
## PAN-150013
```caveat
and PAN-149822
```
A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)).
## PAN-149813
Fixed an issue where the reply to an XML API call from Panorama was in a different format after upgrading to PAN-OS 8.1.14-h1 and later releases, which caused automated systems to fail the API call.
## PAN-149325
Fixed an issue on Panorama where the web interface took more time than expected to load changes when the virtual router was large or when there was a large configuration change request from the web interface.
## PAN-149005
Fixed an issue where XML API failed to fetch logs larger than 10MB.
## PAN-148806
A fix was made to address an uncontrolled resource consumption vulnerability in PAN-OS that allowed for a remote unauthenticated user to upload temporary files through the management web interface that were not properly deleted after the request was finished. An attacker could disrupt the availability of the management web interface by repeatedly uploading files until available disk space was exhausted ([CVE-2020-2039](https://security.paloaltonetworks.com/CVE-2020-2039)).
## PAN-148676
Fixed an issue where the `panlogs` directory reached 100% utilization on the firewall due to early calculation of the .size file.
## PAN-148522
Fixed an issue for PAN-DB where certain situations caused performance issues.
## PAN-147424
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
## PAN-147258
Fixed an issue with one-way audio for inbound voice calls due to incorrect source port translation.
## PAN-147203
Fixed an issue where API calls did not return the output for the operational command for running configurations.
## PAN-146878
Fixed an issue where TCP traffic dropped due to TCP sequence checking in a high availability (HA) active/active configuration where traffic was asymmetric.
## PAN-146837
A fix was made to address a vulnerability involving information exposure through log files where sensitive fields were recorded in the configuration log without masking on PAN-OS software when the `after-change-detail` custom syslog field was enabled for configuration logs and the sensitive field appeared multiple times in one log entry. The first instance of the sensitive field was masked but subsequent instances were left in clear text ([CVE-2020-2043](https://security.paloaltonetworks.com/CVE-2020-2043)).
## PAN-145942
After upgrading to certain PAN-OS 8.1 and 9.0 versions, for certain configurations using dynamic routing without graceful restart and with Bidirectional Forwarding Detection (BFD) enabled, there was a longer traffic hit after an HA failover compared to previous versions. This was due to BFD incorrectly timing admin-down messages for the failover event.
## PAN-145929
Fixed an issue where, after upgrading the passive firewall, the stream control transmission protocol (SCTP) sessions synced from the active firewall did not retain the rule information, and, after failover, SCTP stateful inspection did not work.
## PAN-145422
Fixed an issue where a process (all_pktproc) restarted while processing SSL VPN sessions.
## PAN-145302
Fixed an issue where the HA peer device did not preserve its import configuration when the mode was active/active and VR sync was disabled.
## PAN-144804
Fixed an issue where the firewall generated GPRS tunneling protocol (GTP) logs for invalid GTP packets. This fix also implements a counter, `flow_gtp_invalid_ver`, where the invalid packets are counted.
## PAN-144232
Fixed an issue where, when any change was made to an authentication profile, the LDAP server or local user database in a shared context removed the user group mapping information from the firewall.
## PAN-143686
Fixed an issue where a firewall running in FIPS mode was unable to download the GlobalProtect datafile even when a GlobalProtect license was installed and valid.
## PAN-143493
Fixed an memory issue associated with a process (mgmtsrvr) due to a large number of ACK packets in logs on Panorama or the log collector.
## PAN-142927
Fixed an issue where the locked users list grew too large, which caused 100% CPU usage on a process (authd). With this fix, locked users will be purged hourly if the lockout time for that user has expired.
## PAN-142853
Fixed an issue on Panorama where commits failed, referring to a portion of the configuration that was not changed.
## PAN-142674
Fixed an issue where a process (brdagent) failed in an HA configuration using High Speed Chassis Interconnect (HSCI) ports due to a memory leak.
## PAN-142302
Fixed an issue where the firewalls faced connection issues with Cortex Data Lake.
## PAN-141239
Fixed an issue where dataplane free memory was depleted, which affected new GlobalProtect connections to the firewall.
## PAN-140982
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where a process (mprelay) on the control plane was restarted due to an internal heartbeat miss.
## PAN-140494
Added a mechanism to detect corrupted or incorrect formats received on dataplane CPU. Such packets are dropped, and a counter, `pkt_recv_bad_group`, is incremented.
## PAN-140373
```caveat
PA-5250, PA-5260, and PA-5280 firewalls only
```
Fixed an issue where, when you deployed the firewall in a network that used Dynamic IP and Port (DIPP) NAT translation with PPTP, the generic routing encapsulation (GRE) packet in the PPTP connection from the server was sent back to its ingress interface in some connections.
## PAN-139764
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak, which caused a process (configd) to restart.
## PAN-139172
Fixed an issue where response pages generated from the firewall used the SMAC and DMAC addresses from the original packet, which caused a MAC flap on connected switches.
## PAN-138037
Fixed an issue where the host information profile (HIP) match message was automatically enabled when modifying the GlobalProtect Agent settings.
## PAN-137639
Fixed an issue where the log export query was slower than expected when exporting one million lines of logs.
## PAN-137138
Fixed an issue where a process (configd) consistently restarted with the following error message: `virtual memory limit exceeded, restarting` due to a dynamic updates push from Panorama to multiple firewalls.
## PAN-136957
Fixed an issue where access was denied if a password contained more than 63 characters.
## PAN-136844
Fixed an issue for S11 traffic where if the Modify Bearer Request message came after 30 seconds of Create Session Response message, the firewall dropped the Modify Bearer Request packet. This fix increases this time to 90 seconds.
## PAN-136726
Fixed an issue on the firewall where the dataplane pan-task process (all_pktproc) stopped responding while inspecting Server Message Block (SMB) traffic.
## PAN-136623
Fixed an issue where a process (useridd) failed due to internal user groups that were loading from the disk taking over the lock.
## PAN-136304
Fixed an issue where clientless VPN rewrite failed due to incorrect parsing of the HTML webpage.
## PAN-135418
Fixed an issue on the firewall where configuring uppercase **User Domain** values in authentication profiles led to a failure in GlobalProtect Agent configuration selection based on the domain user match condition.
## PAN-135356
Fixed an issue where policies that contained objects did not display correctly when exported to CSV or PDF format.
## PAN-135262
A fix was made to address a vulnerability involving information exposure through log files where an administrator's password or other sensitive information was logged in cleartext while using the CLI in PAN-OS software. The `opcmdhistory.log` file was introduced to track operational command (op-command) usage but did not mask all sensitive information ([CVE-2020-2044](https://security.paloaltonetworks.com/CVE-2020-2044)).
## PAN-134624
```caveat
VM-Series firewalls only
```
Fixed an issue where the VLAN interface failed to obtain the MAC address when the interface was used as a DHCP relay agent.
## PAN-134488
Fixed an issue where a process (all_pktproc) restarted while processing Clientless VPN traffic.
## PAN-133880
Fixed an issue where RADIUS authentication failed due to an FQDN resolution failure after the VM-Series firewall rebooted.
## PAN-131973
Fixed an issue where both firewalls in an HA active/passive configuration stopped responding at the same time.
## PAN-130564
Fixed an issue where the session ID did not display correctly in the debug logs related to the hardware security module (HSM).
## PAN-130168
Fixed an issue where a process (pan_comm) stopped responding due to operation commands run during a commit.
## PAN-129461
Fixed an issue where excessive next hop FPGA exceptions occurred when an ARP request or response was lost in the network in an ECMP configuration, which blocked subsequent ARP learning due to a full queue.
## PAN-129277
Enhanced a daemon (dnsproxy) to support DNS compression for query strings.
## PAN-128761
A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2037](https://security.paloaltonetworks.com/CVE-2020-2037)).
## PAN-125466
Fixed an issue where, during Antivirus or Threat Content update downloads or install, some show commands in the CLI, API calls, and web interface pages gave information output with significant delay (15-60 seconds).
## PAN-123279
Fixed an issue where a process (configd) stopped responding after upgrading Panorama to 8.1.9 from 8.0.16 due to 8.0 WildFire appliance register requests.
## PAN-118098
Fixed an issue where a process (useridd) restarted while updating user groups. This issue occurred when multiple group mapping profiles were used to fetch the same group information while using different domain override settings.
## PAN-116720
A fix was made to address a reflected cross-site scripting (XSS) vulnerability in the PAN-OS management web interface where, if a remote attacker was able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link, the attacker could execute arbitrary code JavaScript code in the administrator's browser and perform administrative actions ([CVE-2020-2036](https://security.paloaltonetworks.com/CVE-2020-2036)).
## PAN-112539
Fixed an issue where the firewall stopped forwarding logs to the log collector from the Log Processing Card (LPC) after a commit push from Panorama due to a race condition.
## PAN-100757
Fixed an issue where the TCP timestamp was stripped from the Client Hello when SSL Forward Proxy decryption was enabled.
## PAN-93184
Fixed an intermittent issue where the firewall reported `Validation of Local client certificate failed resulting in error 58, Problem with the local SSL certificate` in the system log due to management plane out-of-memory errors when a process (varrcvr) attempted to register to the cloud.
## PAN-84211
In accordance with the latest NIST Revision, PAN-OS FIPS-CC mode releases prior to 9.0 used unsupported ciphers within the UserID Agent connections. With this fix, we removed all the cipher combinations, TLS server, and TLS clients in PAN-OS 8.0.5-h1 and later releases for FIPS-CC mode of operation to meet recent NIAP requirement and policy.
@@ -0,0 +1,113 @@
---
type: Addressed
product: PAN-OS
version: 8.1.18
---
## PAN-155453
Fixed an issue in the configuration logs where the destination zone was masked by asterisks.
## PAN-153673
Fixed an issue where traffic logs were not shown due to a thread timeout that was causing the reading of the logs from the dataplane to slow.
## PAN-153440
Fixed an issue where firewalls repeatedly connected and disconnected to Cortex Data Lake due to a probing issue.
## PAN-153111
Fixed an issue where packet buffer unavailability caused host-bound sessions to remain in an opening state in the dataplane.
## PAN-152743
Fixed an issue where, when initial flows from both directions reached the firewall at the same time, a race condition occurred, which caused the firewall to display the following error message: `Duplicate flows detected while inserting <number>, flow <number> with the same key`. The flow keys were identical due to the flows having the same SRC and DST ports.
## PAN-152706
Fixed an intermittent issue where Panorama did not retrieve firewall logs from Cortex Data Lake.
## PAN-152282
Fixed an issue where platforms using AHO for content and application inspection run into dataplane process (all_pktproc) restarts.
## PAN-151483
Fixed an issue where, when an out-of-order stream of TCP packets was subjected to HTTP header insertion, the packets were duplicated.
## PAN-151149
Fixed an issue where certificates, custom logos, and Security Assertion Markup Language (SAML) metadata were unable to be uploaded from the web interface using a Chromium-based browser running version 84 or later.
## PAN-149377
A fix was made to address a vulnerability regarding information exposure through log files in PAN-OS that made it possible for configuration secrets for HTTP, email, and SNMP trap v3 log forwarding server profiles to be logged to the logrcvr.log system log ([CVE-2021-3032](https://security.paloaltonetworks.com/CVE-2021-3032)).
## PAN-148818
Fixed an issue where the decryption profile was configured without the **Block sessions with expired certificates** option, but the firewall still blocked websites that were signed by an Expired AddTrust Root CA (certificate authority).
## PAN-147529
Fixed an issue where **ValidateAll** jobs were incorrectly logged as **CommitAll** in the configuration log of the firewall.
## PAN-146236
Fixed an issue where the firewall was unable to properly create stream control transmission protocol (SCTP) sessions for multi-homed environments when multiple endpoints on the same SCTP associations sent INIT/INIT-ACK chunks during handshakes.
## PAN-144410
Debug logs were added to detect an out-of-memory (OOM) condition that caused the management server to restart.
## PAN-140669
Fixed a memory leak issue caused by a process (mgmtsrvr).
## PAN-140492
Fixed an issue on the firewall where, with SSL forward proxy feature enabled, random file downloads over a decrypted session would stall or hang in the middle.
## PAN-139007
Fixed an issue where **URL Filtering** logs were misaligned when exported from the firewall due to the presence of a comma in the **User-Agent** field of the logs.
## PAN-137233
Fixed an issue where authenticating to GlobalProtect via expired SAML requests (waiting more than 10 minutes) still sent authentication to the SAML server. This invalidated the previously connected gateway and connected users to the second best gateway.
## PAN-134981
Fixed an issue with a memory leak in a process (user-id) due to failed LDAP over SSL (LDAPS) requests.
## PAN-134840
Fixed an issue where pre-logon users failed authentication if the cookie was expired, instead of using certificate authentication.
## PAN-134663
Fixed an issue where the running configuration on the firewall changed after an upgrade from a Panorama Virtual Appliance in a VMware NSX environment.
## PAN-134029
Fixed an intermittent issue on the firewall where H.225 VOIP signaling packets dropped.
## PAN-132055
Fixed an issue where a process (mgmtsrvr) was unresponsive when the number of active file descriptors was greater than 1024.
## PAN-129234
Fixed an issue where syslog connection failures were frequently reported in system logs.
## PAN-126938
Fixed an issue where multiple daemons restarted due to MP ARP overflow.
## PAN-124681
A fix was made to address a vulnerability where Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls were not cleared before the data frame was created ([CVE-2021-3031](https://security.paloaltonetworks.com/CVE-2021-3031)).
## PAN-110720
Fixed an issue where a high volume of traffic over SSL VPN caused a process (all_pktproc) to unexpectedly stop responding.
@@ -0,0 +1,25 @@
---
type: Addressed
product: PAN-OS
version: 8.1.20-h1
---
## PAN-176661
Fixed an issue in Simple Certificate Enrollment Protocol (SCEP) ([CVE-2021-3060](https://security.paloaltonetworks.com/CVE-2021-3060)).
## PAN-176655
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
## PAN-158334
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
## PAN-176653
A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator with permissions to use XML API to execute arbitrary OS commands to escalate privileges ([CVE-2021-3058](https://security.paloaltonetworks.com/CVE-2021-3058)).
## PAN-176618
A fix was made to address an OS command injection vulnerability in PAN-OS that existed when performing dynamic updates ([CVE-2021-3059](https://security.paloaltonetworks.com/CVE-2021-3059)).
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 8.1.21-h1
---
## PAN-183767
Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at `us-static.updates.paloaltonetworks.com`.
@@ -0,0 +1,17 @@
---
type: Addressed
product: PAN-OS
version: 8.1.21-h2
---
## PAN-202450
Fixed an issue where the `device-client-cert` was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the `root-cert` was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-193004
Fixed an issue where `/opt/pancfg` partition utilization reached 100%, which caused access to the Panorama web interface to fail.
@@ -0,0 +1,25 @@
---
type: Addressed
product: PAN-OS
version: 8.1.22
---
## PAN-176097
Fixed an issue in an active/active HA configuration where the V-wire interface on the active primary firewall forwarded the ICMP error code packet that was received by the active secondary firewall.
## PAN-174709
Fixed an out-of-memory condition that occurred due to multiple parallel jobs being created by the scheduled log export feature.
## PAN-172243
Fixed an issue where NetFlow traffic triggered a packet buffer leak.
## PAN-161496
Fixed an issue when calculating the incremental checksum after a post-NAT translation where the arguments to `pan_in_cksm32_diff` overflowed the 32-bit integer.
## PAN-136007
Fixed an issue where generating subordinate ECDSA Certificate Authority (CA) certificates from the web interface failed if the **Common Name** field contained a space.
@@ -0,0 +1,25 @@
---
type: Addressed
product: PAN-OS
version: 8.1.23
---
## PAN-190175
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
## PAN-190223
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
## PAN-177551
A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)).
## PAN-162600
Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops.
## PAN-158328
Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 8.1.24-h1
---
## PAN-132593
Fixed an issue on the firewall where radius authentication to CLI failed with the error message Invalid user. Please login using a valid account.
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 8.1.24-h2
---
## PAN-208218
```caveat
Releases earlier than PAN-OS 8.1.24-h2
```
Due to a component change, versions earlier than PAN-OS 8.1.24-h2 are no longer supported on later hardware revisions of the PA-5200 Series.
## PAN-204830
Fixed an issue where logging in via the web interface or CLI did not work until an auto-commit was complete.
## PAN-159697
Fixed an issue where, after rebooting the firewall, authenticating using LDAP credentials did not work.
@@ -0,0 +1,33 @@
---
type: Addressed
product: PAN-OS
version: 8.1.24
---
## PAN-195571
A fix was made to address an authentication bypass vulnerability in the PAN-OS 8.1 web interface that allowed a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions ([CVE-2022-0030](https://security.paloaltonetworks.com/CVE-2022-0030)).
## PAN-181759
```caveat
Firewalls in active/active HA configurations only
```
Fixed an issue where firewall configuration files were not synced.
## PAN-168514
Fixed an issue where authentication failed when the destination service route was used to reach the RADIUS server.
## PAN-163030
Fixed an issue where restarting the devsrvr process caused new GlobalProtect connections to fail with the error message required client certificate not found. This issue occurred due to a key mismatch between the dataplane and the management plane.
## PAN-159578
Fixed an issue on the firewall where the varrcvr process stopped responding.
## PAN-126210
Fixed an issue where a role based administrator with the appropriate permissions was unable to run the CLI command show config....
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 8.1.25-h2
---
## PAN-237871
```caveat
WF-500 appliances and PAN-DB private cloud deployments only
```
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,37 @@
---
type: Addressed
product: PAN-OS
version: 8.1.26
---
## BLANK-000000
This release includes bug and performance fixes.
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-237871
```caveat
WF-500 appliances and PAN-DB private cloud deployments only
```
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-217493
Fixed an issue where superusers with read-only privileges were unable to view SCEP object configurations.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 8.1.4-h2
---
## PAN-107271
Fixed an issue on a PA-3200 Series firewall running PAN-OS 8.1.4 in an HA configuration where the HA1-B (backup) port did not come up as expected.
@@ -0,0 +1,403 @@
---
type: Addressed
product: PAN-OS
version: 8.1.6
---
## WF500-4901
Fixed an issue where files sent by Traps™ to WildFire® were referenced for trusted signers in the incorrect database, which resulted in a malicious file verdict and caused conflicting post detection events.
## WF500-4893
```caveat
RADIUS server profile configurations only
```
Fixed an issue where the RADIUS authentication protocol was incorrectly changed to CHAP authentication when you pushed a commit from a Panorama™ appliance running a PAN-OS® 8.1 release to a WF-500 appliance running a PAN-OS 8.0 release.
## WF500-4869
Fixed an issue on a WF-500 appliance where the sample analysis failed when using FIPS-CC mode.
## WF500-4815
Fixed an intermittent issue on WF-500 appliances where the Redis command line interface (CLI) failed to execute during master node re-balancing.
## WF500-4747
Fixed an issue on a WF-500 appliance where the Panorama™ management server ran unrelated Logging Service threads.
## WF500-4636
```caveat
WF-500 Appliances only
```
Fixed a rare issue that occurred after upgrading from a PAN-OS 8.0 release to a PAN-OS 8.1 release where the disk partition became full due to the amount of data on the drive and, when you tried to delete the backup database to free up space, the `debug wildfire reset backup-database-for-old-samples` CLI command failed and resulted in the following error: `Server error : Client wf_devsrvr not ready.`
## PAN-111305
Fixed an issue where you were unable to reference certificate profiles from the External Dynamic Lists (**Objects** > **External Dynamic Lists** > **Add** > **Create List**) but instead, you had to type in the certificate profile.
## PAN-110448
Fixed an issue on PA-3200 Series firewalls where the dataplane took longer than expected to respond or intermittently stopped responding after a firewall reboot.
## PAN-109594
Fixed an issue where the dataplane restarted when an IPsec rekey event occurred and caused a tunnel process (tund) failure when one--but not both--HA peer is running PAN-OS 8.0.14 or PAN-OS 8.1.5.
## PAN-109124
A security-related fix was made to address an issue where you were unable to retrieve GlobalProtect™ cloud service threat packet captures from the Logging Service on Panorama M-Series and virtual appliances.
## PAN-108785
Fixed an intermittent issue on a firewall in an HA active/passive configuration where a ping test stopped responding on Ethernet 1/1, 1/2, and 1/4 due to input errors on the corresponding switch port after an HA failover.
## PAN-108241
Fixed an issue on a PA-3200 Series firewall where multiple dataplane processes (all_pktproc, flow_mgmt, flow_ctrl, and pktlog_forwarding) stopped responding when overloaded with traffic.
## PAN-108165
Fixed memory issues on Palo Alto Networks hardware and virtual appliances that caused intermittent management plane instability.
## PAN-108161
Fixed an issue on an HA active/passive configuration where GTP sessions did not properly sync to the passive firewall, which caused a failure on the passive firewall during a failover.
## PAN-107895
Fixed an issue where PDP Delete Response packet did not match the GTPv1-C tunnel session, which caused the generated GTP log to display incorrect session data.
## PAN-107893
Fixed an issue where a **Delete PDP Context Response** (**Monitor** > **Logs** > **GTP**) did not correlate with a **Delete PDP Context Request** and appeared as a new session.
## PAN-107790
Fixed an issue where Application incorrectly displayed as `unknown-udp` instead of `gtp-c` for the **GTPv1-C tunnel management message** GTP Event Type.
## PAN-107734
Fixed an intermittent issue where IPSec Tunnels failed due to a race condition between the (pan_task) process and (tund) process.
## PAN-107694
Fixed an issue on Panorama M-Series and virtual appliances where after you selected **Allow with Ticket** (**Networks** > **GlobalProtect** > **Portals <Portal-Name>** > **App**) the web interface **Generate Ticket** did not display.
## PAN-107290
Fixed an issue where a single API call failed to locate a Device Group node and create a device node for the Device Group when necessary.
## PAN-107262
A security-related fix was made to prevent cross-site scripting (XSS) attacks through the PAN-OS Management Web Interface (CVE-2019-1566).
## PAN-106947
Fixed an intermittent issue where a large number of out-of-order TCP packets caused packet buffer depletion.
## PAN-106776
A security-related fix was made to prevent a cross-site scripting (XSS) vulnerability in PAN-OS External Dynamic Lists (CVE-2019-1565).
## PAN-106759
Fixed an issue in an HA active/passive configuration where a process (configd) restarted due to a memory error.
## PAN-106253
Fixed an issue where the GTP Message Type **Modify Bearer Response** and GTP Event Code **124223** were denied due to failed stateful inspections.
## PAN-106251
Fixed an issue where the list of Panorama Managed Devices did not display (**Panorama** > **Device** > **Deployment** > **Licenses**).
## PAN-105928
Fixed an issue on a firewall where server side data packets dropped after a terminated challenge ACK session was reused.
## PAN-105759
Fixed an issue on PA-3200 Series and PA-5200 Series firewalls in an HA active/active configuration where the SNMP notification did not report the HA interfaces.
## PAN-105570
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an issue where the QoS profile rule did not match non-offloaded traffic as expected.
## PAN-105567
Fixed an intermittent issue on Panorama M-Series and virtual appliances where a cloned security or NAT policy used the incorrect **Rule order**.
## PAN-105348
Fixed an issue on Panorama M-Series and virtual appliances where Dynamic Updates (**Device** > **Dynamic Updates**) did not allow local overrides on an existing template.
## PAN-105281
```caveat
PAN-OS 8.1.6 and later
```
Fixed an issue where a SAML based GlobalProtect re-authentication portal displayed an authentication error after you have previously logged in.
## PAN-105157
Fixed an intermittent issue on Panaoram M-Series and virtual appliances where logs did not display due to a file descriptor limit by the process (Elasticsearch).
## PAN-105103
Fixed an intermittent issue where GTP logs did not display due to GTP packets with an APN > 14 bytes caused the traffic log to reach the limit and stopped generating logs.
## PAN-105012
Fixed an issue on Panorama M-Series and virtual appliances where a log migration from an old-disk pair to a new-disk pair failed with the following error message: `Error restoring disks from RMAed device`, which caused the (configd) process to fail.
## PAN-104463
Fixed an intermittent issue where the DNS resolution stopped responding when the firewall acted as a DNS proxy and the DNS request volume was higher than expected.
## PAN-104361
Fixed an issue on a firewall in an HA active/passive configuration where a process (all_task) failed due to a (bad_gtp_header) code on the passive firewall after upgrading from PAN-OS 8.0.12.
## PAN-104300
Fixed an issue on a firewall where a process (mprelay) stopped responding while the (`> debug dataplane internal pdt`) command was processed.
## PAN-104165
Fixed an issue on a VM-Series firewall configured to use the i40e single-root input/output virtualization (SR-IOV) virtual function (VF) with VLAN tagging dropped Ethernet frames exceeding 1496 bytes.
## PAN-104077
Fixed an intermittent issue where User-ID™ stopped responding, which caused the user IP mapping to not display.
## PAN-104042
Fixed an issue where directly connected IPv4 routes do not display in the routing table after the firewall was restarted.
## PAN-104041
Fixed an issue where the web interface management session failed to time out as expected when you set the **Idle Timeout** (**Device** > **Setup** > **Management** > **Authentication Settings** > **Edit**) to more than five minutes.
## PAN-103665
Fixed an issue on an HA active/active configuration where the active primary LLDP profile could not be copied to the active secondary firewall.
## PAN-103224
Fixed an issue on a VM-Series firewall where the initialization buffer caused the firewall to stop responding when five or more interfaces were active.
## PAN-102954
A security-related fix was made to address a code parameter in the clientless VPN portal.
## PAN-102625
Fixed an issue on a firewall where traffic stopped passing due to higher than normal duplicate TCP ACK packets sent from the client side, which caused a spike in packet buffers and packet descriptor usage.
## PAN-102338
Fixed an issue where you were unable to configure **Maximum Egress** (**Network** > **QoS**) to 10000 Mbps on a 10000 Mbps port.
## PAN-101990
Fixed an issue on Panorama M-Series and virtual appliances in an HA active/passive configuration where you were unable to edit the template variables (**Panorama** > **Summary**).
## PAN-101973
Fixed an issue where you were unable to configure IPv6 variables (**Network** > **Virtual Routers** > **Add** > **Static** > **Routes** > **IPv6**).
## PAN-101882
Fixed an issue on Panorama M-Series and virtual appliances where a partial Commit and Push for one or more administrators incorrectly sets the Push scope to all relevant firewalls as if a full Commit and Push was performed.
## PAN-101851
Fixed an intermittent issue on PAN-OS 8.1.3 and later releases, where downloading files from email services were allowed when the file blocking profile was configured to block email service file downloads.
## PAN-101800
Fixed an issue where the parent session stopped responding during a file transfer using a decryption enabled FTP server with the following error message: `Lost connection`.
## PAN-101692
Fixed an issue where the (`show session all filter nat-rule`) command did not respond with destination NAT rules.
## PAN-101684
Fixed an issue on Panorama M-Series and virtual appliances where adding a threat exception for a child Device Group caused existing rules to be removed from the Global Device Group.
## PAN-101614
Fixed an issue on a firewall where SSL/TLS Service Profile (**Device** > **SSL/TLS Service Profile**) values failed to change after an override.
## PAN-101607
Fixed an issue where template administrators with the required permission made configuration changes on shared objects and the Commit failed with the following error message: `No pending change to commit`.
## PAN-101401
Fixed an issue where a DNS App-ID™ security policy allowed non-DNS traffic to flow through.
## PAN-101202
Fixed an issue on a firewall where the TFC padding parameter was set to **null** when negotiating with a peer device capable of TFC padding during IKEv2 negotiations.
## PAN-101185
Fixed an issue on Panorama M-Series and virtual appliances where the Decrypt Mirror (**Network** > **Interfaces** > **Ethernet** > **Interface Type**) template setting did not Push to a firewall.
## PAN-101031
Fixed an issue where you were unable to select existing certificates after you created an IKE gateway on a template stack and changed Authentication to Certificate.
## PAN-101029
Fixed an issue where routing traffic dropped due to an increased activity in global counter (`flow_fpga_rcv_egr_L3_NH_NF`) when an interface is moved from one virtual router to another.
## PAN-100962
Fixed an issue on Panorama M-Series and virtual appliances where the disk quota configuration exceeded a combined total of 100 percent when a Push was performed from Panorama due to value discrepancies between Panorama and the firewall.
## PAN-100717
Fixed an issue where the (configd) process depleted memory when you deleted multiple security rules with an XML API call.
## PAN-100623
Fixed an issue on a firewall in an HA active/passive configuration where a higher than normal rate of HA session update messages caused higher than normal CPU usage on both active and passive nodes.
## PAN-100381
Fixed an issue on a firewall in an HA configuration where a path monitoring variable was not available for Destination IP (**Device** > **High Availability** > **Link and Path Monitoring** > **Add Virtual Router Path**).
## PAN-100173
Fixed an issue where H.323 based calls had audio issues due to the predicted RTP session not following the policy-based forwarding (PBF) rules that sends traffic from the client to servers, which caused RTP traffic to be forwarded incorrectly by route.
## PAN-99924
Fixed an issue where the Panorama management server web and CLI stopped responding after a partial configuration load (**Panorama** > **Setup** > **Operations**).
## PAN-99764
Fixed an issue on VM-Series firewalls where CPU calculations for additional vCPUs in the dataplane did not display correctly.
## PAN-99742
Fixed an issue on a PA-500 Series firewall where SSL Forward Proxy was denied due to insufficient shared memory.
## PAN-99621
Fixed an issue on a firewall where Captive Portal sessions matched incorrect policies and were incorrectly logged in the traffic log.
## PAN-99504
Fixed an issue on a firewall where Group Mapping (**Device** > **User Identification** > **Group Mapping Settings**) did not display the list of LDAP server profile users when a Domino server with an empty distinguished name (DN) was used.
## PAN-99079
Fixed an issue on Panorama M-Series and virtual appliances where Logging Service was enabled, traffic log filters with a variable length subnet mask did not display any logs.
## PAN-99058
Fixed an issue where threat log messages (`SCAN: UDP Port Scan`) appeared when the UDP port scan traffic rate was less than the Reconnaissance Protection UDP port scan threshold.
## PAN-99002
Fixed a rare issue where XML files with random file sizes failed to upload through API calls.
## PAN-99000
Fixed an issue where the packet capture option did not display (**Monitor** > **Traffic**) when administrators switched context from Panorama to a managed firewall.
## PAN-98861
Fixed an issue where shadowed rule warnings did not display during commits.
## PAN-98811
Fixed an issue on Panorama M-Series and virtual appliances where Group Mapping Settings (**Object** > **Security Profile** > **URL Filtering** > **User Credential Detection**) did not display profile names.
## PAN-98786
Fixed an issue where websites were not accessible when you configured a decryption policy Action to **No Decrypt** and enabled **Block sessions with expired certificates**.
## PAN-98625
Fixed an issue where the Threat Category (**Monitor** > **Threat**) did not display as expected on Panorama M-Series and virtual appliances when it received logs from PA-200, PA-220, PA-500, and PA-800 Series firewalls.
## PAN-97898
Fixed a rare issue where the traffic log did not generate data due to a negative log counter reading.
## PAN-97743
Fixed an issue where the firewall did not recognize the small form-factor pluggable (SFP) port, which caused the dataplane to restart when the path monitor process stopped responding.
To ensure a successful upgrade to PAN-OS 8.1.6 for this fix, re-seat all connected SFP transceivers and then follow the [upgrade path](https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/upgrade-to-pan-os-81/upgrade-the-firewall-to-pan-os-81/determine-pan-os-upgrade-path.html) described in the PAN-OS 8.1 upgrade procedure ([PAN-OS 8.1 New Features Guide](https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features.html)).
## PAN-97672
Fixed an issue where polled SNMP object identifiers (OID) stopped responding after the firewall was restarted.
## PAN-97670
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where after a reboot, the passive firewall sent ARP packets during the initialization state, which caused a traffic conflict with the active firewall.
## PAN-97496
Fixed an issue on a firewall where the (`show running resource-monitor ingress-backlogs`) CLI command displayed invalid session IDs.
## PAN-97298
```caveat
PAN-OS 8.1.1 and later releases only
```
Fixed an issue where **Address Groups** (**Objects** > **Address Groups**) search results were cleared from the web interface when you switched between tabs.
## PAN-97223
Fixed an issue where an administrator with superuser access was unable to remove a configuration lock from a logged out administrator whose username contained a backslash (" \ ").
## PAN-97139
Fixed an issue where the GlobalProtect Data File (**Device** > **Dynamic Updates** > **GlobalProtect data File**) version did not update after a PAN-OS 8.1 upgrade.
## PAN-95975
Fixed an issue on a firewall in an HA active/passive configuration where the scheduled antivirus content update failed due to a process (mgmtsrvr) failure.
## PAN-95121
Fixed an issue where applications gets disabled after you enabled them during the install or revert of application and threat signatures.
## PAN-93112
Fixed an issue on a PA-5200 Series firewall where small form-factor pluggable (SFP) ports only linked in auto negotiation mode.
## PAN-91059
Fixed an issue where GTP log query filters did not work when you filtered based on a value of **unknown** for the message type or GTP interface fields (**Monitor** > **Logs** > **GTP**).
## PAN-90096
Fixed an issue where Threat logs recorded incorrect IMSI values for GTP packets when you enabled **Packet Capture** in Vulnerability Protection profiles (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<vulnerability_protection_profile>** > **Rules**).
## PAN-88461
Fixed an issue on PA-3050 and PA-3060 firewalls in an HA active/passive configuration with link state pass-through enabled in virtual wire (vwire) where the Aggregate Ethernet (AE) interface communication failed during an HA failover event.
## PAN-84292
Fixed an issue on a firewall where the (`show system state browser`) command window displayed live traffic values toggle between zero and other incorrect values.
@@ -0,0 +1,349 @@
---
type: Addressed
product: PAN-OS
version: 8.1.7
---
## WF500-4093
Fixed an issue on a WF-500 appliance cluster where a firewall failed to join the cluster with a large data set of previously processed files.
## PAN-113536
Fixed an issue where the automatic refresh of external dynamic lists (EDLs) did not update the URL or Domain EDLs.
## PAN-112540
Fixed an issue on a VM-Series firewall where traffic stopped processing and resumed processing only after the firewall was restarted.
## PAN-112428
```caveat
Panorama™ running PAN-OS® 8.1.6 only
```
Fixed an intermittent issue where autocommits failed and Panorama stopped displaying device groups when managing a WildFire® appliance running PAN-OS 8.1.5 or an earlier PAN-OS 8.1 release.
## PAN-112305
Fixed an issue where source URLs (**Objects** > **External Dynamic Lists** > **<EDL-name>** > **Create List** > **Source URL**), which contained double escape characters caused external dynamic list entries to display incorrect values in the policies.
## PAN-112098
Fixed an intermittent issue on a firewall where outbound traffic failed with an error message: (`proxy decrypt failure`) when configured with HTTP Header Insertion (**Objects** > **Security Profiles** > **URL Filtering** > **<Filter-name>** > **HTTP Header Insertion**).
## PAN-111866
Fixed an issue where the push scope selection on the Panorama web interface displayed incorrectly even though the commit scope displayed as expected. This issue occurred when one administrator made configuration changes to separate device groups or templates that affected multiple firewalls and a different administrator attempted to push those changes.
## PAN-111817
Fixed an intermittent issue on Panorama M-Series and virtual appliances where elastic search queries to Cortex Data Lake did not display logs.
## PAN-111638
Fixed an issue where the external dynamic list did not update after a scheduled refresh of the list.
## PAN-111593
```caveat
PA-3200 Series and PA-5200 Series firewalls only
```
Fixed an issue where a firewall dropped generic routing encapsulation (GRE) version 1 traffic.
## PAN-110526
Fixed an issue where Captive Portal authentication required two log-in attempts when the authentication sequence was configured as an authentication profile.
## PAN-110341
Fixed an issue where the firewall sent RIP updates more frequently than expected.
## PAN-110293
Fixed an issue where GTP-U traffic dropped when the GTP tunnel endpoint ID (TEID) was not updated correctly during a GTP-C update.
## PAN-110262
Fixed an issue on VM-Series firewalls Dynamic Address Groups did not display all the tags and labels for registered IPs.
## PAN-109668
A security related fix was made to limit the amount of information returned from an API call error message.
## PAN-109506
Fixed an issue where a process (useridd) stopped responding when the firewall received excessive Security Assertion Markup Language (SAML) requests received.
## PAN-109336
```caveat
PA-500 and PA-800 Series firewalls only
```
Fixed an issue where commits failed after you imported a device state from Panorama the template configuration referenced Bidirectional Forwarding Detection (BFD).
## PAN-109187
Fixed an issue where an administrator with a custom configuration role could not export reports.
## PAN-109096
Fixed an issue where the firewall did not remove the 4-Byte AS Format number when **Remove Private AS** was enabled.
## PAN-109003
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) stopped responding during a local commit.
## PAN-108990
Fixed an intermittent issue on a firewall where configuring **Force Template Values** (**Network** > **Interfaces** > **Commit** > **Push to Devices** > **Templates**) deleted the zone assigned to an interface.
## PAN-108642
Fixed an issue where P2MP OSPF static neighbor did not display in the run-time neighbor table.
## PAN-108542
Fixed an issue where the DHCP client interface was configured with an incorrect subnet mask value instead of the value provided by DHCP option 1.
## PAN-108374
Fixed an issue on GlobalProtect™ where you were unable to authenticate when the domain name included the ampersand ( `&` ) character.
## PAN-108123
Fixed an issue where applications took longer than expected to load when accessed through a Clientless VPN.
## PAN-107989
Fixed an issue where the Strict IP Address Check incorrectly triggered when you enabled ECMP (**Network >Virtual Routers** > **Add** > **Router settings** > **ECMP**).
## PAN-107922
Fixed an issue on a VM-Series firewall where packet sizes more than 1,500 bytes caused the firewall to stop transmitting and receiving packets.
## PAN-107848
Fixed an issue where commits failed after a BGP aggregate route configuration modification.
## PAN-107729
Fixed an issue on a VM-Series firewall where the PCI-PT interface did not receive VLAN tagged traffic after a system boot up.
## PAN-107659
```caveat
PA-5000 Series firewalls only
```
Fixed an issue where extra byte (1 to 7) padding were appended to the initial SYN and UDP packets, which caused the server to stop responding.
## PAN-107636
```caveat
Panorama M-Series and virtual appliances only
```
Fixed a rare issue where the web interface did not display new logs as expected because Elasticsearch (ES) stopped working when the Raid drives reached maximum capacity and the purge script to remove old ES indices failed to execute and make room for new indices. However, this issue also resulted in creation of new ES indices that were empty because the appliance could not read or write to them. With this fix, old indices are purged as expected; however, empty ES indices created before you upgraded to this release with this fix are not removed as expected (see [known issue PAN-114041](/content/techdocs/en_US/pan-os/8-1/pan-os-release-notes/pan-os-8-1-release-information/known-issues/known-issues-related-to-pan-os-8-1-releases.html#id1787F0E08SZ_id6f06b6f6-f9fb-4b15-a7f2-e0a9a42e1032)).
## PAN-107607
Fixed an issue where the `test security-policy-match` XML API command returned invalid XML responses.
## PAN-107240
Fixed an issue where you were unable to retrieve the external dynamic list for URLs that included the ampersand ( `&` ) character in the URL string.
## PAN-107120
Fixed an intermittent issue on a firewall where the (all_pktproc) stopped responding and caused the dataplane to restart.
## PAN-107006
Fixed an issue where you were unable to search for service objects by destination port numbers.
## PAN-106963
Fixed an issue where the firewall did not display the full URL information in the URL Filtering log (**Monitor** > **URL Filtering**) after a (“ \r “) return character.
## PAN-106922
A security-related fix was made to address a denial of service (DoS) vulnerability in PAN-OS SNMP (CVE-2018-18065 / PAN-SA-2019-0007).
## PAN-106865
Fixed an issue where DNS proxy memory leaks occurred during the FQDN refresh process.
## PAN-106857
Fixed an issue where the dataplane restarted due to an internal path monitoring failure caused by large SSL decrypted file transfer sessions.
## PAN-106724
Fixed an intermittent issue on a firewall where the log receiver leaked memory after 24 hours of runtime, which caused the firewall to stop responding.
## PAN-106548
Fixed an issue where MIB attributes caused MIB compilation failures when using a third-party compiler.
## PAN-106426
Fixed an issue where GlobalProtect did not authenticate and displayed the following error message: `search failed 32`.
## PAN-106356
Fixed an issue where you could not log in to GlobalProtect from a mobile device when the mobile ID contained a hyphen (`-`) character in the mobile ID string.
## PAN-106274
Fixed an issue on a firewall where a Layer 2 interface that contained a VLAN sub-interface in conjunction with policy based forwarding (PBF) caused the firewall to forward the return traffic to the incorrect web interface.
## PAN-105966
A security-related fix was made to address the Linux Kernel Local Privilege Escalation vulnerability (CVE-2018-14634 / PAN-SA-2019-0006).
## PAN-105849
A security-related fix was made to address an issue with the `wf_curl.log` file in WF-500 appliances (WildFire).
## PAN-105792
Fixed an issue where NetFlow server profile traffic did not route over IPSec tunnels when the service route was configured to use the dataplane interface.
## PAN-105747
Fixed an issue where correlated events forwarded as email alerts displayed the incorrect date and time.
## PAN-105684
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where OSPF and BGP running on an Aggregate Ethernet (AE) interface with LACP enabled took longer than expected to restart after a failover.
## PAN-104866
Fixed an issue on a VM-Series firewall where the dataplane interface continuously flapped when **PCI passthrough** was enabled with DPDK.
## PAN-104738
Fixed an intermittent issue where octet values were incorrect for random flows in the NetFlow traffic.
## PAN-104466
Fixed an issue on a VM-50 firewall where an out-of-memory event caused the firewall to restart.
## PAN-104354
Fixed an issue in an HA active/passive configuration where the passive firewall ran a configuration out-of-sync after a restart.
## PAN-104263
Fixed an issue where the real-time clock (RTC) battery voltage exceeded the maximum threshold value.
## PAN-104078
Fixed an issue where BGP conditional advertisements did not respond, the BGP conditional advertisements did not match the suppress condition policy even when the prefix in the non-exist filter condition matched.
## PAN-103857
Fixed an issue in an HA active/passive configuration where a suspended firewall processed traffic.
## PAN-103497
Fixed an issue on PA-3200 Series firewalls where an SNMP OID (sysObjectID) reported the incorrect model (for example, PA-2020 instead of PA-3260).
## PAN-103285
Fixed an issue where an API call (`show system disk details`), responded with the following error message: `An error occurred. See dagger.log for information`.
## PAN-103225
Fixed an issue on Panorama M-Series and virtual appliances where the Task Manager did not display progress after you pushed a configuration to a firewall.
## PAN-103140
Fixed an issue where a newly deployed VM-Series firewall in the VMware NSX environment did not display on the summary web interface (**Panorama** > **Summary**) after a partial commit.
## PAN-103023
Fixed an intermittent issue where a job type (content) caused a firewall configuration failure and the firewall to stop responding.
## PAN-102745
Fixed an intermittent issue on a firewall where a commit and FQDN refresh took longer than expected.
## PAN-102526
Fixed an issue on Panorama M-Series and virtual appliances where disk quota edits failed and resulted in the following error message: `quota-settings -> disk-quota is invalid`.
## PAN-101527
Fixed an issue on a PA-5200 Series firewall where enhanced small form-factor pluggable (SFP+) ports were unable to detect link-fault events on the transmission side.
## PAN-101451
Fixed an issue where SNMP queries displayed incorrect values.
## PAN-101365
Fixed an intermittent issue where the session ID did not clear when the session ID was set to 0.
## PAN-101341
Fixed an issue where administrators configured with **Device Group** and **Template Admin** type were unable to perform a global search and returned the following message: `Unauthorized request`.
## PAN-101224
Fixed an intermittent issue on VM-Series firewalls in an AWS environment where packets were dropped due to a longer than expected delay in transmission.
## PAN-101068
Fixed an issue where the object identifier (OID) `ifAdminStatus` incorrectly displayed "up" when it was configured to be configured "down."
## PAN-100761
A security-related fix was made to address a development configuration file issue.
## PAN-100408
Fixed an issue where the IPv6 flow label was set to 0 when decryption was configured, which caused the firewall to drop IPv6 traffic during the SSL handshake.
## PAN-98420
Fixed an issue on Panorama M-Series and virtual appliances where TCP port 28 was accessible on management plane.
## PAN-98128
Fixed an issue where SYN-ACK packets with low time-to-live (TTL) values were sent, which caused a connection failure.
## PAN-97385
An enhancement was made to enable you to monitor connections between a firewall and Cortex Data Lake on the web interface.
## PAN-96344
Fixed an issue on a firewall where TCP reset packets were sent even after you set the vulnerability profile action to drop the packets.
## PAN-96038
```caveat
PA-200 <N/A in 9.0>, PA-220, and PA-220R firewalls only
```
Fixed an issue with the Ethernet driver that caused the firewall to reboot when experiencing heavy broadcast traffic on the management interface.
## PAN-95034
Fixed an issue where a firewall stopped responding when a NAT Dynamic IP and Port (DIPP) was configured as a NAT dynamic IP fallback.
## PAN-94342
Fixed an issue where the GlobalProtect Gateway host information profile (HIP) notification operation failed to execute and returned the following message: `GP-EX-GW-21 -> hip-notification - > win-fw-is-not-enable -> not-match-message -> message is invalid`.
## PAN-84670
Fixed an issue where firewalls that were not configured to decrypt HTTPS services and applications traffic allowed users without valid authentication timestamps to access those resources regardless of Authentication Policy settings. To prevent such access, either configure the firewall to decrypt traffic or run the `debug device-server cp-deny-encrypted on` command and execute the `commit force` CLI command (this command will persist across reboots).
## PAN-82421
Fixed an issue where the new connection did not get established after you changed the IP address of a log collector.
@@ -0,0 +1,17 @@
---
type: Addressed
product: PAN-OS
version: 8.1.8-h5
---
## PAN-119745
A security-related fix was made to address the Netflix Linux kernel TCP SACK vulnerability ([PAN-SA-2019-0013](https://securityadvisories.paloaltonetworks.com/Home/Detail/151) / CVE-2019-11477,CVE-2019-11478,CVE-2019-11479, and CVE-2019-5599).
## PAN-118869
A security-related fix was made to address an issue where the php-debug log incorrectly displayed non-sanitized data ([PAN-SA-2019-0019](https://securityadvisories.paloaltonetworks.com/Home/Detail/157) / CVE-2019-1575).
## PAN-107239
A security-related fix was made to address cleartext passwords and keys that were visible in the logs for XML API calls ([PAN-SA-2019-0019](https://securityadvisories.paloaltonetworks.com/Home/Detail/157) / CVE-2019-1575).
@@ -0,0 +1,509 @@
---
type: Addressed
product: PAN-OS
version: 8.1.8
---
## WF500-5023
Fixed an issue on WF-500 appliances where the cluster service took longer than expected to start due to a large number of queued sample data.
## WF500-4974
Fixed an issue on WF-500 appliances where the static analysis results displayed in the PDF report but did not display in the WildFire® analysis summary of the web interface.
## WF500-4844
Fixed an issue on WildFire appliance clusters where the passive-controller responded with the incorrect Common Name (CN) in the certificate, which caused the registration to fail.
## WF500-4838
Fixed an intermittent issue on a WF-500 appliance where WildFire reports took longer than expected to generate, which caused the task to automatically timeout.
## WF500-4785
Fixed a rare issue on WF-500 appliances where the firewall did not respond after you upgraded the appliance from a PAN-OS® 8.0.1 release to a PAN-OS 8.0.10 or later release. With this fix, you can run the new `debug software raid fixup auto` CLI command to recover the RAID controller.
## WF500-4784
Fixed an issue on a WF-500 appliance where during a reboot, the following error message displayed: `FATAL: module nbd not found`.
## WF500-4743
Fixed an intermittent issue on a WF-500 appliance where the CLI command `debug wildfire reset global-database fix` stopped responding.
## PAN-116316
Fixed an issue where RTP and RTCP predict sessions failed, which caused RTSP based video streaming to stop processing.
## PAN-116084
Fixed a file descriptor issue that caused an interface on a VM-Series firewall on Azure to stop receiving traffic.
## PAN-114984
Fixed OpenSSL vulnerability CVE-2019-1559, see [PAN-SA-2019-0039](https://securityadvisories.paloaltonetworks.com/Home/Detail/202) for details.
## PAN-114403
Fixed an issue on Panorama™ M-Series and virtual appliances where serial numbers for deployed firewalls did not display in the web interface with the exception of GlobalProtect™ cloud service firewalls.
## PAN-114181
Fixed an issue where the firewall incorrectly triggered Reverse Path Forwarding (RPF), which caused packet leaks.
## PAN-113692
Fixed an intermittent issue on a firewall in a high availability (HA) active/passive configuration where five minutes after a failover test IP routes disappeared, which caused traffic interruptions.
## PAN-113446
Fixed an issue where the firewall unintentionally generated the following system log: `Installed content package WildFire is newer than available package, skipping,` when you checked for WildFire updates.
## PAN-112815
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) did not respond to the alternate user attribute (**Device** > **User Identification** > **Group Mapping Settings** > **<group mapping-name>** > **User and Group Attributes**) on the passive firewall during a restart.
## PAN-112814
Fixed an issue where H.323-based calls lost audio because the predicted H.245 session was not converted to Active status, which caused the firewall to drop the H.245 traffic.
## PAN-112729
Fixed an issue on Panorama M-Series and virtual appliances where Decrypted Sessions Info (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **<device-name>** > **Sessions**) did not display as expected for VM-Series firewalls.
## PAN-112445
Fixed an issue on a firewall in an HA active/passive configuration where a race condition caused the firewall to stop responding after an HA1 link flap.
## PAN-112194
Fixed an issue where packet buffers did not release GlobalProtect clientless VPN packets, which caused the firewall to stop responding.
## PAN-112187
Fixed an issue where a process (report_gen) ran out-of-memory, which caused the dataplane to restart.
## PAN-111897
Fixed an issue where the tags were not set on OSPFv3 routes redistributed to BGP-3.
## PAN-111844
```caveat
VM-50 and VM-50 Lite firewalls only
```
Fixed a rare out-of-memory (OOM) condition.
## PAN-111822
```caveat
PA-3200, PA-5200, and PA-7000 Series firewalls only
```
Fixed an intermittent issue on a firewall configured with policy-based forwarding (PBF) and symmetric return, where traffic dropped because the ARP table did not get updated.
## PAN-111679
Fixed an issue where URL filtering profiles were being incorrectly applied to security policies during a commit.
## PAN-111653
Fixed an issue on PA-7000 Series firewalls where an internal packet buffer leak caused heartbeat failures.
## PAN-111052
Fixed an issue where a firewall silently dropped TCP packets when you enabled the Antivirus profile while the software deterministic finite automation (DFA) option is disabled (DFA is disabled by default).
## PAN-111048
Fixed an issue where the `show object dynamic address group` XML API command returned an invalid error message: `You must specify a valid Device Group`.
## PAN-110996
Fixed an issue where the dataplane stopped responding due to an incorrectly calculated offset when you configured **Exclude video traffic from the tunnel** (**Network** > **GlobalProtect** > **Gateways** > **<gateway-name>** > **Agent** > **Video Traffic**).
## PAN-110873
Fixed an issue where member interfaces of the aggregate interface did not display on web interface (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **<device-name>** > **Interfaces**).
## PAN-110796
Fixed an issue on PA-3200 and PA-5200 Series firewalls where an erroneous dataplane error (`power status is bad, shutting system down`) caused the firewall to shutdown.
## PAN-110758
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to configure the firewall to disable the portal log-in page.
## PAN-110628
Fixed an issue where user groups were deleted from the Group Include List (**Device** > **User identification** > **Group Mapping Settings** > **<group-name>** > **Group Include List**) if you changed the LDAP server profile account password.
## PAN-110441
```caveat
PA-5200 Series firewall only
```
Fixed an intermittent issue where the internal path monitoring failed, which caused the firewall to unexpectedly restart.
## PAN-110390
Fixed an issue on PA-7000 Series firewalls where invalid filters caused the device management server to stop responding when you generated a database (DB) report from a remote firewall.
## PAN-110336
```caveat
PA-3000, PA-3200, PA-5000, PA-5200, and PA-7000 Series firewalls only
```
Fixed an issue where a process (mpreplay) restarted and caused the offload traffic to drop.
## PAN-110273
Fixed an issue where you were unable to establish OSPF neighborship when an OSPF routing protocol was configured with MD5 authentication and one of the firewalls was restarted.
## PAN-109966
Fixed an issue where the content update threshold downloaded and installed an older content version after you manually installed a newer content version.
## PAN-109954
Fixed an issue where a commit failed with an error message: `cluster is missing 'encryption'` when HA Traffic Encryption (**Panorama** > **Managed WildFire Clusters** > **<appliance-name>** > **Communication**) was not configured and after upgrading from PAN-OS 8.0.12 to PAN-OS 8.1.4.
## PAN-109944
Fixed an intermittent issue where a process (configd) restarted due to a race condition when generating custom reports.
## PAN-109837
Fixed an issue where a race condition occurred when a configuration push and Netflow update occurred simultaneously, which caused the dataplane to restart.
## PAN-109803
Fixed an issue where credential phishing prevention did not detect user or password phishing when passwords, which contained two discontiguous character spaces were used.
## PAN-109759
Fixed an issue where the firewall did not generate a notification for the GlobalProtect client when the firewall denied unencrypted TLS sessions due to an authentication policy match.
## PAN-109757
Fixed an issue on Panorama M-Series and virtual appliances where the management server stopped responding when the log collector disconnected and reconnected to Panorama.
## PAN-109665
Fixed an issue where you were unable to disable the Graceful Restart (**Network** > **Virtual Routers** > **<router-name>** > **BGP** > **Advanced**) configuration.
## PAN-109619
Fixed an issue where a physical or Aggregate Ethernet (AE) Layer 3 configuration edit (**Network** > **Interfaces** > **<interface-name>**) removed the DHCP Client setting when it was configured in the subinterface.
## PAN-109575
Fixed an issue where you were unable to configure more than one device certificate (**Device** > **Certificate Management** > **Certificates** > **<device certificate-name>**) with **Trusted Root CA**.
## PAN-109344
Fixed an issue where service objects did not import into Panorama when you configured them identically but with different names.
## PAN-109101
Fixed an issue where you were unable to override IKE Gateway configurations (**Network** > **IKE Gateways** > **<template-name>**) in the template stack. However, with this fix, you still cannot override template stacks when you configure any value with "none." Additionally, to override the Local Identification, select **Authentication** in the pop-up dialogue.
## PAN-108878
Fixed an issue where host traffic ICMP packets larger than 9,180 bytes dropped when you configured a jumbo frame with a maximum MTU value of 9,216 bytes and with the DF option enabled.
## PAN-108846
Fixed an issue where a higher than expected rate of tunnel resolution packets occurred due to an internal loop, which caused a spike in dataplane CPU usage for firewalls that support distributed tunnel ownership.
## PAN-108715
Fixed an issue where the firewall did not update the dataplane DNS cache after the management plane (MP) DNS entries expired, which caused evasion signatures to erroneously trigger a `Suspicious TLS/HTTP Evasion Found` event.
## PAN-108620
Fixed an issue where Traps ESM (**Monitor** > **Traps ESM**) logs were sent to the Log Collector but did not display in the web interface.
## PAN-108459
Fixed an issue where Network Activity (**ACC** > **Network Activity**) incorrectly displayed no session activity at random time points.
## PAN-108409
Fixed an issue on a firewall in an HA active/passive configuration where scheduled dynamic updates pushed from Panorama to the managed firewalls failed.
## PAN-108215
Fixed an issue where the `test security-policy-match` CLI command ignored `source-user` when matching security policies.
## PAN-108164
Fixed an issue where a process (tund) caused the dataplane to restart during a commit.
## PAN-107998
Fixed an issue where you could not log-in to GlobalProtect and resulted in the following error message: `The client certificate is invalid. Please contact your IT administrator`.
## PAN-107662
Fixed an issue on a firewall in an HA active/active configuration where client-bound DHCPv6 packets dropped when you configured the firewall as a DHCPv6 relay agent.
## PAN-107370
Fixed an issue where IPv6 traffic throughput reduced more than expected after you updated a static ND entry (**Network** > **Interfaces** > **<interface-name>** > **Advanced** > **ND Entries**) by moving the interface to a different virtual router.
## PAN-107126
Fixed an issue where an SSL inbound session cache corruption caused a process (all_pktproc) to stop responding.
## PAN-106950
Fixed an intermittent issue where authd CPU usage is higher than expected during RADIUS authentication.
## PAN-106861
Fixed an issue where stale route entries remained in the FIB after the routes were removed from the routing table when you used a redistribution rule without a profile.
## PAN-106783
Fixed an issue where after a SAML authentication an incorrect query was sent to the web browser.
## PAN-106746
Fixed an issue where VoIP traffic dropped when policy-based forwarding (PBF) was configured as a rule.
## PAN-106735
Fixed an issue where the firewall incorrectly set the FPGA, which caused the dataplane to stop responding.
## PAN-106695
Fixed an issue on a firewall in an HA active/passive configuration where the Panorama management server enabled the administrator to clone a rule on the passive firewall.
## PAN-106433
Fixed an issue where after you configured Packet Buffer Protection on a firewall, a process (all_pktproc) stopped responding.
## PAN-106259
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall reported a higher number of GlobalProtect user accounts than the active firewall.
## PAN-106249
```caveat
PA-200, PA-220, and PA-800 Series firewalls only
```
Fixed an issue where the **Block IP List** option, which is not supported, displayed in the administrator role profile (**Device** > **Admin Role** > **Web UI**).
## PAN-106069
Fixed an issue on a firewall in an HA active/active configuration where the iBGP peer default route did not get added to the routing table after a reboot of either firewall.
## PAN-105925
Fixed an issue where the GlobalProtect Gateway web interface did not display the list of previous users.
## PAN-105466
Fixed an issue where the **Allow matching usernames without domain** (**Device** > **User Identification** > **User-ID Agent Setup** > **Cache**) configuration did not respond without a domain when you used the PAN-OS XML API.
## PAN-105397
Fixed an issue where a firewall incorrectly processed path monitoring, which originated from a NAT firewall on the same network segment.
## PAN-105252
Fixed an intermittent issue on a firewall where dataplane CPU spikes occurred, which caused an LACP flap.
## PAN-105086
Fixed an issue where the firewall incorrectly calculated the password expiry time for admin accounts, which caused Panorama to push locked user accounts.
## PAN-104578
```caveat
PA-800 Series firewalls only
```
Fixed an issue on a firewall in an HA active/passive configuration where the HA failover took longer than expected.
## PAN-104568
Fixed an issue where the firewall did not send emails when you configured the email gateway with an FQDN.
## PAN-104274
Addressed an issue where in a slow network environment the firewall displayed an error message: `error on line 1 at column 1: document is empty` when you used an API call to fetch a license even when the auth code was successfully applied. Extremely slow networks may still see this issue.
## PAN-104264
Fixed an issue where the Panorama management server stopped responding when you upgraded from PAN-OS 8.0.9 to PAN-OS 8.1.3.
## PAN-104007
Fixed an issue where the WildFire signatures sent Windows Server Updates Services (WSUS) traffic when the virus identification was incorrectly enabled in the ms-sms app definition.
## PAN-103863
Fixed an issue where the IPSec tunnel restart (**Network** > **IPSec Tunnels** > **IKE Info**) did not display properly on the web interface.
## PAN-103844
Fixed an issue where Global Find incorrectly returned the query when there were more than one users or groups listed in the security rule.
## PAN-103367
Fixed an issue where Detailed Log View (**Monitor** > **Traffic** > **Detailed Log View**) did not display the file blocking logs as expected.
## PAN-103061
Fixed an issue where special characters contained in the comment field of the Ethernet Interface web interface caused a process (devsrvr) to stop responding.
## PAN-102979
Fixed an issue where Dynamic Updates did not display expired threat prevention licenses when you tried to install an application from Panorama.
## PAN-102595
Fixed an intermittent issue on a firewall in an HA active/active configuration where fragmented ICMP and UDP packets dropped from the packet transmission.
## PAN-102532
Fixed an issue where the firewall used an expired certificate, which caused connecting to Cortex Data Lake to fail.
## PAN-102327
Fixed an issue on PA-3200 Series firewalls in an HA active/passive configuration where the copper ports of passive firewall were active when the passive link state was set to **shutdown**.
## PAN-102145
Fixed an issue where the API keys did not update after you changed the master key.
## PAN-102029
Fixed an issue on a firewall where the DNS resolution routed through the dataplane and configured with a service route, stopped responding when the management interface was not configured.
## PAN-101764
Fixed an issue where a process (slmgr) stopped responding during an auto-commit.
## PAN-101391
Fixed an issue where the scheduled nightly custom report was not generated or emailed as expected.
## PAN-101379
Fixed an issue where an invalid Captive Portal authentication policy was successfully pushed to managed firewalls, which caused autocommits to fail.
## PAN-100832
Fixed an issue where, when you performed a Commit from Panorama to bring a firewall back to sync, the rule order displayed a random distribution instead of reflecting the order configured in Panorama.
## PAN-100742
Fixed an issue on Panorama M-Series and virtual appliances where scheduled reports generated more than one DNS lookups, which caused inconsistent name resolutions for DNS deployments.
## PAN-100693
Fixed an issue where you were unable to process Address Group match criteria when the match name included the double quotation ( " ) character.
## PAN-99976
Fixed an issue where a process (pan_threatvault_reports) caused the elastic search script and another process (configd) to stop responding.
## PAN-99707
Fixed an issue where the command-line interface (CLI) displayed an error message when you used a parenthesis character in a Global Protect External Gateway name.
## PAN-99640
A security-related fix was made to address a denial of service (DoS) vulnerability in PAN-OS Linux Kernel (CVE-2017-8890).
## PAN-99478
Fixed an issue where a daemon (authd) took longer than expected to fetch group mapping, which caused commits to take longer than expected.
## PAN-99354
Fixed an issue where the firewall incorrectly denied URL access when the URL filtering profile was configured to alert.
## PAN-98746
Fixed an issue where GlobalProtect clientless VPN did not get redirected to the application URL when you used Internet Explorer as a web browser.
## PAN-98386
Fixed an issue where a security rule with an "Any" destination address did not shadow rules with IPv6 destination addresses when you performed a commit or configuration validation.
## PAN-98107
Fixed an issue on PA-7000 Series firewalls where Encapsulating Security Payload (ESP) sequence numbers were reused when multiple proxy IDs were in use, which caused ESP traffic to drop while you conducted an ESP sequence check.
## PAN-97953
Fixed an issue where Threats (**Monitor** > **Reports** > **Threat Reports** > **Threats**) did not display resolved Threat IDs to Threat/Content Names for disabled signatures as expected.
## PAN-97862
Fixed an issue where an administrator with a custom configuration role could not export custom reports and returned the following error message: `Error enqueuing export job`.
## PAN-97700
Fixed an issue where administrators could not view Managed Collectors (**Panorama** > **Managed Collectors**) web interface.
## PAN-97488
Fixed an issue on Panorama M-Series and virtual appliances where the commit preview did not display as expected.
## PAN-97288
Fixed an issue on GlobalProtect Clientless VPN where the URL gets truncated when you exclude the domain from the `rewrite exclude domain` list.
## PAN-97187
Fixed an issue on VM-Series firewalls where a configuration commit failed due to a reversed bootstrapping process where the configuration was applied before the auth code.
## PAN-96036
Fixed an issue on Panorama M-Series and virtual appliances where the Group Include List (**Device** > **User Identification** > **<group-name>** > **Group Include List**) search function did not respond as expected.
## PAN-95644
Fixed an issue on a firewall where the web interface did not display traffic and unified logs due to a race condition.
## PAN-94475
```caveat
Panorama virtual appliances only
```
Improved a condition where a disk calculation error resulted in an erroneous opt/panlogs/ partition full condition and caused a process (CDB) to stop responding.
## PAN-94161
Fixed an issue where the log collector mode did not display logs as expected after you rebooted Panorama.
## PAN-92872
Fixed an intermittent issue where the firewall sent packets incorrectly to an outgoing interface.
## PAN-92161
Fixed an issue where an internal power status reported as `abnormal` caused the firewall to shutdown.
## PAN-92155
Fixed an issue where administrators were unable to configure an IP address using templates for HA2 (**Device** > **High Availability** > **Data Link (HA2)**) after setting the configuration to **IP** or **Ethernet** for Panorama management servers in an HA configuration.
## PAN-81778
Fixed an issue where scheduled reports did not generate as expected due to a race condition.
## PAN-79640
Fixed an issue where the firewall intermittently logged incorrect actions for WildFire submissions and reports.
@@ -1,301 +0,0 @@
---
type: Known
product: PAN-OS
version: 11.2.10
---
## WF500-6271
A WildFire cluster node that has been configured with an IPv6 management port might not display the signature status when using the following CLI: show wildfire global signature-status sha256 equal <SHA_256_Value>
Workaround: Gracefully restart the affected Wildfire cluster nodes.
## WF500-6259
When a WildFire cluster node configured as a server or worker node is rebooted, issuing the CLI command, global sample-status does not update the samples processed list on the active controller and non-server worker nodes.
Workaround: Gracefully restart the affected WildFire active controller and passive controller in the cluster.
## WF500-6270
The WildFire cluster server and worker nodes might disconnect from the Wildfire cluster management network, resulting in a notifier process exit on WildFire cluster controllers.
Workaround: Gracefully restart the WildFire cluster node where the process exit occurred.
## WF500-6222
When WildFire secure cluster communication is enabled using a custom DNS, the cluster formation might fail due to cluster management communication issues.
Workaround: Do not configure a custom DNS when WildFire secure cluster communication is enabled.
## WF500-6176
When Panorama is used to manage a WildFire cluster, switchover functionality for active and passive controller roles is not available.
## PAN-308507
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.
## PAN-308418
When Advanced DNS Security is enabled and experiences unusually high loads, DNS traffic sessions may be impacted, resulting in DNS resolution failures. Traffic logs for these sessions show an end-reason of resources-unavailable.
Workaround: Disable Advanced DNS Security telemetry (DeviceSetupContent-IDAdvanced DNS Security and uncheck Telemetry Enable).
## PAN-304756
After you disable the shared optimization feature in Panorama, ensure that you perform a full configuration push to all managed multi-vsys devices to re-establish a baseline. Failure to include every device group associated with the multi-vsys device during this push may result in incomplete or inconsistent configurations across virtual systems.
## PAN-304576
Traffic interruption may occur when inspection of HTTP/2 traffic is enabled.
Workaround: Disable HTTP/2 server push using the set deviceconfig setting http2 server-push no CLI command.
## PAN-303959
Traffic that is incorrectly identified as unknown-tcp/unknown-udp eventually drops due to an App-ID resource limitation issue.
## PAN-302927
After an upgrade, the Push to Devices window fails to populate the list of devices automatically. If you manually select devices by clicking Edit Selections, the OK button becomes unresponsive and fails to save or close the selection window. Additionally, clicking Cancel might incorrectly show the device list as empty while retaining the selections in the background.
## PAN-297610
A firewall may become unresponsive after an upgrade due to the fsck command scanning drive partitions in parallel with the root partition, causing the process to take an extended amount of time.
## PAN-295803
A configd memory leak occurs post commit (during Panorama connectivity check), potentially leading to OOM (out of memory condition) and device reboot.
## PAN-295645
When a WildFire cluster is configured centrally using Panorama, it initiates a series of processes, including a software install and reboot, in an order that will leave the resulting WildFire cluster in an unusable state.
## PAN-294179
On the Panorama Config Audit page, some commit versions might display incorrect or missing data. Fields such as, COMMITTED BY , COMMIT DATE , and OBJECT CHANGES might not be visible for some commit versions. Sometimes, commit versions can disappear after a refresh and the commit description field might display corrupted characters.
## PAN-288525
When the Enterprise DLP data filtering profile is configured with a Block action and is used in conjunction with Advanced Threat Prevention, which is configured with an action of reset-both, reset-server, reset-client, or drop for the HTTP Command and Control detector, Dropbox file uploads that exceed the maximum configured file size action will fail.
Workaround: Configure the Advanced Threat Prevention Inline Cloud analysis (ObjectsSecurity ProfilesAnti-Spyware) action for the HTTP Command and Control detector to alert.
## PAN-285061
When Enterprise DLP is enabled, file uploads might unexpectedly fail when 100 continue response is received from the server during file uploads.
## PAN-284700
File downloads for content encoded with zstd (Zstandard), such as specific content from box.com, fail when using Enterprise DLP because zstd decompression is not supported in PAN-OS.
## PAN-283429
When you use custom certificates for the connection between Panorama and a log collector, the automated renewal for the predefined ElasticSearch certificates gets disrupted.
Workaround: Remove the custom certificates before the ElasticSearch certificates expire. This allows the system to correctly identify and renew the predefined ElasticSearch certificates. After the renewal is complete, re-install the custom certificates.
## PAN-278688
```caveat
PA-7500, PA-5500, and PA-3500 firewalls only
```
When DNS Security packet capture is enabled and a domain name has a length of 62 characters, the DNS Security threat log entry is not generated. On the affected platforms, this condition can also trigger a pan_task crash due to shared memory corruption.
Workaround: Disable DNS Security packet capture in anti-spyware profiles (ObjectsSecurity ProfilesAnti-Spyware) and in the DNS Policies tab, set Packet Capture to disable.
## PAN-273158
```caveat
PA-7000 Series firewalls only
```
Due to an incorrect configuration on the ASIC, receiving a mix of jumbo and non-jumbo packets may cause silent packet drops or application slowness.
## PAN-260851
From the NGFW or Panorama CLI, you can override the existing application tag even if Disable Override is enabled for the application (ObjectsApplications) tag.
## PAN-260212
When viewing Applications (ObjectsApplications), child App-IDs may be listed under the incorrect container App-ID.
## PAN-259853
When the DHCP server is enabled for GlobalProtect, the commit error message is not properly displayed when Any is selected as the source interface in the service router configuration ( DeviceSetupServiceService Router Configuration).
## PAN-259423
When the GlobalProtect DHCP feature is enabled with two primary DHCP servers on the GlobalProtect gateway, the gpsvc gets stuck during renewal and after HA failover.
## PAN-254236
TLSv1.3 hybridized Kyber support in the latest versions of Chrome and Edge browsers results in dropped Client Hello packets when SSL/TLS handshake inspection is enabled.
Workaround: Disable SSL/TLS handshake inspection.
## PAN-254108
when upgrading or downgrading a Panorama management server (PanoramaSoftware), managed device (PanoramaDevice DeploymentSoftware), or standalone firewall (DeviceSoftware), Base Releases and Preferred Releases settings are checked (enabled) by default and cause no PAN-OS software images to display.
Workaround: Uncheck (disable) Base Releases or Preferred Releases to display either the available base PAN-OS or preferred PAN-OS releases available to download and install.
## PAN-253963
The auto commit job may take longer than expected to complete when the Panorama management server is in Panorama or Log Collector mode.
## PAN-252661
If you change the service route of gp-ip-mgmt in Device > Setup > Services > Service Features > gp-ip-mgmt and Commit, the change wont take effect. gp-ip-mgmt continues to use the last committed service route.
Workaround: After you change the service route interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or gateway, click OK to save the configuration, and Commit the changes. This commit will include the service route change.
## PAN-250246
Panorama and the firewall display inconsistent IP addresses for dynamic address group members after manually syncing.
## PAN-250062
Device telemetry might fail at configured intervals due to bundle generation issues.
## PAN-248836
The Advanced DNS Security trial license and trial license information cannot be activated and viewed, respectively, on a managed firewall (with expired or active status) from Panorama. These tasks can only be performed on the firewall.
## PAN-247728
When Advanced Routing is enabled, IP multicast is not supported. An upcoming version will provide support for this feature. Customers who have multicast configured or who plan to deploy multicast routing should not upgrade to 11.2.0. Additionally, when Advanced Routing is enabled, the BGP dampening configuration isn't applied to any peers or peer group; the configuration is preserved but has no effect on BGP. Customers can use BGP even if they have applied a Dampening profile to a specific set of peers. The issue doesn't affect any other BGP features.
## PAN-241994
The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards. Palo Alto Networks recommends that you upgrade your ESXi version if it is less than 6.7 U2. For more information, see the compatibility matrix.
## PAN-239612
When the firewall is running PAN-OS 11.2.0 and Advanced Routing is enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay agent doesn't work.
## PAN-237106
LSVPN satellite certificates may be generated with serial numbers exceeding 40 hexadecimal characters. This causes certificate revocation and deletion operations to fail with the following error messages:
db-serialno can be at most 40 characters
db-serialno is invalid
To resolve this issue, use the following CLI commands with the LSVPN satellite serial number to manually delete or revoke the affected certificates:
Delete certificate information:delete sslmgr-store certificate-info portal name <name> serialno <satellite_serial>
Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal <name> serialno <list_of_satellite_serials>
## PAN-236649
If you change the configuration of a firewall acting as a PPPoEv4 or PPPoEv6 client, old routes from the Forwarding Information Base (FIB) and route table for an inherited configuration with dynamic-identifier or client remain visible. Old routes also remain visible for an inherited interface when you execute the CLI command, show interface all.
Workaround: Unconfigure and configure the Inherited Interface.
## PAN-234015
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
## PAN-207442
For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the active-primary HA peer configuration sync to the secondary-passive HA peer may fail. When the config sync fails, the job Results is Successful (Tasks), however the sync status on the Dashboard displays as Out of Sync for both HA peers.
Workaround: Perform a local commit on the active-primary HA peer and then synchronize the HA configuration.
Log in to the Panorama web interface of the active-primary HA peer.
Log in to the Panorama web interface of the active-primary HA peer.
Select Commit and Commit to Panorama.
Select Commit and Commit to Panorama.
In the active-primary HA peer Dashboard, click Sync to Peer in the High Availability widget.
In the active-primary HA peer Dashboard, click Sync to Peer in the High Availability widget.
## PAN-206909
The Dedicated Log Collector is unable to reconnect to the Panorama management server if the configd process crashes. This results in the Dedicated Log Collector losing connectivity to Panorama despite the managed collector connection Status (PanoramaManaged Collector) displaying connected and the managed colletor Health status displaying as healthy.
This results in the local Panorama config and system logs not being forwarded to the Dedicated Log Collector. Firewall log forwarding to the disconnected Dedicated Log Collector is not impacted.
Workaround: Restart the mgmtsrvr process on the Dedicated Log Collector.
Log in to the Dedicated Log Collector CLI.
Log in to the Dedicated Log Collector CLI.
Confirm the Dedicated Log Collector is disconnected from Panorama.admin> show panorama-status Verify the Connected status is no.
Confirm the Dedicated Log Collector is disconnected from Panorama.
admin> show panorama-status Verify the Connected status is no.
admin> show panorama-status
admin> show panorama-status
Verify the Connected status is no.
Restart the mgmtsrvr process.admin> debug software restart process management-server
Restart the mgmtsrvr process.
admin> debug software restart process management-server
admin> debug software restart process management-server
admin> debug software restart process management-server
## PAN-197588
The PAN-OS ACC (Application Command Center) does not display a widget detailing statistics and data associated with vulnerability exploits that have been detected using inline cloud analysis.
## PAN-197419
```caveat
PA-1400 Series firewalls only
```
In NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a Tag value.
## PAN-196758
On the Panorama management server, pushing a configuration change to firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP configurations for SD-WAN as being edited or deleted despite no edits or deletions being made when you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
## PAN-195968
```caveat
PA-1400 Series firewalls only
```
When using the CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI prints an error depending on whether an interface type was selected on the non-PoE port or not. If an interface type, such as tap, Layer 2, or virtual wire, was selected before PoE was configured, the error message will not include the interface name (eg. ethernet1/4). If an interface type was not selected before PoE was configured, the error message will include the interface name.
## PAN-187685
On the Panorama management server, the Template Status displays no synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama.
Workaround: After the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and select CommitPush to Devices.
## PAN-187407
The configured Advanced Threat Prevention inline cloud analysis action for a given model might not be honored under the following condition: If the firewall is set to Hold client request for category lookup and the action set to Reset-Both and the URL cache has been cleared, the first request for inline cloud analysis will be bypassed.
## PAN-184406
Using the CLI to add a RAID disk pair to an M-700 appliance causes the dmdb process to crash.
Workaround: Contact customer support to stop the dmdb process before adding a RAID disk pair to a M-700 appliance.
## PAN-183404
Static IP addresses are not recognized when "and" operators are used with IP CIDR range.
## PAN-181933
If you use multiple log forwarding cards (LFCs) on the PA-7000 series, all of the cards may not receive all of the updates and the mappings for the clients may become out of sync, which causes the firewall to not correctly populate the Source User column in the session logs.
@@ -4,6 +4,34 @@ product: PAN-OS
version: 11.2.10
---
## WF500-6271
A WildFire cluster node that has been configured with an IPv6 management port might not display the signature status when using the following CLI: show wildfire global signature-status sha256 equal <SHA_256_Value>
Workaround: Gracefully restart the affected Wildfire cluster nodes.
## WF500-6259
When a WildFire cluster node configured as a server or worker node is rebooted, issuing the CLI command, global sample-status does not update the samples processed list on the active controller and non-server worker nodes.
Workaround: Gracefully restart the affected WildFire active controller and passive controller in the cluster.
## WF500-6270
The WildFire cluster server and worker nodes might disconnect from the Wildfire cluster management network, resulting in a notifier process exit on WildFire cluster controllers.
Workaround: Gracefully restart the WildFire cluster node where the process exit occurred.
## WF500-6222
When WildFire secure cluster communication is enabled using a custom DNS, the cluster formation might fail due to cluster management communication issues.
Workaround: Do not configure a custom DNS when WildFire secure cluster communication is enabled.
## WF500-6176
When Panorama is used to manage a WildFire cluster, switchover functionality for active and passive controller roles is not available.
## PAN-308507
Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss.