diff --git a/web/data/issues/PAN-OS/addressed/9.1.12-h6_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.12-h6_2026-03-31.md new file mode 100644 index 0000000..7b1b627 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.12-h6_2026-03-31.md @@ -0,0 +1,13 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.12-h6 +--- + +## PAN-202450 + +Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended. + +## PAN-198372 + +Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended. diff --git a/web/data/issues/PAN-OS/addressed/9.1.13-h5_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.13-h5_2026-03-31.md new file mode 100644 index 0000000..40b54ad --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.13-h5_2026-03-31.md @@ -0,0 +1,13 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.13-h5 +--- + +## PAN-237935 + +Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024. + +## PAN-215576 + +Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032. diff --git a/web/data/issues/PAN-OS/addressed/9.1.13_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.13_2026-03-31.md new file mode 100644 index 0000000..82184c5 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.13_2026-03-31.md @@ -0,0 +1,177 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.13 +--- + +## WF500-5513 + +Fixed an issue where cloud queries failed, which generated system logs. The issue occurred because a hash was not found in the cloud. + +## PAN-184445 + +Fixed an issue where, after upgrading Panorama, when **Share Unused Address and Service Objects with Devices** was unchecked, address objects using tags to dynamic address groups were removed after a full commit. + +## PAN-181802 + +Fixed an issue where a memory utilization condition resulted in the web interface responding more slowly than expected and management server restarting. + +## PAN-181309 + +Fixed an issue where Panorama was inaccessible due to the configd process not responding. + +## PAN-180338 + +Fixed an issue where the CTD loop count wasn't accurately incremented. + +## PAN-179274 + +Fixed an issue on high availability configurations where, after upgrading to PAN-OS 9.1.10, PAN-OS 10.0.6, or PAN-OS 10.1.0, the high availability (HA1) and HA1-Backup link stayed down. This issue occurred when the peer firewall IP address was in a different subnet. + +## PAN-179164 + +Fixed an issue where a web-proxy port number was added to the destination URL when captive portal authentication was run. + +## PAN-177907 + +Fixed an issue where, after rebooting the firewall, FQDN address objects referred in rules in a virtual system (vsys) did not resolve when the vsys used a custom DNS proxy. + +## PAN-177626 + +Fixed an issue where aggressive situations caused on-chip descriptor exhaustion. + +## PAN-177551 + +A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)). + +## PAN-176054 + +Fixed an intermittent issue where users did not have access to resources due to a host information profile (HIP) check failure that was caused by the HIP data not being synced between the management plane and the dataplane. + +## PAN-175628 + +```caveat +PA-5200 Series firewalls only +``` + +Fixed an issue where the firewall was unable to monitor AUX1 and AUX2 interfaces through SNMP. + +## PAN-175211 + +Fixed a memory leak issue in the (mgmtsrvr) process. + +## PAN-174781 + +Fixed an issue where the firewall did not send an SMTP 541 error message to the email client after detecting a malicious file attachment. + +## PAN-174709 + +Fixed an out-of-memory (OOM) condition that occurred due to multiple parallel jobs being created by the scheduled log export feature. + +## PAN-174244 + +Fixed an issue where a sudden increase in URL data approached the maximum cache capacity of the firewall. + +## PAN-173469 + +Fixed an intermittent issue where websites were blocked and categorized as not resolved. + +## PAN-173373 + +```caveat +VM-Series firewalls in NSX-T deployments only +``` + +Fixed an issue where deployments dropped packets with the counter pan_netx_send_pkt error. + +## PAN-172837 + +Fixed an intermittent issue where the firewall didn't generate block URL logs for URLs even though the websites were blocked in the client device. + +## PAN-172295 + +Fixed an issue where a HIP database cache loop caused high CPU utilization on a process (useridd) and caused IP address-to-user mapping redistribution failure. + +## PAN-172243 + +Fixed an issue where NetFlow traffic triggered a packet buffer leak. + +## PAN-172056 + +```caveat +VM-Series firewalls only +``` + +The logging rate limit was improved to prevent log loss. + +## PAN-170997 + +Fixed an issue where FQDN service routes were not installed after a system reboot. + +## PAN-170952 + +Fixed script issues that caused diagnostic data to not be collected after path monitor failure. + +## PAN-169212 + +Fixed an issue where information level logs caused configd logs to fill. + +## PAN-168452 + +Fixed an issue where DNS signatures did not trigger. + +## PAN-168400 + +Fixed an issue where, after installing Cloud Services plugin 2.0, the **Plugin cloud_services** status (**Dashboard > High Availability**) displayed as **Mismatch**. + +## PAN-163030 + +Fixed an issue where restarting the devsrvr process caused new GlobalProtect connections to fail with the error message required client certificate not found. This issue occurred due to a key mismatch between the dataplane and the management plane. + +## PAN-161297 + +Fixed an interoperability issue with other vendors when IKEv2 used SHA2-based certificate authentication. + +## PAN-160419 + +Fixed an issue where the following error message displayed in the system log after restarting the firewall: dns-signature initialization from file storage failed, start with empty cache. + +## PAN-159295 + +Fixed an issue where scheduled configuration export files saved in the /tmp folder weren't periodically purged, which caused the root partition to fill up. + +## PAN-159214 + +Fixed an issue where a .txt file was corrupted, which caused the web interface to not display the requested information. + +## PAN-159210 + +Fixed an issue where timed-out DNS Security queries produced incorrect system log entries indicating cloud service connection refused. With this fix, timed-out queries are correctly logged as cloud query timeout. + +## PAN-158541 + +Fixed an OOM condition on the dataplane on FIPS-mode firewall decryption that used DHE ciphers. + +## PAN-158280 + +Fixed an issue where SMB sessions were discarded with the following error message: ctd out of resource. + +## PAN-153019 + +Fixed an issue where the following error message appeared: Error: pan_tdb_load_sml_dfa_serialize(pan_tdb_ser.c:2424): pan_util_file_to_buf /opt/pancfg/mgmt/content//cache/common//sml_dfa.cache.ser error, even though the cache file got regenerated if it was missing. + +## PAN-151749 + +Fixed an issue where Panorama did not show warnings of the last commit job. + +## PAN-146734 + +Fixed an issue where, when a Panorama-pushed configuration was referenced in a local configuration, commits failed after updating the master key on the firewall, which resulted in the following error message: Invalid candidate configuration. Master key change aborted.... + +## PAN-145833 + +```caveat +PA-3200 Series firewalls only +``` + +Fixed an issue where the firewall stopped recording dataplane diagnostic data in dp-monitor.log after a few hours of uptime. diff --git a/web/data/issues/PAN-OS/addressed/9.1.15-h1_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.15-h1_2026-03-31.md new file mode 100644 index 0000000..319f236 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.15-h1_2026-03-31.md @@ -0,0 +1,21 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.15-h1 +--- + +## PAN-204118 + +Fixed an issue where browser sessions stopped responding device group template admin users with access domains that had many device groups or templates. + +## PAN-199500 + +Fixed an issue where, when many NAT policy rules were configured, the pan_comm process stopped responding after a configuration commit due to a high number of debug messages. + +## PAN-196874 + +Fixed an issue where, when the firewall accepted ICMP redirect messages on the management interface, the firewall did not clear the route from the cache. + +## PAN-202247 + +Fixed an issue with firewalls in HA configurations where the firewall dropped IKE SA connections if the peer firewall received an INVALID_SPI message. This occurred even though no IKE SA was associated with the SPI in the received INVALID-SPI payload. diff --git a/web/data/issues/PAN-OS/addressed/9.1.16-h4_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.16-h4_2026-03-31.md new file mode 100644 index 0000000..d64c4d0 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.16-h4_2026-03-31.md @@ -0,0 +1,13 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.16-h4 +--- + +## PAN-237871 + +```caveat +WF-500 appliances and PAN-DB private cloud deployments only +``` + +Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended. diff --git a/web/data/issues/PAN-OS/addressed/9.1.17-h1_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.17-h1_2026-03-31.md new file mode 100644 index 0000000..900664e --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.17-h1_2026-03-31.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.17-h1 +--- + +## PAN-239241 + +Extended the root certificate for WildFire appliances to December 31, 2032. diff --git a/web/data/issues/PAN-OS/addressed/9.1.18_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.18_2026-03-31.md new file mode 100644 index 0000000..b8f947f --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.18_2026-03-31.md @@ -0,0 +1,57 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.18 +--- + +## PAN-242561 + +Fixed an issue where GlobalProtect tunnels disconnected shortly after being established when SSL was used as the transfer protocol. + +## PAN-240688 + +Fixed an issue where LSVPN tunnels did not come up and did not switch tunnel monitoring up. + +## PAN-234596 + +Fixed an issue on firewalls in active/passive high availability (HA) configurations where the passive firewall incorrectly became active after a reboot. + +## PAN-221208 + +Fixed an issue where the tunnel monitor was unable to remain up when Zone Protection with Strict IP was enabled and NAT Traversal was applied. + +## PAN-217465 + +Fixed an issue where the Panorama web interface became unresponsive and displayed the error message **504 Gateway Not Reachable**. + +## PAN-212860 + +Fixed an issue where changes to the SD-WAN database did not remove the old entries. + +## PAN-205255 + +Fixed a rare issue that caused the dataplane to restart unexpectedly. + +## PAN-201269 + +Fixed an issue where commits failed with the error message IPv6 addresses are not allowed because IPv6-firewalling is disabled when Security policy rules had an address group with more than 1000 FQDN address objects. + +## PAN-199214 + +Fixed an intermittent issue where downloading threat pcap via XML API failed with the following error message: /opt/pancfg/session/pan/user_tmp/XXXXX/YYYYY.pcap does not exist. + +## PAN-196457 + +Fixed an issue where extraneous logs displayed in the Traffic log when Security policy rule settings were changed. + +## PAN-195342 + +Fixed an issue on Panorama where, when you attempted to context switch from a managed firewall on PAN-OS 10.1.7 or an earlier release back to Panorama, the context switch failed with the following error message: Could not find start token '@start@. + +## PAN-180948 + +Fixed an issue where an external dynamic list fetch failed with the error message Unable to fetch external dynamic list. Couldn't resolve host name. Using old copy for refresh. + +## PAN-159508 + +Fixed an IPSec tunnel memory leak issue where IPSec tunnels failed during rekey. diff --git a/web/data/issues/PAN-OS/addressed/9.1.19_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.19_2026-03-31.md new file mode 100644 index 0000000..2a3997a --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.19_2026-03-31.md @@ -0,0 +1,13 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.19 +--- + +## PAN-245041 + +Fixed an issue where the WF-500 appliance returned an error verdict for every sample in FIPS mode. + +## PAN-231658 + +Fixed an issue where DNS resolution failed when interfaces were configured as DHCP and a DNS server was provided via DHCP while also statically configured with DNS servers. diff --git a/web/data/issues/PAN-OS/addressed/9.1.2-h1_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.2-h1_2026-03-31.md new file mode 100644 index 0000000..b77fe57 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.2-h1_2026-03-31.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.2-h1 +--- + +## PAN-144073 + +Fixed an issue where on the Panorama management server, hub and branch firewall latency, jitter, and packet loss data was not updated when monitoring SD-WAN link performance (**Panorama** > **SD-WAN** > **Monitoring**). diff --git a/web/data/issues/PAN-OS/addressed/9.1.3-h1_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.3-h1_2026-03-31.md new file mode 100644 index 0000000..ced8fe3 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.3-h1_2026-03-31.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.3-h1 +--- + +## PAN-150172 + +Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled. diff --git a/web/data/issues/PAN-OS/addressed/9.1.4_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.4_2026-03-31.md new file mode 100644 index 0000000..2a3c628 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.4_2026-03-31.md @@ -0,0 +1,309 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.4 +--- + +## WF500-5320 + +Fixed an issue where the WF-500 cluster did not synchronize verdicts after successful verdict recheck queries with the WildFire global cloud. + +## PAN-151197 + +Fixed an issue where a process (authd) restarted when an administrator authenticated to the firewall with an Active Directory (AD) account. This issue occurred when LDAP was configured with FQDN, used DHCP instead of a static management IP address, and used the management interface to connect to the LDAP server. + +## PAN-150172 + +Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled. + +## PAN-150170 + +```caveat +and PAN-149822 +``` + +A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)). + +## PAN-150013 + +```caveat +and PAN-149822 +``` + +A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)). + +## PAN-149377 + +A fix was made to address a vulnerability regarding information exposure through log files in PAN-OS that made it possible for configuration secrets for HTTP, email, and SNMP trap v3 log forwarding server profiles to be logged to the logrcvr.log system log ([CVE-2021-3032](https://security.paloaltonetworks.com/CVE-2021-3032)). + +## PAN-148806 + +A fix was made to address an uncontrolled resource consumption vulnerability in PAN-OS that allowed for a remote unauthenticated user to upload temporary files through the management web interface that were not properly deleted after the request was finished. An attacker could disrupt the availability of the management web interface by repeatedly uploading files until available disk space was exhausted ([CVE-2020-2039](https://security.paloaltonetworks.com/CVE-2020-2039)). + +## PAN-148676 + +Fixed an issue where the panlogs directory reached 100% utilization on the firewall due to early calculation of the .size file. + +## PAN-148522 + +Fixed an issue for PAN-DB where certain situations caused performance issues. + +## PAN-147996 + +```caveat +PA-7000b Series firewalls only +``` + +Fixed a buffer overflow issue. + +## PAN-147399 + +Fixed an issue where Panorama in Legacy mode rebooted due to multiple process (reportd) restarts. + +## PAN-147258 + +Fixed an issue with one-way audio for inbound voice calls due to incorrect source port translation. + +## PAN-147203 + +Fixed an issue where API calls did not return the output for the operational command for running configurations. + +## PAN-146837 + +A fix was made to address a vulnerability involving information exposure through log files where sensitive fields were recorded in the configuration log without masking on PAN-OS software when the after-change-detail custom syslog field was enabled for configuration logs and the sensitive field appeared multiple times in one log entry. The first instance of the sensitive field was masked but subsequent instances were left in clear text ([CVE-2020-2043](https://security.paloaltonetworks.com/CVE-2020-2043)). + +## PAN-146624 + +Fixed an issue where exporting logs from the web interface did not generate a system log entry. + +## PAN-146531 + +Fixed an issue where conversion from Panorama mode to logger mode was enabled even when an admin user named admin did not exist in the configuration, which caused access to the appliance to be lost. + +## PAN-146086 + +Fixed an issue for Amazon Web Services (AWS) types C5 and M5 where Panorama was unable to use NMVe storage. + +## PAN-145942 + +After upgrading to certain PAN-OS 8.1 and 9.0 versions, for certain configurations using dynamic routing without graceful restart and with Bidirectional Forwarding Detection (BFD) enabled, there was a longer traffic hit after an HA failover compared to previous versions. This was due to BFD incorrectly timing admin-down messages for the failover event. + +## PAN-145929 + +Fixed an issue where, after upgrading the passive firewall, the stream control transmission protocol (SCTP) sessions synced from the active firewall did not retain the rule information, and, after failover, SCTP stateful inspection did not work. + +## PAN-145422 + +Fixed an issue where a process (all_pktproc) restarted while processing SSL VPN sessions. + +## PAN-145302 + +Fixed an issue where the high availability (HA) peer device did not preserve its import configuration when the mode was active/active and VR sync was disabled. + +## PAN-145142 + +Fixed an issue where Panorama running 9.0.8 allowed a user with the admin role Device Group and Template to create templates and template stacks. + +## PAN-144882 + +Fixed an issue where the firewall generated critical system logs: Fsck failed for Logging Raid Disk Pair after downgrading from PAN-OS 9.0 to PAN-OS 8.1. + +## PAN-144804 + +Fixed an issue where the firewall generated GPRS tunneling protocol (GTP) logs for invalid GTP packets. This fix also implements a counter, flow_gtp_invalid_ver, where the invalid packets are counted. + +## PAN-144670 + +Fixed an issue where the multi-factor authentication (MFA) timestamp was not redistributed across the virtual system (vsys) when the IP address-to-user mapping type was UIA. + +## PAN-144613 + +Fixed an issue where, when previewing device group configurations from Panorama, invalid messages were returned. With this fix, the configuration preview no longer returns invalid messages. + +## PAN-144492 + +Fixed an issue where traffic matched an incorrect URL filtering profile due to a similarity in the MD5 hashes between the URL filtering profiles. + +## PAN-143705 + +Fixed an issue where delicensing a large number of devices from Panorama failed. + +## PAN-143686 + +Fixed an issue where a firewall running in FIPS mode was unable to download the GlobalProtect datafile even when a GlobalProtect license was installed and valid. + +## PAN-143644 + +Fixed an issue where traffic did not match an FQDN address group based policy. + +## PAN-143090 + +Fixed an issue where the firewall silently dropped TCP out-of-order packets. + +## PAN-142927 + +Fixed an issue where the locked users list grew too large, which caused 100% CPU usage on a process (authd). With this fix, locked users will be purged hourly if the lockout time for that user has expired. + +## PAN-142853 + +Fixed an issue on Panorama where commits failed, referring to a portion of the configuration that was not changed. + +## PAN-142523 + +Fixed an issue where application-based SD-WAN policy match did not work if application traffic was subjected to SSL decryption. + +## PAN-141515 + +Fixed an issue where a service object with a destination port that is pushed from Panorama displays as **[object Object]** on the firewall. + +## PAN-141099 + +Fixed an issue where the HTTP/2 stream method was no longer valid after overloading the same pointer to point to either the HTTP/2 stream or the proxy flow. + +## PAN-140747 + +Fixed an issue where the firewall failed to establish SFTP firewall-server connections when SSH decryption was enabled. + +## PAN-140494 + +Added a mechanism to detect corrupted or incorrect formats received on dataplane CPU. Such packets are dropped, and a counter, pkt_recv_bad_group, is incremented. + +## PAN-140272 + +Fixed an issue where RADIUS authentication failed when using an ampersand (&) in the RADIUS shared secret. + +## PAN-139764 + +Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak, which caused a process (configd) to restart. + +## PAN-139680 + +Fixed an issue where dynamic route updates triggered an unintentional refresh of the DHCP client interface IP address, which led to the removal and re-addition of the default route associated with the DHCP client IP address and caused traffic disruption. + +## PAN-139587 + +```caveat +PA-5200 Series and PA-7000 Series firewalls only +``` + +Fixed an issue where high and continuous CPU utilization was seen on dataplanes after IPSec Encapsulating Security Payload (ESP) rekeying occurred for multiple tunnels. + +## PAN-139365 + +```caveat +PA-7000 Series firewalls only +``` + +Enhanced latency-sensitive protocols processing. With this fix, the following latency-sensitive control traffic will be prioritized: BGP, Bidirectional Forwarding Detection (BFD), LACP, OSPF, OSPFv3, Protocol Independent Multicast (PIM), and Internet Group Management Protocol (IGMP). + +## PAN-139264 + +Fixed an issue where the Elasticsearch cluster status displayed in yellow due to a missing replica serial number. + +## PAN-139172 + +Fixed an issue where response pages generated from the firewall used the SMAC and DMAC addresses from the original packet, which caused a MAC flap on connected switches. + +## PAN-138584 + +Fixed an issue that prevented the addition of a secondary logging disk for a VM-Series firewall deployed on Amazon Web Services (AWS) using Nitro server instance types. + +## PAN-137770 + +Fixed an issue where the dataplane restarted due to a loop in DoS protection source-destination IP address classification. + +## PAN-137661 + +Fixed an issue where certain packets destined to untagged subinterfaces were silently dropped on multi-dataplane platforms. + +## PAN-137138 + +Fixed an issue where a process (configd) consistently restarted with the following error message: virtual memory limit exceeded, restarting due to a dynamic updates push from Panorama to multiple firewalls. + +## PAN-136844 + +Fixed an issue for S11 traffic where if the Modify Bearer Request message came after 30 seconds of Create Session Response message, the firewall dropped the Modify Bearer Request packet. This fix increases this time to 90 seconds. + +## PAN-136650 + +Fixed an issue where a Log Collector remained in an out-of-sync state after configuring an IP address (local or public) on an additional Ethernet interface. + +## PAN-135889 + +Fixed an issue where GTP-U tunnel session was setup incorrectly on receiving Modify Bearer Requests/ Responses with multiple Bearer Context for different EBIs + +## PAN-135887 + +Fixed an issue where the inner GTP-U flows were installed using incorrect zones, which led to traffic issues if the firewall was in line for the S1-U interface. + +## PAN-135673 + +Fixed an issue where the firewall kept its connection to Cortex Data Lake even after the configuration had been disabled and the license was expired. + +## PAN-135134 + +Fixed an issue where using a session_proxy() without checking that it actually is a proxy led to a dataplane process restart. + +## PAN-134029 + +Fixed an intermittent issue on the firewall where H.225 VOIP signaling packets dropped. + +## PAN-132285 + +Fixed an intermittent issue where a Security policy with **Send ICMP Unreachable** enabled for certain drop or reset sessions caused a process (all-pktproc) to restart. + +## PAN-131474 + +A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where the connection details for a scheduled configuration export were logged in system logs ([CVE-2021-3037](https://security.paloaltonetworks.com/CVE-2021-3037)). + +## PAN-129461 + +Fixed an issue where excessive next hop FPGA exceptions occurred when an ARP request or response was lost in the network in an ECMP configuration, which blocked subsequent ARP learning due to a full queue. + +## PAN-128650 + +Fixed an issue where selecting **Preview Changes** under a specific device group resulted in the following error message: Parameter device group missing. + +## PAN-123279 + +Fixed an issue where a process (configd) stopped responding after upgrading Panorama to 8.1.9 from 8.0.16 due to 8.0 WildFire appliance register requests. + +## PAN-115896 + +Fixed an issue where the static route path monitoring status was not viewable from the CLI or web interface and failed with the following error message: failed to execute op command. + +## PAN-114761 + +Fixed an issue where the log receiver failed to establish connections to Cortex Data Lake when it was unable to validate Cortex Data Lake certificates. + +## PAN-114264 + +Fixed an issue where sessions were offloaded as the application identification was performed when you configured a custom application with **Continue scanning for other application**. + +## PAN-113767 + +Fixed an issue where the firewall silently dropped packets when security profiles were attached and FPGA enabled AHO and DFA. + +## PAN-112972 + +Fixed an issue where scheduled reports were not generated as expected when you added groups in a query builder. + +## PAN-111333 + +An enhancement was made to increase the pattern match limit to recognize applications and threats accurately. + +## PAN-110685 + +Fixed a rare issue where an incorrect User-ID™ match to the respective LDAP group caused a security policy mismatch. + +## PAN-109894 + +Fixed an issue where, when DHCP requests were sent from a subinterface configured as a DHCP client, packets dropped due to improper handling of the ARP reply for the DHCP requests. + +## PAN-103865 + +Fixed an issue where the firewall did not detect user credentials when the number of users exceeded 60,000. To leverage this fix, you must upgrade Windows agents to User-ID agent <8.1.11 | 9.0.4> or a later User-ID agent <8.1 | 9.0> release. + +## PAN-101484 + +A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2038](https://security.paloaltonetworks.com/CVE-2020-2038)). diff --git a/web/data/issues/PAN-OS/addressed/9.1.5_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.5_2026-03-31.md new file mode 100644 index 0000000..e5a39e4 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.5_2026-03-31.md @@ -0,0 +1,421 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.5 +--- + +## PAN-154092 + +Added an enhancement that provides an option to increase Data Plane Development Kit (DPDK) ring size and DPDK queue number for VM-Series firewalls deployed on ESXi. + +## PAN-152699 + +Fixed an issue where the firewall added a redundant 0\r\n packet while processing Clientless VPN traffic. + +## PAN-152285 + +Fixed an issue where certain GPRS tunneling protocol (GTP-U) sessions that could not complete installation still occupied the flow table, which led to higher session table usage. + +## PAN-151203 + +Fixed an issue where the firewall dropped certain GTPv1 Update PDP Context packets. + +## PAN-151164 + +Fixed an issue where logs weren't able to be migrated from PA-5200 Series firewalls manually via the CLI. + +## PAN-151057 + +Fixed an issue where upgrading the capacity license on a virtual machine (VM) high availability (HA) pair resulted in both firewalls going into a non-functional state instead of only the higher capacity license firewall. + +## PAN-150750 + +```caveat +PA-5200 and PA-7000 Series firewalls only +``` + +Fixed an intermittent issue where the firewall dropped packets when two or more GTP packets on the same GTP tunnel were very close to each other. + +## PAN-150748 + +Fixed an issue where the firewall silently dropped GTPv2-C Delete Session Response packets. + +## PAN-150746 + +Fixed an issue where the firewall dropped GTP packets with Delete Bearer messages for EBI 6 if they were received within two seconds of receiving the Delete Bearer messages for EBI 5. + +## PAN-150243 + +Fixed an issue where after a successful commit, the candidate configuration was not updated to running configuration when initiated by an API-privileges-only custom role based administrator. + +## PAN-149839 + +```caveat +PA-7000 Series firewalls only +``` + +Added CLI commands to enable/disable resource-control groups and CLI commands to set an upper memory limit of 8G on a process (mgmtsrvr). To enable resource-control groups, use debug software resource-control enable and to disable them, use debug software resource-control disable. To set the memory limit, use debug management-server limit-memory enable, and to remove the limit, use debug management-server limit-memory disable. For the memory limit change to take effect, the firewall must be rebooted. + +## PAN-149813 + +Fixed an issue where the reply to an XML API call from Panorama was in a different format after upgrading to PAN-OS 8.1.14-h1 and later releases, which caused automated systems to fail the API call. + +## PAN-149770 + +Fixed an issue with debug file handling that led to a process (mgmtsrvr) restart. + +## PAN-149480 + +Fixed an issue where, if Panorama was connected to log collectors running an earlier release, a custom report query from Panorama, which includes new fields not supported in prior releases, triggered a restart on a process (reportd). + +## PAN-149426 + +Fixed an issue where non-superuser administrators with all rights enabled were unable to **Review Policies** or **Review Apps** for downloaded or installed content versions. + +## PAN-149325 + +Fixed an issue on Panorama where the web interface took more time than expected to load changes when the virtual router was large or when there was a large configuration change request from the web interface. + +## PAN-149296 + +Fixed an issue on Panorama where system and configuration logs of dedicated Log Collectors did not show up on Panorama appliances in Management Only mode. + +## PAN-149008 + +Fixed an issue where the CLI command Show config running following the CLI command set cli op-command-xml-output on produces an unreadable output. + +## PAN-149005 + +Fixed an issue where XML API failed to fetch logs larger than 10MB. + +## PAN-148564 + +Fixed an issue where Panorama stopped showing new logs when url_category_list was in the URL payload format of the HTTP(S) server profile used to forward URL logs from the Panorama Log Collector. + +## PAN-148087 + +Fixed an issue where the object identifier (OID) being polled for the component hrStorageUsed was not unique after a PAN-OS upgrade. + +## PAN-147741 + +Fixed an issue where an API call for correlated events did not return any events. + +## PAN-147595 + +Fixed an issue where, after a policy commit and session rematch, stream control transmission protocol (SCTP) logs for an existing SCTP session still showed old rule information. + +## PAN-147285 + +Fixed an issue where host information profile (HIP) details were not available on Panorama even when a HIP redistribution configuration was in place. + +## PAN-146878 + +Fixed an issue where TCP traffic dropped due to TCP sequence checking in an HA active/active configuration where traffic was asymmetric. + +## PAN-146841 + +Fixed an issue in Panorama where a commit-all to the managed firewalls failed with the following error message: invalid object reference when address objects were uploaded using an external script. + +## PAN-146787 + +Fixed an issue where traffic incorrectly matched URL based authentication policies. + +## PAN-146650 + +A fix was made to address an authentication bypass vulnerability in the GlobalProtect SSL VPN component of PAN-OS that allowed an attacker to bypass all client certificate checks with an invalid certificate. As a result, the attacker was able to authenticate as any user and gain access to restricted VPN network resources when the gateway or portal was configured to rely only on certificate-based authentication ([CVE-2020-2050](https://security.paloaltonetworks.com/CVE-2020-2050)). + +## PAN-146623 + +Fixed an issue where a GlobalProtect client in a system with umlaut diacritics serial number was unable to log in to the GlobalProtect gateway. + +## PAN-146506 + +Fixed an issue where memory usage on a process (useridd) was high, which caused the process to restart on the firewall acting as the User-ID redistribution agent. This issue occurred when multiple clients requested IP address-to-user mappings at the same time. + +## PAN-146284 + +Fixed an issue where Application and Threat Content installation failed on the firewall with the following error message: Error: Threat database handler failed. + +## PAN-146117 + +Fixed an issue on the firewalls where memory usage on a process (devsrvr) increased after running the show object dynamic-address-group all CLI command. + +## PAN-146115 + +Fixed an issue where GlobalProtect IPsec connections flapped when the peer address to the gateway changed due to NAT. + +## PAN-146107 + +Fixed an issue where memory allocation failure caused a process (pan_comm) to restart several times, which caused the firewall to restart. + +## PAN-145823 + +Fixed an issue where BGP learned routes were incorrectly populated with a VR error as a next hop. + +## PAN-145757 + +Fixed an issue on the firewalls where a process (all_pktproc) restarted while processing Session Traversal Utilities for NAT (STUN) over TCP. + +## PAN-145752 + +Fixed an issue where exporting policies to PDF or CSV files did not include all policies and contained duplicates. + +## PAN-145721 + +Fixed an issue where Application Command Center (ACC) data did not load when accessed from the **Top Applications** widget in the **Dashboard**. + +## PAN-145507 + +Fixed an issue on the firewalls where traffic originating from a GlobalProtect user did not match HIP-based Security policies using the cached HIP report. Instead, the traffic was denied until the GlobalProtect agent submitted a new HIP report about 20 seconds later. + +## PAN-145305 + +Fixed an issue where an inconsistent PAN-DB cloud connection caused the firewall to negotiate the incorrect version and decode the cloud responses with the incorrect format. + +## PAN-145133 + +A fix was made to address a vulnerability in the PAN-OS signature-based threat detection engine that allowed an attacker to evade threat prevention signatures using specifically crafted TCP packets ([CVE-2020-1999](https://security.paloaltonetworks.com/CVE-2020-1999)). + +## PAN-145041 + +Fixed an issue on the firewalls where a process (all_task) stopped responding. + +## PAN-144919 + +Fixed an issue on an M-600 appliance where the Panorama management server stopped receiving new logs from firewalls because delayed log purging caused log storage on the Log Collectors to reach maximum capacity. + +## PAN-144448 + +Fixed an issue with the automated correlation engine that caused firewalls to stop generating correlated event logs for the beacon-heuristics object (ID 6005). + +## PAN-144232 + +Fixed an issue where, when any change was made to an authentication profile, the LDAP server or local user database in a shared context removed the user group mapping information from the firewall. + +## PAN-143959 + +Fixed an issue on Panorama where a custom administrator with all rights enabled was not able to display the content of the external dynamic list (EDL) on the Panorama web interface. + +## PAN-143809 + +Fixed an issue where Log Collectors had problems ingesting logs for older days received at a high rate. + +## PAN-143796 + +Fixed an issue where commits failed on the firewall due to memory allocation failure. Configuration memory can be checked using the debug dataplane show cfg-memstat statistics CLI command. + +## PAN-143010 + +```caveat +PA-7000 Series firewalls only +``` + +Fixed an issue with intermittent packet loss for GlobalProtect SSL tunnel traffic. + +## PAN-142562 + +Fixed an issue on Panorama where creating certificates took longer than expected, which caused configuration lock timeouts. + +## PAN-142363 + +Fixed an issue where a process (mprelay) stopped responding and invoked an out-of-memory (OOM) killer condition and displayed the following error messages: `tcam full` and pan_plfm_fe_cp_arp_delete. + +## PAN-142219 + +Fixed an issue where a Panorama log query did not work for closed indices. + +## PAN-141980 + +Fixed an issue where random member ports in a link aggregate group failed to join the aggregate group due to the following error: Link speed mismatch. + +## PAN-141895 + +Fixed an issue that prevented GTP tunnel session timeout values from being configured via the web interface. + +## PAN-141793 + +Fixed an issue where Panorama did not show correct logs filtered with not, leq, and geq. + +## PAN-141717 + +Fixed an issue where an administrative user using custom admin roles and without access to the **Device** tab was unable to expand the detailed views of **Monitor > Logs**. + +## PAN-141551 + +Fixed an issue where SSH service restart management did not take effect in the SSH management server profile. + +## PAN-141296 + +Fixed an issue where a large certificate chain transmission delayed the decryption process and did not populate the mutual authentication cache. + +## PAN-140900 + +Fixed an issue where IP address-to-tag mapping entries had negative time-to-live (TTL) values instead of being removed after expiry. + +## PAN-140883 + +Fixed an issue where, after rebooting the firewall, the SNMP object identifier (OID) for TCP connections per second (panVsysActiveTcpCps / .1.3.6.1.4.1.25461.2.1.2.3.9.1.6.1) returned 0 until another OID was pulled. Additionally, after a restart of a daemon (snmpd), if the above OID was called before other OIDs, there was an approximate 10 second delay in populating the data pulled by each OID. + +## PAN-140736 + +Fixed an issue where configuration synchronization failed in an HA configuration. + +## PAN-140382 + +Fixed an issue where the Host Evasion Threat ID signature did not trigger for the initial session even after the DNS response was received before the session expired. + +## PAN-140227 + +```caveat +PA-7000 Series firewalls only +``` + +Fixed a rare issue where the firewall rebooted due to path monitoring failure on the Log Processing Card (LPC). + +## PAN-140173 + +Fixed an issue where a high number of groups in group mapping caused a process (useridd) to exit. + +## PAN-140100 + +Fixed an issue where **Detailed Log View** (**Monitor > Logs > Traffic**) did not display the URL filtering logs as expected on HTTP/2 stream sessions. + +## PAN-140084 + +```caveat +PA-3200 Series firewalls only +``` + +Fixed an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate was set as 2. + +## PAN-139991 + +Fixed an issue where the web interface and the CLI were inaccessible, which caused the following error message to display on the web interface: Timed out while getting config lock. + +## PAN-139233 + +Fixed an issue where HIP reports failed to show up via the web interface or the CLI. + +## PAN-139136 + +Fixed an issue where a large number of groups in group mappings caused a process (useridd) to exit. + +## PAN-138427 + +Fixed an issue where pushing a configuration from a Panorama management server running PAN-OS 9.0 to a firewall running PAN-OS 8.1 produced a HTTP/2 warning. To leverage this fix, update both Panorama and the firewall to PAN-OS 9.1.5. + +## PAN-137663 + +Fixed a cosmetic issue where misleading App-ID and rule shadowing warnings populated after a commit. + +## PAN-137157 + +Fixed an issue where Panorama became inaccessible with the following error message: Timed out while getting config lock. + +## PAN-135989 + +Fixed an issue where the serial number was unknown for VM-Series firewalls after upgrading from PAN-OS 8.0 to PAN-OS 8.1. + +## PAN-135354 + +Fixed an issue where the paths between the control plane and the dataplanes in network processing cards (NPCs) stalled in the dataplane-to-control plane direction due to the Ring Descriptor entries becoming out of sync on each side. This produced unrecoverable data path monitoring failures, which caused the chassis to become nonfunctional. + +## PAN-135071 + +Fixed an issue in Panorama where the template stack drop-down was missing templates when using access domain. This issue is fixed only for existing template stacks. + +## PAN-134907 + +Fixed an issue where IP tags were not evaluated in the filter evaluation criteria when Dynamic Address Groups were configured. + +## PAN-134745 + +Fixed an issue where Panorama commits failed due to a process (useridd) running on high file descriptors as a large number firewalls connect to Panorama for User-ID redistribution. + +## PAN-134226 + +Fixed an issue where **AdminStatus** for HA1 and High Speed Chassis Interconnect (HSCI) interfaces were incorrectly reported. + +## PAN-133934 + +Fixed an intermittent issue where user-to-IP address mappings were not redistributed to client firewalls. + +## PAN-131750 + +Fixed an issue where a configuration push from Panorama to the firewall showed the **Commit All** status as completed even though the job was still being processed. + +## PAN-130955 + +Fixed an issue where templates on the secondary Panorama appliance were out of sync with the primary Panorama appliance due to an empty content-preview node. + +## PAN-130389 + +```caveat +PA-220 firewalls only +``` + +Fixed an issue where rx-broadcast and rx-multicast interface counters were not increasing even broadcast and/or multicast traffic was being received. + +## PAN-130357 + +Fixed a memory leak issue where virtual memory used by the SNMP process started to slowly increase when the request was sent with a request-id of 0. + +## PAN-129376 + +```caveat +PA-800 Series firewalls only +``` + +Fixed an issue that prevented ports 9-12 from being powered down by hardware after being requested to do so. + +## PAN-129234 + +Fixed an issue where syslog connection failures were frequently reported in system logs. + +## PAN-128048 + +Fixed an issue where certificate-based authentication with IKEv2 IPSec tunnels failed to establish with some third-party vendors. + +## PAN-126353 + +Fixed an issue where the XML API used to retrieve hardware status periodically failed with a 200 OK message and no data. + +## PAN-125218 + +A fix was made to address an information exposure vulnerability in Panorama that disclosed the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performed a context switch ([CVE-2020-2022](https://security.paloaltonetworks.com/CVE-2020-2022)). + +## PAN-124681 + +A fix was made to address a vulnerability where Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls were not cleared before the data frame was created ([CVE-2021-3031](https://security.paloaltonetworks.com/CVE-2021-3031)). + +## PAN-121035 + +Added support of high powered module PAN-QSFP28-100GBASE-ER4. + +## PAN-120245 + +Fixed an issue on Panorama where WildFire cloud content download failed for content deployment to the WF-500 appliance. + +## PAN-119982 + +Fixed an issue where template variable view failed to display some template variables when the **Device Priority** type variable was configured. + +## PAN-115541 + +Fixed an issue where removing a cipher from an SSL/TLS profile did not take effect if it was attached to the management interface. + +## PAN-112449 + +Fixed an issue that caused a daemon (snmpd) to hang when sending a Simple Network Management Protocol (SNMP) GET request for LcLogUsageTable on a Panorama appliance in Management Only mode. + +## PAN-110423 + +Fixed an issue where mounting failure occurred and root partition reached 100%. + +## PAN-110168 + +Fixed an issue where the firewall and Panorama web interface did not present HSTS headers to your web browser. + +## PAN-103018 + +Fixed an issue where, when defining the match criteria for dynamic address groups on Panorama, the boolean AND/OR operators did not function properly. diff --git a/web/data/issues/PAN-OS/addressed/9.1.6_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.6_2026-03-31.md new file mode 100644 index 0000000..83d3326 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.6_2026-03-31.md @@ -0,0 +1,305 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.6 +--- + +## PAN-154166 + +```caveat +VM-500 and later firewalls only +``` + +A new CLI command was added to increase the number of threads for handling incoming GlobalProtect connection requests when there is a high login rate and a slow authentication response from an external server. + +## PAN-154114 + +A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where secrets in PAN-OS XML API requests were logged in cleartext in the web server logs when the API was used incorrectly ([CVE-2021-3036](https://security.paloaltonetworks.com/CVE-2021-3036)). + +## PAN-154093 + +Fixed an issue where a process (httpd) restarted during Security Assertion Markup Language (SAML) logout sessions initiated from the IdP. + +## PAN-153983 + +Fixed an issue where the IPSec encapsulation sequence was not properly synced to the dataplanes on a high availability (HA) active/passive cluster. + +## PAN-153874 + +Fixed a capacity issue caused by high operational activity and large configurations on Panorama. This fix increased the virtual memory limit on the configd process to 32GB. + +## PAN-153868 + +Fixed an issue where firewall forwarding logs to Cortex Data Lake displayed **License** as gray and device connectivity as **Error** under **Logging Service Status**. + +## PAN-153813 + +Fixed an issue where the proxy configuration did not get honored, which caused certificate revocation list (CRL) checks from the firewall to fail. + +## PAN-153673 + +Fixed an issue where traffic logs were not shown due to a thread timeout that was causing the reading of the logs from the dataplane to slow. + +## PAN-153440 + +Fixed an issue where firewalls repeatedly connected and disconnected to Cortex Data Lake due to a probing issue. + +## PAN-153436 + +Added CLI commands to increase thread limits to reduce task thread exhaustion on a process (configd). + +## PAN-153111 + +Fixed an issue where packet buffer unavailability caused host-bound sessions to remain in an opening state in the dataplane. + +## PAN-152706 + +Fixed an intermittent issue where Panorama did not retrieve firewall logs from Cortex Data Lake. + +## PAN-152440 + +Fixed an issue where the syntax on GlobalProtect DNS suffixes was not validated. + +## PAN-152282 + +Fixed an issue where platforms using AHO for content and application inspection run into dataplane process (all_pktproc) restarts. + +## PAN-152253 + +Fixed an issue where the Destination NAT with **DNS Rewrite** enabled and set to **forward** did not work when the destination IP address was a single IP address instead of an IP range. + +## PAN-152106 + +Fixed an issue where a process (genindex.sh) caused the management plane CPU usage to remain high for a longer period of time than expected. + +## PAN-152027 + +Fixed an issue with URL Filtering where websites that were previously in the malicious category but have since been cleared remained in the malicious category in the dataplane cache. These websites were moved to the benign category only after you manually cleared the cache. + +## PAN-152017 + +Fixed an issue where a VM-Series firewall on Amazon Web Services (AWS) failed on first reboot after enabling FIPS mode + +## PAN-151692 + +Fixed a permission issue where a Panorama administrator was unable to download or install dynamic updates (**Panorama > Device Deployment**). + +## PAN-151149 + +Fixed an issue where certificates, custom logos, and SAML metadata were unable to be uploaded from the web interface using a Chromium-based browser running version 84 or later. + +## PAN-150613 + +Fixed an issue that caused a process (mprelay) to stop responding when committing changes in the Netflow Server Profile configuration (**Device > Server Profiles > Netflow**). + +## PAN-150305 + +Fixed an issue where the output for show user ip-user-mapping-mp all, when called via XML API, was written to a file instead of returned via the API. + +## PAN-149912 + +Fixed an issue where FIB entries were unexpectedly removed due to miscommunication between internal processes. + +## PAN-149696 + +Fixed an intermittent issue where the GlobalProtect portal stopped responding with a 502 Bad Gateway response page when trying to access the portal URL using a web browser. + +## PAN-149295 + +Fixed an issue where the Safe Search Block Page was visible for a few seconds when browsing HTTP2 websites, which resulted in latency when browsing. + +## PAN-149248 + +Fixed an issue that prevented Panorama from pushing dynamic content to VM-Series firewalls configured with a pay-as-you-go (PAYG) license. + +## PAN-149217 + +Fixed an issue where overridden TCP timeout values for service-based sessions did not take effect, and sessions timed out according to default application values. + +## PAN-149054 + +Fixed an issue in Panorama where a commit-all to managed firewalls failed after renaming a device group. + +## PAN-149006 + +Fixed an issue on VM-Series firewalls deployed on Google Cloud Platform (GCP) where traffic was backhauled after a reboot when the policy-based forwarding (PBF) enforced symmetric return with a next hop feature was enabled and interface IP addresses were learned via DHCP. + +## PAN-149001 + +Fixed an issue where, when using certificate profiles configured under specific virtual systems (vsys), the GlobalProtect **Machine Certification Check** and **HIP Object** fail during a client certificate check. + +## PAN-148441 + +Fixed an issue where required processes were not automatically restarted on the Log Processing Card (LPC) or the Log Forwarding Card (LFC). + +## PAN-147847 + +Fixed an issue where traffic didn't hit the intended Security policy if SSL forward proxy was enabled and service was set to **application-default**. + +## PAN-147796 + +Fixed an issue on the firewalls with an IPsec/Encapuslating Security Payload (ESP) traffic with GlobalProtect gateway configuration where multiple processes (flow_ctrl, pktlog_forwarding, and all_task) restarted, which caused the device to reboot. + +## PAN-147529 + +Fixed an issue where **ValidateAll** jobs were incorrectly logged as **CommitAll** in the configuration log of the firewall. + +## PAN-147305 + +Fixed an issue where a process (useridd) stopped responding to requests. + +## PAN-147298 + +```caveat +PA-7050 and PA-7080 firewalls with 100G NPC only +``` + +Fixed an issue where jumbo frames brought down the Network Processing Card (NPC) when traffic traversed the firewall at a high rate. + +## PAN-147130 + +Fixed an issue where user-to-IP address mapping that was redistributed between virtual systems (vsys) was not removed when the XML API unique identifier (UID) payload was set to timeout=Never. + +## PAN-147036 + +Fixed an issue where TCP connections got stuck between the firewall and the Log Collector if some packets were dropped on the path between the two appliances. + +## PAN-146763 + +Fixed a configuration issue on a multi-vsys where the configured interface service route for email schedule reports was not being used. + +## PAN-146215 + +```caveat +FPP offload based hardware model only +``` + +Fixed an issue where, when UDP traffic that was received on a tunnel had back-to-back client-to-server packets, random packets dropped. + +## PAN-145996 + +An update was made to change the following system log message: DO NOT CHOOSE WMI in Active-Directory FOR YOUR USE CASE IF SEE THIS LOG AGAIN IN SECONDS to Please change server monitor(log server) Transport Protocol from WMI to WinRM for better performance. This update also reduces the severity from **High** to **Informational**. + +## PAN-145524 + +Fixed an issue where **ACC > GlobalProtect Activity** on Panorama in management only mode with a dedicated log collector did not display any reports. + +## PAN-145475 + +Fixed an issue where the firewall sent Bidirectional Forwarding Detection (BFD) packets with the final bit always set to on. With this fix, the final bit is cleared after the first response. + +## PAN-145385 + +Fixed a rare issue where HTTP/2 sessions matched to an incorrect policy. + +## PAN-145188 + +Fixed an issue on Panorama in PAN-DB mode where content updates did not successfully install, which caused the cloud state to degrade. + +## PAN-144723 + +A new CLI command, debug proxy fast-session-delete enable yes, was added to better handle SSL-decrypted sessions where TCP port numbers were reused before the TIME_WAIT period expired. + +## PAN-144410 + +Debug logs were added to detect an out-of-memory (OOM) condition that caused the management server to restart. + +## PAN-143332 + +```caveat +PA-800 Series firewalls only +``` + +Fixed an issue where the deployment of the Master Key through the web interface failed. + +## PAN-142867 + +Fixed an issue where service session timeout override was not used for custom applications and the default value was chosen instead. + +## PAN-140492 + +Fixed an issue on the firewall where, with SSL forward proxy feature enabled, random file downloads over a decrypted session would stall or hang in the middle. + +## PAN-139007 + +Fixed an issue where **URL Filtering** logs were misaligned when exported from the firewall due to the presence of a comma in the **User-Agent** field of the logs. + +## PAN-138995 + +Fixed an issue where even after disabling **Tasks** in the web interface of an **Admin Role Profile**, the **Task Manager** panel appeared during a commit. + +## PAN-138926 + +Fixed an issue where an improperly formatted GlobalProtect Portal from the CLI was able to be created, which prevented it from being seeing in the web interface. + +## PAN-138573 + +Fixed an issue where the keyword **[Disabled]** was missing from the disabled policies exported in CSV/PDF format. + +## PAN-137741 + +Fixed an issue where the data for a botnet report was deleted before the botnet report was completed. + +## PAN-137671 + +Fixed an issue where testing and confirming server connections from **Panorama > Server profiles > HTTP > Test Server Connection** did not work. + +## PAN-136652 + +```caveat +PA-3200 Series and PA-800 Series firewalls only +``` + +Fixed an issue where you were unable to disable auto negotiation on small form-factor pluggable (SFP) ports. + +## PAN-135228 + +Fixed an issue where **Destination_Interface** (**Templates > Network > QoS > QoS Interface > Clear Text Traffic**) was not available when configuring QoS using the Panorama web interface. + +## PAN-134909 + +Fixed an issue where region information was not called due to a mismatch in uppercase and lowercase letters in the region name. + +## PAN-134840 + +Fixed an issue where pre-logon users failed authentication if the cookie was expired, instead of using certificate authentication. + +## PAN-134467 + +Fixed an issue with the GlobalProtect portal where pre-logon authentication failed when agent Config Selection Critiera was configured on the firewall. + +## PAN-134251 + +```caveat +PA-7000 Series firewalls only +``` + +Fixed an issue where unplugging cables from Quad Small Form-factor Pluggable (QSFP) interfaces on 100G NPC causes path monitoring failures. + +## PAN-133774 + +Fixed an issue where the **Logging Services Status** was incorrect. This was caused by the namespace of the daemons that were running not being updated correctly. + +## PAN-133388 + +Fixed an issue where an HA configuration went out of sync when the HA sync job was queued and processed during an ongoing content installation job on the passive firewall. + +## PAN-132055 + +Fixed an issue where a process (mgmtsrvr) was unresponsive when the number of active file descriptors was greater than 1024. + +## PAN-132053 + +Added an enhancement to improve handling for firewall management web interface sessions that timeout so that the message Your session has expired does not display. Now, the web interface will present a timeout page that presents a button to redirect back to the login page. + +## PAN-121484 + +Fixed an issue where the dataplane sent positive acknowledgments to predict-status checks from FPP when the corresponding predict was deleted, which caused SIP and RTSP applications to perform less than the expected achievable performance. + +## PAN-110511 + +Fixed an issue where a passive Panorama appliance reported that device groups were out of sync despite a successful HA sync from the active Panorama appliance. This issue occurred when the address objects defined in the device group were in use under the corresponding template. + +## PAN-109877 + +Fixed an issue where BGP flapped continuously with Jumbo Frames enabled on the firewall. diff --git a/web/data/issues/PAN-OS/addressed/9.1.8_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.8_2026-03-31.md new file mode 100644 index 0000000..03f2827 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.8_2026-03-31.md @@ -0,0 +1,337 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.8 +--- + +## PAN-161121 + +Fixed an issue on the Panorama management server that caused invalid reference errors when attempting to delete an address object (**Objects > Addresses**) after removing the address object reference from an address group (**Objects > Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls. + +## PAN-160376 + +Fixed an issue where, for local administrators using an authentication profile, the **save filter** (**Monitor > Logs**) option was grayed out. + +## PAN-158650 + +Fixed an issue where several operations and processes stopped responding due to a deadlock issue between the CLI thread and the Terminal Server (TS) agent message processing the thread. + +## PAN-158638 + +Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg. + +## PAN-158293 + +Fixed an issue where a sudden increase in packet buffer descriptors disrupted traffic. + +## PAN-158122 + +Fixed an issue where SNMP readings reported 0 for dataplane interface packet statistics when using PacketMMAP mode. This issue occurred because the physical port counters read from MAC addresses were reported as 0. + +## PAN-157786 + +Fixed an issue where the **Device > Setup** page was blank after downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release. + +## PAN-157319 + +```caveat +PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only +``` + +Fixed an issue where GlobalProtect logs showed the incorrect client version and did not show event ID information. + +## PAN-157168 + +Fixed an issue where a process (mprelay) stopped responding when displaying debug PDT commands + +## PAN-157049 + +```caveat +PA-3200 Series firewalls only +``` + +Fixed an issue where the firewall processed internal path monitoring packets more slowly than expected when processing large amounts of traffic, which caused the dataplane to restart. + +## PAN-156891 + +Fixed an issue where some zip files did not download and the following error message displayed: resources-unavailable. + +## PAN-156716 + +Fixed an issue where the firewall sent ARP replies without checking the ingress interface when the requested IP address was configured as a destination NAT (DNAT) address. + +## PAN-155665 + +Fixed an issue where, if an authentication profile was configured with an authorization type of **none**, users were inappropriately prompted for a password. Since the authentication type was set to **none**, any input was successful. This issue occurred when **Allow Authentication with User Credentials OR Client Certificate** was set to **no**. + +## PAN-155326 + +Fixed an issue where the BGP **AS Number** template variable was not referenceable from the web interface. + +## PAN-155294 + +Fixed an issue where iPad devices did not display Captive Portal multi-factor authentication (MFA) pages correctly when using Okta for push notifications. + +## PAN-155124 + +Fixed an issue where IP address-to-username mapping did not correctly sync to the secondary active firewall in an active/active HA configuration if a logout and a log in event occurred within the same second. + +## PAN-154899 + +Fixed an out-of-memory (OOM) issue on the firewalls that caused LACP, BGP, and OSPF to go down, resulting in the firewall not receiving LACPDU messages. + +## PAN-154844 + +Fixed an issue where commits and autocommits repeatedly failed due to an OOM condition that disrupted the processes pan_task and devsrvr. + +## PAN-154812 + +Fixed a memory leak issue related to a process (configd) that was caused by log queries filtering by address. + +## PAN-154591 + +Fixed an issue where NULL users in panGlobalProtectGetConfig were not checked for before calling strcmp(). + +## PAN-154391 + +Fixed an issue where a Log Collector did not forward correlation logs to the syslog server over TCP. + +## PAN-154365 + +Fixed an issue where Security policy rules targeted by tags incorrectly displayed as deleted when previewing commit changes. + +## PAN-153814 + +Fixed an issue where the firewall displayed the URL Filtering Safe Search Block Page on the specific site only, even when the traffic was matched to a specific rule that did not have any URL filtering policies. + +## PAN-153705 + +Fixed an issue where packets were not evenly distributed among a process (pan_tasks), which caused latency and poor performance. + +## PAN-153631 + +Fixed an issue where the firewalls did not generate traffic logs for implicitly allowed applications. + +## PAN-153614 + +Fixed an issue where user-based policies did not correctly match if the same user was included in both a policy with the username in NetBIOS format and another policy with the username in FQDN format. + +## PAN-153294 + +Fixed an issue on the firewall where a GlobalProtect username authenticated via Kerberos was unnecessarily normalized to SAMAccountName format. + +## PAN-153261 + +Fixed an issue where not all fragmented packets were transmitted, which caused increased packet buffer usage. + +## PAN-152998 + +Fixed an issue where the User-ID process CPU usage remained high when a large number of Terminal Server (TS) agents were configured but only a few were connected. + +## PAN-152813 + +Fixed an issue with configuration memory leaks on Panorama that caused a process (configd) to restart. + +## PAN-152677 + +```caveat +VM-Series firewalls on Azure only +``` + +Fixed an issue where packet buffers showed high values when Data Plane Development Kit (DPDK) was enabled. + +## PAN-152648 + +Fixed an issue where multiple all_pktproc processes stopped responding, which caused the dataplane to restart. + +## PAN-152103 + +Fixed a memory leak issue where a process (dnsproxy) did not properly release memory after use. + +## PAN-151997 + +Fixed an issue where the option to sinkhole was not displayed in the ACC filter drop-down (**ACC > Threat Activity > Global filters > Action**). + +## PAN-151888 + +Fixed an issue where remote users were able to save log filters, which created a local user with the same username. With this fix, remote users cannot save a log filter. + +## PAN-151808 + +Fixed an issue where an EDL refresh job did not complete when the configuration for EDL servers used certificate profiles, due to the large server certificates. + +## PAN-151803 + +Fixed an issue on Panorama where commits failed when using device-id as a template variable. + +## PAN-151503 + +Fixed an intermittent issue where memory was not fully freed after a Panorama commitAll completion on the firewall. + +## PAN-151218 + +```caveat +PA-3200 Series firewalls only +``` + +Fixed an issue where the crashinfo file was not generated after a process (all_pktproc) stopped responding on the dataplane before path monitoring triggered a device reboot. + +## PAN-150867 + +An enhancement was made to enable additional logging during kernel panic/oops that helps identify the cause. + +## PAN-150798 + +```caveat +PA-7000 Series firewalls only +``` + +Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot. + +## PAN-150534 + +Fixed an issue where authentication logs with the subtype SAML were not forwarded to the syslog server. + +## PAN-150467 + +Fixed a memory leak issue with a unified query that caused a process (mprelay) to restart due to an OOM condition. + +## PAN-150085 + +Fixed an issue where a process (configd) stopped responding which caused context switches to slow. + +## PAN-150008 + +Fixed an issue on the firewall where configuring auto-tagging based on URL filtering logs resulted in tags being added to source IP addresses and not matching the log forwarding filter match criteria. + +## PAN-149283 + +Fixed an issue where editing device log forwarding in the collector group then filtering specific firewalls and adding new firewalls caused the old firewalls to disappear from the log forwarding preferences list. + +## PAN-148800 + +Fixed an issue where the firewall used port 1080 to reach dns.service.paloaltonetworks.com when web-proxy was configured. + +## PAN-148549 + +Fixed an issue where newly created interface management profiles were unable to be linked to subinterfaces. + +## PAN-148359 + +Fixed an issue where SD-WAN server-to-client symmetric return did not function correctly in certain circumstances. This issue intermittently affected path selection of parent/child applications, such as FTP. + +## PAN-147254 + +jQuery was updated to 3.5.1. + +## PAN-147221 + +Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints + +## PAN-145733 + +Fixed an issue where the SNMP INDEX for panZoneTable on the PAN-COMMON-MIB.my file did not work as expected, which led to entries in panZoneTable not being uniquely identified. + +## PAN-145417 + +Debug commands were added to address an issue where the firewall connect to Cortex Data Lake due to the Online Certificate Status Protocol (OSCP) message missing the nextUpdate value in the OSCP response. + +## PAN-144975 + +Fixed an intermittent issue where a high traffic load in a Layer 2 deployment caused SNMP and Panorama health monitoring failures. + +## PAN-144887 + +```caveat +Panorama virtual appliances in high availability (HA) configurations with VMware NSX plugin only +``` + +Fixed an issue where dynamic address group updates and configuration pushes failed when new plugins were installed or uninstalled, or when a process (configd) was restarted or reinitialized. + +## PAN-144594 + +Fixed an issue where web pages failed to launch over clientless VPN when cookies had the expiry value set to 0 in the packet. + +## PAN-143485 + +Fixed a memory leak issue related to a process (devsrvr). + +## PAN-141813 + +Fixed an issue where multiple daemons restarted due to a management plane ARP overflow. + +## PAN-140093 + +```caveat +PA-220 firewalls only +``` + +Fixed an issue where the master key was unable to be changed. + +## PAN-137205 + +Fixed an issue where **Review Policies** did not show all related policies. + +## PAN-136478 + +```caveat +PA-7000 Series firewalls +``` + +where syslog forwarding over TCP did not work in a multi-vsys environment. + +## PAN-136073 + +Fixed an issue where the High Speed Chassis Interconnect (HSCI) port flapped continuously after an upgrade or reboot. + +## PAN-134461 + +Fixed an issue where an admin user authenticated to Panorama with RADIUS and assigned a Device Group and Template Admin role using access domains was unable to add a managed firewall to Panorama and received the following error message: Import failed user does not exist. + +## PAN-133886 + +Fixed an issue where GlobalProtect users were unable to connect to mobile gateways when download of a large CRL failed due to timeouts that resulted in CRL check failures. + +## PAN-133863 + +Fixed an issue where the Panorama Virtual Appliance in Log Collector mode went into maintenance mode due to a process (reportd) not responding. + +## PAN-132035 + +Fixed an issue on Panorama appliances in an active/passive high availability configuration where a managed firewall generated high priority alerts that it failed to connect to the passive Panorama appliance's User-ID agent server. This issue occurred because the firewall was only able to connect to one Panorama User-ID server at a time, and it connected only to the active Panorama appliance's User-ID server. + +## PAN-131462 + +Fixed an issue where the title page of PDF reports did not show the entire Palo Alto Networks logo. + +## PAN-129927 + +```caveat +VM-Series firewalls only +``` + +Fixed an issue where firewalls with Layer 3 subinterfaces reset Class of Service (CoS) bits in 802.1q. + +## PAN-120013 + +Fixed an issue where secure communication settings were incorrectly synchronized between Panorama appliances in an HA configuration. + +## PAN-115494 + +Fixed an issue where the /opt/pancfg/ partition became full due to a configuration preview operation not responding. + +## PAN-114351 + +Fixed an issue where SSL decryption slowed traffic with the TCP timestamp option enabled. + +## PAN-113386 + +Fixed an issue where an address object with a tag that contained a space character inside quotation marks was not properly processed and assigned to the appropriate Dynamic Address Group. + +## PAN-110962 + +Fixed an issue where a process (*all_pktproc*) stopped responding when SSH decryption was enabled, which caused the dataplane to restart. + +## PAN-100693 + +Fixed an issue where you were unable to process Address Group match criteria when the match name included the double quotation ( " ) character. diff --git a/web/data/issues/PAN-OS/addressed/9.1.9_2026-03-31.md b/web/data/issues/PAN-OS/addressed/9.1.9_2026-03-31.md new file mode 100644 index 0000000..f015df8 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/9.1.9_2026-03-31.md @@ -0,0 +1,252 @@ +--- +type: Addressed +product: PAN-OS +version: 9.1.9 +--- + +## PAN-165194 + +Fixed an issue where multiple messages were exchanged between secondary and primary Data Plane Development Kit (DPDK) processes, which caused a process (brdagent) to stop responding. + +## PAN-164564 + +Fixed an issue where stats API attempted to get stats from an unavailable port. + +## PAN-163538 + +Fixed an issue on multi-dataplane platforms where traffic through Large Scale VPN (LSVPN) tunnels dropped with the error message tunnel resolution failure. + +## PAN-163164 + +Fixed an issue where the GlobalProtect client used IPv6 during gateway login but used IPv4 during IPsec tunnel creation, which caused it to fallback to SSL. + +## PAN-162746 + +Fixed an issue where DNS over TCP caused a process (dnsproxy) to run out of memory. + +## PAN-161745 + +Fixed an issue where the time-to-live (TTL) value received from the DNS server reset to 0 on DNS secure TCP transactions when anti-spyware profiles were used, which caused DNS dynamic updates to fail. + +## PAN-160782 + +Fixed an issue where the routed process stopped responding when the BGP peer sent AS_PATHs with more than 255 AS numbers in all of the segments combined. There can now be a maximum of 255 AS numbers in an AS_PATH list for a prefix. + +## PAN-160744 + +Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found. + +## PAN-160455 + +Certain invalid URL entries contained in an External Dynamic List (EDL) cause a process (devsrvr) to stop responding ([CVE-2021-3048](https://security.paloaltonetworks.com/CVE-2021-3048)). + +## PAN-160434 + +Fixed an issue where firewalls stopped processing Layer-3-tagged traffic after Panorama pushed VLAN sub-interface configurations to the firewall with the **commit_all** operation. + +## PAN-159944 + +Fixed an issue where a process (dnsproxyd) stopped responding due to an error in the DNS cache operation. + +## PAN-159826 + +Fixed an issue where SSL VPN leaked when the default browser feature on GlobalProtect was not enabled. + +## PAN-159135 + +Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above. + +## PAN-158988 + +Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented. + +## PAN-158844 + +Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh. + +## PAN-158774 + +Fixed an issue where random DNS queries dropped with the counter ctd_dns_wait_pkt_drop when DNS security was enabled. + +## PAN-158723 + +A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)). + +## PAN-158328 + +Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups. + +## PAN-158262 + +A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code. + +A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)). + +## PAN-158036 + +Fixed an issue on the firewall where custom application signatures based on PROPFIND http-method didn't trigger if webdav application ID was blocked by a Security policy. + +To utilize this fix, you must install content version 8367-6513 or later. + +## PAN-157735 + +Fixed an issue where the new PA-7000100G network processing card (NPC) took 25 minutes to start after rebooting the PA-7080 chassis. + +## PAN-157721 + +Fixed an issue where the firewall dropped GPRS tunneling protocol (GTPv2) Create Session Requests and Responses that had IEs 201 and 202 with the error Abnormal GTPv2-C message with invalid IE. + +## PAN-157346 + +Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal > Agent > HIP Data Collection**). + +## PAN-157271 + +Fixed an issue where **Panorama > Cloud Services** was visible to users with device group and template admin roles even if the admin role was disabled. + +## PAN-156896 + +```caveat +VM-Series firewalls only +``` + +Fixed an issue where the firewall frequently stopped responding with the following log: CONFIG_UPDATE_INC : Incremental update to DP failed please try to commit force the latest config. + +## PAN-156264 + +Fixed an issue where the firewall displayed **IP address** **Netmask** and **default gateway** as **unknown** on the web interface as well as the CLI. + +## PAN-156225 + +```caveat +PA-3200 Series firewalls only +``` + +Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to later 9.1 releases and from PAN-OS 10.0.0 to PAN-OS 10.0.4. + +## PAN-155656 + +Fixed an issue where multicast RTP traffic triggered unicast RTP Control Protocol (RTCP), and the predict session failed to install, which blocked the parent RTP session from forwarding packets. + +## PAN-155147 + +```caveat +VM-Series firewalls on Microsoft Azure that use accelerated networking interfaces with DPDK mode +``` + +Fixed an issue where hot plug notifications caused traffic disruption. + +## PAN-154557 + +Fixed an issue that caused a process (useridd) core dump when parsing the Subject Alternative Name from a client certificate sent in the HIP report. + +## PAN-154403 + +Fixed an issue with HIP matching logic for missing patches where previous behavior indicated missing patches when no patches were missing. + +## PAN-154376 + +Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled. + +## PAN-154195 + +Fixed an issue where the firewall dropped VoIP traffic over IPSec with counters flow_predict_convert_rtp_drop and flow_predict_convert_failed. + +## PAN-153316 + +CLI commands were added to address an issue where virtual memory on a process (configd) exceeded the new 32G limit. + +- To disable the virtual memory limit, use debug software disable-virt-limit. +- To enable the virtual memory limit, use debug software enable-virt-limit. + +## PAN-153286 + +Fixed an issue on Panorama deployed on Amazon Web Services (AWS) where the Log Collector disk was on Admin disabled state when changing the instance type from m4 to m5. + +## PAN-153213 + +Fixed a rare issue where TCP packets randomly dropped due to reassembly failure. + +## PAN-152497 + +Fixed an issue where the firewall was unable to create a new GTP-U session when it received Create Session Response messages, which caused the following error message to display in the GTP log: GTPv1 message failed stateful inspection. + +## PAN-152458 + +```caveat +VM-Series firewalls on Microsoft Hyper-V only +``` + +Fixed an issue where, when upgrading to PAN-OS 9.0.8 or later, ethernet packets dropped after adding VLAN tags during egress from a subinterface. To leverage this fix, set the interface level maximum transmission unit (MTU) to 1496 or less. + +## PAN-152003 + +Fixed an issue where an email client was unable to open an attached file due to removal of part of the file name encoded in UTF-8 by the firewall CTD function for SMTP and NAT sessions. + +## PAN-151395 + +Fixed an issue where the firewall repeatedly logged connection failures to a configured Log Collector. + +## PAN-150298 + +Fixed an issue where Android clients matched HIP objects configured for Apple products. + +## PAN-150097 + +Fixed an issue where hourly URL summary log generation failed. + +## PAN-150023 + +A fix was made to address an improper authentication vulnerability in PAN-OS that enabled a SAML authenticated attacker to impersonate any other user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)). + +## PAN-149501 + +A fix was made to address a memory corruption vulnerability in the GlobalProtect Clientless VPN that enabled an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication ([CVE-2021-3056](https://security.paloaltonetworks.com/CVE-2021-3056)). + +## PAN-147792 + +Fixed an issue where a process (configd) stopped responding due to a buffer overflow. + +## PAN-147783 + +Checks were added to help prevent the dataplane from restarting. + +## PAN-144538 + +Fixed an issue where locally disabling the rule hit-count feature on Panorama caused a memory leak. + +## PAN-144470 + +Fixed an issue where driver descriptor rings were out of sync in the control plane to dataplane direction, which caused internal path monitoring heartbeat failures. + +## PAN-142818 + +Fixed an issue where the management server restarted due to a telemetry buffer overflow that occurred when generated threat logs had specific signature flags set. + +## PAN-142621 + +Fixed an issue where the firewall was unable to log debug information in case of kernel panic. + +## PAN-142473 + +Fixed an issue where a commit failed with the following error message: Disk quotas add up to more than 100%. Invalid configuration. due to an integration issue. + +## PAN-136347 + +Fixed an issue wherer DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding. + +## PAN-134799 + +Fixed an issue where packets of the same session were forwarded through a different member of an Aggregate Ethernet (AE) group once the session was offloaded. + +## PAN-120423 + +Support was added for XML API for GlobalProtect logs. + +## PAN-113795 + +Fixed an issue on a firewall configured with GlobalProtect Clientless VPN where a process (*all_pkts*) stopped responding, which caused the dataplane to restart. + +## PAN-110429 + +Fixed an issue with firewalls in a high availability configuration where multiple all_pktproc processes stopped responding due to missing heartbeats, which caused service outages. diff --git a/web/data/issues/PAN-OS/known/9.1.13_2026-03-31.md b/web/data/issues/PAN-OS/known/9.1.13_2026-03-31.md new file mode 100644 index 0000000..37d54c9 --- /dev/null +++ b/web/data/issues/PAN-OS/known/9.1.13_2026-03-31.md @@ -0,0 +1,498 @@ +--- +type: Known +product: PAN-OS +version: 9.1.13 +--- + +## BLANK-000000 + +Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process. + +## BLANK-000000 + +A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available. + +- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.` +- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50. + The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM- license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model. + +## PLUG-380 + +When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls. + +## PAN-223365 + +The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded. + +**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot. + +`admin``request restart system` + +Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector. + +## PAN-221015 + +On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded. + +**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes. + +`admin>``debug elasticsearch es-restart optional all` + +Code copied to clipboard + +Unable to copy due to lack of browser support. + +Copy + +## PAN-199557 + +On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive. + +**Workaround:** Manually reboot the `Active` Panorama HA peer. + +## PAN-197341 + +On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule. + +For example: + +1. You create a parent device group `DG-A` and a child device group `DG-B`. +2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`. +3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`. + +Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object. + +## PAN-186937 + +```caveat +This issue is now resolved. See PAN-OS 9.1.14 Addressed Issues. +``` + +The firewall drops Encapsulating Security Payload (ESP) IPsec packets that originate from the same firewall. This behavior occurs when you enable **Strict IP Address Check** in the Zone Protection profile (Packet Based Attack Protection tab, IP Drop section) and the packet’s source IP address is the same as the egress interface address. + +**Workaround**: Disable the **Strict IP Address Check** option in the Zone Protection profile. Alternatively, downgrade to 9.1.11 or earlier or upgrade to 10.0.0 or later if you want to enable the **Strict IP Address Check**. + +## PAN-178194 + +Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering. + +## PAN-154266 + +When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used. + +**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies. + +## PAN-154247 + +On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out. + +**Workaround:** Log out and back in to the Panorama web interface. + +## PAN-153803 + +On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer. + +## PAN-146573 + +PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries. + +## PAN-146485 + +On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`. + +Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`. + +**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration. + +## PAN-144889 + +```caveat +PAN-OS 9.1.2-h1 and later releases only +``` + +On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`. + +**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**). + +## PAN-140959 + +The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported. + +## PAN-134456 + +SNMP traps configured to use the dataplane port in service routes are still sent using the management interface. + +**Workaround:** Use a destination-based service route for the SNMP trap server. + +## PAN-134053 + +ACC does not filter WildFire logs from Dynamic User Groups. + +## PAN-130550 + +```caveat +PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls +``` + +For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation. + +**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic. + +## PAN-127813 + +In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub. + +**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration. + +## PAN-127550 + +Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI. + +## PAN-127474 + +When you configure a Server Profile, the custom log format for GlobalProtect logs is missing. + +## PAN-127206 + +If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out. + +## PAN-123277 + +Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface. + +## PAN-123040 + +When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround. + +## PAN-120440 + +There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`. + +## PAN-120303 + +There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface. + +**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below. + +- Modify the PAN-DB Server IP address on the managed firewall. + 1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings). + 2. **Commit** your changes. + 3. Add the new M-500 Eth1/1 IP PAN-DB IP address. + 4. **Commit** your changes. +- Restart the firewall (devsrvr) process. + 1. Log in to the firewall CLI. + 2. Restart the devsrvr process: `debug software restart process device-server` + +## PAN-118065 + +```caveat +M-Series Panorama management servers in Management Only mode +``` + +When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit. + +**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change. + +## PAN-116017 + +```caveat +Google Cloud Platform (GCP) only +``` + +The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall. + +**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process. + +## PAN-115816 + +```caveat +Microsoft Azure only +``` + +There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall. + +**Workaround:** Reboot the firewall. + +## PAN-114495 + +Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets. + +Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode. + +## PAN-112694 + +```caveat +Firewalls with multiple virtual systems only +``` + +If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one. + +## PAN-112456 + +You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter. + +## PAN-111928 + +Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration. + +**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors. + +## PAN-111866 + +The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes. + +**Workaround:** Perform one of the following tasks. + +- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations. +- Manually select the devices that belong to the modified device group and template configurations. + +## PAN-111729 + +If you disable DPDK mode and enable it again, you must immediately reboot the firewall. + +## PAN-111670 + +Tagged VLAN traffic fails when sent through an SR-IOV adapter. + +## PAN-111251 + +Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect. + +## PAN-110794 + +DGA-based threats shown in the firewall threat log display the same name for all such instances. + +## PAN-109759 + +The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match. + +## PAN-109526 + +The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters. + +## PAN-106675 + +After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers. + +**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports. + +## PAN-104780 + +If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints. + +Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report. + +## PAN-103276 + +Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive. + +**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again. + +## PAN-101688 + +```caveat +Panorama plugins +``` + +The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group. + +**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`. + +## PAN-101537 + +After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log direction equal | in ` command on a managed firewall only returns address and address group objects pushed form the Shared device group. + +**Workaround:** Specify the vsys in the query string: + +`admin>` `set system target-vsys ` + +`admin>` `show log direction equal query equal ‘vsys eq | in ` + +## PAN-98520 + +When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored. + +## PAN-97757 + +GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect. + +**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP. + +## PAN-97524 + +```caveat +Panorama management server only +``` + +The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch. + +## PAN-96985 + +The `request shutdown system` command does not shut down the Panorama management server. + +## PAN-96960 + +You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI. + +## PAN-96446 + +A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode. + +## PAN-95773 + +On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate. + +**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command. + +## PAN-95511 + +The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule. + +## PAN-95028 + +For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.) + +## PAN-94846 + +When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state. + +## PAN-94093 + +HTTP Header Insertion does not work when jumbo frames are received out of order. + +## PAN-93968 + +The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature. + +## PAN-93607 + +When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles. + +**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there. + +## PAN-93532 + +When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**). + +## PAN-93193 + +The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not: + +- Switch to the firewall **Context** on the Panorama management server. +- Commit changes when a dynamic update is being installed. +- Generate a custom report when a dynamic update is being installed. +- Generate custom reports during a commit. + +**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall. + +Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall. + +## PAN-91802 + +On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions. + +## PAN-83610 + +In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets. + +**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command. + +## PAN-83236 + +The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**). + +**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides. + +## PAN-83215 + +SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM). + +## PAN-81521 + +Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**). + +**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile. + +## PAN-77125 + +PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out. + +**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command. + +## PAN-75457 + +```caveat +PAN-OS 8.0.1 and later releases +``` + +In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive. + +## PAN-73530 + +The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files. + +## PAN-73401 + +```caveat +PAN-OS 8.0.1 and later releases +``` + +When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist: + +- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.) +- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes). + +**Workaround:** There are three possible workarounds to sync the controller nodes: + +- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync. +- Configure a worker list on the cluster controller: + admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list ` + (`` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround. +- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled. + admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes` + or + admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no` + Both commands result in Panorama reporting that the controller nodes are in sync. + +## PAN-71329 + +Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **** > **Clientless VPN** > **Applications**). + +**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications. + +## PAN-70906 + +If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface. + +**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal. + +## PAN-69505 + +When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**). + +## PAN-41558 + +When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan. + +**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic. + +## PAN-40079 + +The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality. + +## PAN-39636 + +Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**. + +**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report. + +## PAN-38255 + +When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command. + +## PAN-31832 + +The following issues apply when configuring a firewall to use a hardware security module (HSM): + +- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay. +- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds. diff --git a/web/data/issues/PAN-OS/known/9.1.14_2026-03-31.md b/web/data/issues/PAN-OS/known/9.1.14_2026-03-31.md new file mode 100644 index 0000000..1809b65 --- /dev/null +++ b/web/data/issues/PAN-OS/known/9.1.14_2026-03-31.md @@ -0,0 +1,512 @@ +--- +type: Known +product: PAN-OS +version: 9.1.14 +--- + +## BLANK-000000 + +Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process. + +## BLANK-000000 + +A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available. + +- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.` +- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50. + The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM- license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model. + +## PLUG-380 + +When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls. + +## PAN-223365 + +The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded. + +**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot. + +`admin``request restart system` + +Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector. + +## PAN-221015 + +On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded. + +**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes. + +`admin>``debug elasticsearch es-restart optional all` + +Code copied to clipboard + +Unable to copy due to lack of browser support. + +Copy + +## PAN-199557 + +On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive. + +**Workaround:** Manually reboot the `Active` Panorama HA peer. + +## PAN-197919 + +```caveat +This issue is now resolved. See PAN-OS 9.1.16 Addressed Issues. +``` + +When path monitoring for a static route is configured with a new Ping Interval value, that value does not get used as intended. + +**Workaround**: Disable and re-enable path monitoring for that static route to change that Ping Interval value. + +## PAN-197859 + +On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap. + +## PAN-197341 + +On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule. + +For example: + +1. You create a parent device group `DG-A` and a child device group `DG-B`. +2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`. +3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`. + +Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object. + +## PAN-194395 + +```caveat +This issue is now resolved. See PAN-OS 9.1.14-h1 Addressed Issues. +``` + +The firewall drops all decrypted outbound (SSL Forward Proxy) HTTP/2 traffic after you upgrade to PAN-OS 9.1.14. Dropping this traffic prevents users from loading HTTP/2 web pages and accessing websites that use HTTP/2. + +**Workaround**: On the SSL Forward Proxy tab in the Decryption profile attached to the Decryption Policy rule that controls the HTTP/2 traffic, select **Strip ALPN**. When you **Strip ALPN**, the firewall negotiates HTTP/1.1 instead of HTTP/2. + +## PAN-178194 + +Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering. + +## PAN-154266 + +When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used. + +**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies. + +## PAN-154247 + +On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out. + +**Workaround:** Log out and back in to the Panorama web interface. + +## PAN-153803 + +On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer. + +## PAN-146573 + +PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries. + +## PAN-146485 + +On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`. + +Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`. + +**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration. + +## PAN-144889 + +```caveat +PAN-OS 9.1.2-h1 and later releases only +``` + +On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`. + +**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**). + +## PAN-140959 + +The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported. + +## PAN-134456 + +SNMP traps configured to use the dataplane port in service routes are still sent using the management interface. + +**Workaround:** Use a destination-based service route for the SNMP trap server. + +## PAN-134053 + +ACC does not filter WildFire logs from Dynamic User Groups. + +## PAN-130550 + +```caveat +PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls +``` + +For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation. + +**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic. + +## PAN-127813 + +In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub. + +**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration. + +## PAN-127550 + +Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI. + +## PAN-127474 + +When you configure a Server Profile, the custom log format for GlobalProtect logs is missing. + +## PAN-127206 + +If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out. + +## PAN-123277 + +Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface. + +## PAN-123040 + +When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround. + +## PAN-120440 + +There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`. + +## PAN-120303 + +There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface. + +**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below. + +- Modify the PAN-DB Server IP address on the managed firewall. + 1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings). + 2. **Commit** your changes. + 3. Add the new M-500 Eth1/1 IP PAN-DB IP address. + 4. **Commit** your changes. +- Restart the firewall (devsrvr) process. + 1. Log in to the firewall CLI. + 2. Restart the devsrvr process: `debug software restart process device-server` + +## PAN-118065 + +```caveat +M-Series Panorama management servers in Management Only mode +``` + +When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit. + +**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change. + +## PAN-116017 + +```caveat +Google Cloud Platform (GCP) only +``` + +The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall. + +**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process. + +## PAN-115816 + +```caveat +Microsoft Azure only +``` + +There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall. + +**Workaround:** Reboot the firewall. + +## PAN-114495 + +Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets. + +Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode. + +## PAN-112694 + +```caveat +Firewalls with multiple virtual systems only +``` + +If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one. + +## PAN-112456 + +You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter. + +## PAN-111928 + +Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration. + +**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors. + +## PAN-111866 + +The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes. + +**Workaround:** Perform one of the following tasks. + +- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations. +- Manually select the devices that belong to the modified device group and template configurations. + +## PAN-111729 + +If you disable DPDK mode and enable it again, you must immediately reboot the firewall. + +## PAN-111670 + +Tagged VLAN traffic fails when sent through an SR-IOV adapter. + +## PAN-111251 + +Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect. + +## PAN-110794 + +DGA-based threats shown in the firewall threat log display the same name for all such instances. + +## PAN-109759 + +The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match. + +## PAN-109526 + +The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters. + +## PAN-106675 + +After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers. + +**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports. + +## PAN-104780 + +If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints. + +Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report. + +## PAN-103276 + +Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive. + +**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again. + +## PAN-101688 + +```caveat +Panorama plugins +``` + +The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group. + +**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`. + +## PAN-101537 + +After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log direction equal | in ` command on a managed firewall only returns address and address group objects pushed form the Shared device group. + +**Workaround:** Specify the vsys in the query string: + +`admin>` `set system target-vsys ` + +`admin>` `show log direction equal query equal ‘vsys eq | in ` + +## PAN-98520 + +When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored. + +## PAN-97757 + +GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect. + +**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP. + +## PAN-97524 + +```caveat +Panorama management server only +``` + +The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch. + +## PAN-96985 + +The `request shutdown system` command does not shut down the Panorama management server. + +## PAN-96960 + +You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI. + +## PAN-96446 + +A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode. + +## PAN-95773 + +On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate. + +**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command. + +## PAN-95511 + +The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule. + +## PAN-95028 + +For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.) + +## PAN-94846 + +When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state. + +## PAN-94093 + +HTTP Header Insertion does not work when jumbo frames are received out of order. + +## PAN-93968 + +The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature. + +## PAN-93607 + +When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles. + +**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there. + +## PAN-93532 + +When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**). + +## PAN-93193 + +The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not: + +- Switch to the firewall **Context** on the Panorama management server. +- Commit changes when a dynamic update is being installed. +- Generate a custom report when a dynamic update is being installed. +- Generate custom reports during a commit. + +**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall. + +Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall. + +## PAN-91802 + +On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions. + +## PAN-83610 + +In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets. + +**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command. + +## PAN-83236 + +The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**). + +**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides. + +## PAN-83215 + +SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM). + +## PAN-81521 + +Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**). + +**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile. + +## PAN-77125 + +PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out. + +**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command. + +## PAN-75457 + +```caveat +PAN-OS 8.0.1 and later releases +``` + +In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive. + +## PAN-73530 + +The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files. + +## PAN-73401 + +```caveat +PAN-OS 8.0.1 and later releases +``` + +When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist: + +- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.) +- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes). + +**Workaround:** There are three possible workarounds to sync the controller nodes: + +- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync. +- Configure a worker list on the cluster controller: + admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list ` + (`` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround. +- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled. + admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes` + or + admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no` + Both commands result in Panorama reporting that the controller nodes are in sync. + +## PAN-71329 + +Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **** > **Clientless VPN** > **Applications**). + +**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications. + +## PAN-70906 + +If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface. + +**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal. + +## PAN-69505 + +When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**). + +## PAN-41558 + +When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan. + +**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic. + +## PAN-40079 + +The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality. + +## PAN-39636 + +Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**. + +**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report. + +## PAN-38255 + +When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command. + +## PAN-31832 + +The following issues apply when configuring a firewall to use a hardware security module (HSM): + +- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay. +- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds. diff --git a/web/data/issues/PAN-OS/known/9.1.19_2026-03-31.md b/web/data/issues/PAN-OS/known/9.1.19_2026-03-31.md new file mode 100644 index 0000000..f20d966 --- /dev/null +++ b/web/data/issues/PAN-OS/known/9.1.19_2026-03-31.md @@ -0,0 +1,486 @@ +--- +type: Known +product: PAN-OS +version: 9.1.19 +--- + +## BLANK-000000 + +Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process. + +## BLANK-000000 + +A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available. + +- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.` +- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50. + The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM- license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model. + +## PLUG-380 + +When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls. + +## PAN-223365 + +The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded. + +**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot. + +`admin``request restart system` + +Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector. + +## PAN-221015 + +On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded. + +**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes. + +`admin>``debug elasticsearch es-restart optional all` + +Code copied to clipboard + +Unable to copy due to lack of browser support. + +Copy + +## PAN-197859 + +On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap. + +## PAN-197341 + +On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule. + +For example: + +1. You create a parent device group `DG-A` and a child device group `DG-B`. +2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`. +3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`. + +Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object. + +## PAN-178194 + +Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering. + +## PAN-154266 + +When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used. + +**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies. + +## PAN-154247 + +On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out. + +**Workaround:** Log out and back in to the Panorama web interface. + +## PAN-153803 + +On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer. + +## PAN-146573 + +PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries. + +## PAN-146485 + +On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`. + +Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`. + +**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration. + +## PAN-144889 + +```caveat +PAN-OS 9.1.2-h1 and later releases only +``` + +On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`. + +**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**). + +## PAN-140959 + +The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported. + +## PAN-134456 + +SNMP traps configured to use the dataplane port in service routes are still sent using the management interface. + +**Workaround:** Use a destination-based service route for the SNMP trap server. + +## PAN-134053 + +ACC does not filter WildFire logs from Dynamic User Groups. + +## PAN-130550 + +```caveat +PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls +``` + +For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation. + +**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic. + +## PAN-127813 + +In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub. + +**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration. + +## PAN-127550 + +Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI. + +## PAN-127474 + +When you configure a Server Profile, the custom log format for GlobalProtect logs is missing. + +## PAN-127206 + +If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out. + +## PAN-123277 + +Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface. + +## PAN-123040 + +When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround. + +## PAN-120440 + +There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`. + +## PAN-120303 + +There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface. + +**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below. + +- Modify the PAN-DB Server IP address on the managed firewall. + 1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings). + 2. **Commit** your changes. + 3. Add the new M-500 Eth1/1 IP PAN-DB IP address. + 4. **Commit** your changes. +- Restart the firewall (devsrvr) process. + 1. Log in to the firewall CLI. + 2. Restart the devsrvr process: `debug software restart process device-server` + +## PAN-118065 + +```caveat +M-Series Panorama management servers in Management Only mode +``` + +When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit. + +**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change. + +## PAN-116017 + +```caveat +Google Cloud Platform (GCP) only +``` + +The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall. + +**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process. + +## PAN-115816 + +```caveat +Microsoft Azure only +``` + +There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall. + +**Workaround:** Reboot the firewall. + +## PAN-114495 + +Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets. + +Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode. + +## PAN-112694 + +```caveat +Firewalls with multiple virtual systems only +``` + +If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one. + +## PAN-112456 + +You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter. + +## PAN-111928 + +Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration. + +**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors. + +## PAN-111866 + +The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes. + +**Workaround:** Perform one of the following tasks. + +- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations. +- Manually select the devices that belong to the modified device group and template configurations. + +## PAN-111729 + +If you disable DPDK mode and enable it again, you must immediately reboot the firewall. + +## PAN-111670 + +Tagged VLAN traffic fails when sent through an SR-IOV adapter. + +## PAN-111251 + +Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect. + +## PAN-110794 + +DGA-based threats shown in the firewall threat log display the same name for all such instances. + +## PAN-109759 + +The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match. + +## PAN-109526 + +The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters. + +## PAN-106675 + +After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers. + +**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports. + +## PAN-104780 + +If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints. + +Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report. + +## PAN-103276 + +Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive. + +**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again. + +## PAN-101688 + +```caveat +Panorama plugins +``` + +The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group. + +**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`. + +## PAN-101537 + +After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log direction equal | in ` command on a managed firewall only returns address and address group objects pushed form the Shared device group. + +**Workaround:** Specify the vsys in the query string: + +`admin>` `set system target-vsys ` + +`admin>` `show log direction equal query equal ‘vsys eq | in ` + +## PAN-98520 + +When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored. + +## PAN-97757 + +GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect. + +**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP. + +## PAN-97524 + +```caveat +Panorama management server only +``` + +The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch. + +## PAN-96985 + +The `request shutdown system` command does not shut down the Panorama management server. + +## PAN-96960 + +You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI. + +## PAN-96446 + +A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode. + +## PAN-95773 + +On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate. + +**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command. + +## PAN-95511 + +The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule. + +## PAN-95028 + +For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.) + +## PAN-94846 + +When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state. + +## PAN-94093 + +HTTP Header Insertion does not work when jumbo frames are received out of order. + +## PAN-93968 + +The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature. + +## PAN-93607 + +When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles. + +**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there. + +## PAN-93532 + +When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**). + +## PAN-93193 + +The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not: + +- Switch to the firewall **Context** on the Panorama management server. +- Commit changes when a dynamic update is being installed. +- Generate a custom report when a dynamic update is being installed. +- Generate custom reports during a commit. + +**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall. + +Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall. + +## PAN-91802 + +On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions. + +## PAN-83610 + +In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets. + +**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command. + +## PAN-83236 + +The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**). + +**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides. + +## PAN-83215 + +SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM). + +## PAN-81521 + +Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**). + +**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile. + +## PAN-77125 + +PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out. + +**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command. + +## PAN-75457 + +```caveat +PAN-OS 8.0.1 and later releases +``` + +In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive. + +## PAN-73530 + +The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files. + +## PAN-73401 + +```caveat +PAN-OS 8.0.1 and later releases +``` + +When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist: + +- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.) +- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes). + +**Workaround:** There are three possible workarounds to sync the controller nodes: + +- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync. +- Configure a worker list on the cluster controller: + admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list ` + (`` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround. +- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled. + admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes` + or + admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no` + Both commands result in Panorama reporting that the controller nodes are in sync. + +## PAN-71329 + +Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **** > **Clientless VPN** > **Applications**). + +**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications. + +## PAN-70906 + +If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface. + +**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal. + +## PAN-69505 + +When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**). + +## PAN-41558 + +When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan. + +**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic. + +## PAN-40079 + +The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality. + +## PAN-39636 + +Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**. + +**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report. + +## PAN-38255 + +When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command. + +## PAN-31832 + +The following issues apply when configuring a firewall to use a hardware security module (HSM): + +- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay. +- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds. diff --git a/web/data/issues/PAN-OS/known/9.1.4_2026-03-31.md b/web/data/issues/PAN-OS/known/9.1.4_2026-03-31.md new file mode 100644 index 0000000..9004a65 --- /dev/null +++ b/web/data/issues/PAN-OS/known/9.1.4_2026-03-31.md @@ -0,0 +1,552 @@ +--- +type: Known +product: PAN-OS +version: 9.1.4 +--- + +## BLANK-000000 + +Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process. + +## BLANK-000000 + +A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available. + +- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.` +- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50. + The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM- license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model. + +## PLUG-380 + +When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls. + +## PAN-223365 + +The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded. + +**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot. + +`admin``request restart system` + +Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector. + +## PAN-199557 + +On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive. + +**Workaround:** Manually reboot the `Active` Panorama HA peer. + +## PAN-197341 + +On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule. + +For example: + +1. You create a parent device group `DG-A` and a child device group `DG-B`. +2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`. +3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`. + +Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object. + +## PAN-178194 + +Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering. + +## PAN-154266 + +When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used. + +**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies. + +## PAN-154247 + +On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out. + +**Workaround:** Log out and back in to the Panorama web interface. + +## PAN-153803 + +On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer. + +## PAN-151909 + +```caveat +This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues. +``` + +On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**). + +## PAN-148359 + +```caveat +This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues. +``` + +SD-WAN server-to-client symmetric return does not function correctly under certain circumstances, and the issue can also affect path selection of parent/child applications, such as FTP. + +## PAN-146573 + +PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries. + +## PAN-146485 + +On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`. + +Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`. + +**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration. + +## PAN-144889 + +```caveat +PAN-OS 9.1.2-h1 and later releases only +``` + +On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`. + +**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**). + +## PAN-140959 + +The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported. + +## PAN-136701 + +```caveat +PA-7000b Series firewalls only +``` + +Packets for new sessions drop when handling predict sessions. + +**Workaround:** Use the following CLi commands to bypass this issue: + +- `set session hwpredict disable yes` +- `show session hwpredict status` + +## PAN-140084 + +```caveat +This issue is now resolved. See PAN-OS 9.1.5 Addressed Issues. +``` + +There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2. + +## PAN-136701 + +```caveat +PA-7000b Series firewalls only +``` + +Packets for new sessions drop when handling predict sessions. + +**Workaround:** Use the following CLi commands to bypass this issue: + +- `set session hwpredict disable yes` +- `show session hwpredict status` + +## PAN-134456 + +SNMP traps configured to use the dataplane port in service routes are still sent using the management interface. + +**Workaround:** Use a destination-based service route for the SNMP trap server. + +## PAN-134053 + +ACC does not filter WildFire logs from Dynamic User Groups. + +## PAN-130550 + +```caveat +PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls +``` + +For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation. + +**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic. + +## PAN-127813 + +In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub. + +**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration. + +## PAN-127550 + +Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI. + +## PAN-127474 + +When you configure a Server Profile, the custom log format for GlobalProtect logs is missing. + +## PAN-127206 + +If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out. + +## PAN-124956 + +```caveat +This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues. +``` + +There is an issue where VM-Series firewalls do not support packet buffer protection. + +## PAN-123277 + +Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface. + +## PAN-123040 + +When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround. + +## PAN-121484 + +```caveat +This issue is now resolved. See PAN-OS 9.1.6 Addressed Issues. +``` + +The dataplane sends positive acknowledgments to predict-status checks from FPP when the corresponding predict is deleted, which causes SIP and RTSP applications to perform less than the expected achievable performance. + +## PAN-120440 + +There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`. + +## PAN-120423 + +PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs. + +## PAN-120303 + +There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface. + +**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below. + +- Modify the PAN-DB Server IP address on the managed firewall. + 1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings). + 2. **Commit** your changes. + 3. Add the new M-500 Eth1/1 IP PAN-DB IP address. + 4. **Commit** your changes. +- Restart the firewall (devsrvr) process. + 1. Log in to the firewall CLI. + 2. Restart the devsrvr process: `debug software restart process device-server` + +## PAN-118065 + +```caveat +M-Series Panorama management servers in Management Only mode +``` + +When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit. + +**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change. + +## PAN-116017 + +```caveat +Google Cloud Platform (GCP) only +``` + +The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall. + +**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process. + +## PAN-115816 + +```caveat +Microsoft Azure only +``` + +There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall. + +**Workaround:** Reboot the firewall. + +## PAN-114495 + +Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets. + +Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode. + +## PAN-112694 + +```caveat +Firewalls with multiple virtual systems only +``` + +If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one. + +## PAN-112456 + +You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter. + +## PAN-111928 + +Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration. + +**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors. + +## PAN-111866 + +The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes. + +**Workaround:** Perform one of the following tasks. + +- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations. +- Manually select the devices that belong to the modified device group and template configurations. + +## PAN-111729 + +If you disable DPDK mode and enable it again, you must immediately reboot the firewall. + +## PAN-111670 + +Tagged VLAN traffic fails when sent through an SR-IOV adapter. + +## PAN-111251 + +Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect. + +## PAN-110794 + +DGA-based threats shown in the firewall threat log display the same name for all such instances. + +## PAN-109759 + +The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match. + +## PAN-109526 + +The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters. + +## PAN-106675 + +After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers. + +**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports. + +## PAN-104780 + +If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints. + +Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report. + +## PAN-103276 + +Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive. + +**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again. + +## PAN-103018 + +```caveat +Panorama plugins +``` + +When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected. + +## PAN-101688 + +```caveat +Panorama plugins +``` + +The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group. + +**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`. + +## PAN-101537 + +After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log direction equal | in ` command on a managed firewall only returns address and address group objects pushed form the Shared device group. + +**Workaround:** Specify the vsys in the query string: + +`admin>` `set system target-vsys ` + +`admin>` `show log direction equal query equal ‘vsys eq | in ` + +## PAN-98520 + +When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored. + +## PAN-97757 + +GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect. + +**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP. + +## PAN-97524 + +```caveat +Panorama management server only +``` + +The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch. + +## PAN-96985 + +The `request shutdown system` command does not shut down the Panorama management server. + +## PAN-96960 + +You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI. + +## PAN-96446 + +A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode. + +## PAN-95773 + +On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate. + +**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command. + +## PAN-95511 + +The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule. + +## PAN-95028 + +For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.) + +## PAN-94846 + +When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state. + +## PAN-94093 + +HTTP Header Insertion does not work when jumbo frames are received out of order. + +## PAN-93968 + +The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature. + +## PAN-93607 + +When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles. + +**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there. + +## PAN-93532 + +When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**). + +## PAN-93193 + +The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not: + +- Switch to the firewall **Context** on the Panorama management server. +- Commit changes when a dynamic update is being installed. +- Generate a custom report when a dynamic update is being installed. +- Generate custom reports during a commit. + +**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall. + +Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall. + +## PAN-91802 + +On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions. + +## PAN-83610 + +In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets. + +**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command. + +## PAN-83236 + +The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**). + +**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides. + +## PAN-83215 + +SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM). + +## PAN-81521 + +Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**). + +**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile. + +## PAN-77125 + +PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out. + +**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command. + +## PAN-75457 + +```caveat +PAN-OS 8.0.1 and later releases +``` + +In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive. + +## PAN-73530 + +The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files. + +## PAN-73401 + +```caveat +PAN-OS 8.0.1 and later releases +``` + +When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist: + +- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.) +- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes). + +**Workaround:** There are three possible workarounds to sync the controller nodes: + +- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync. +- Configure a worker list on the cluster controller: + admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list ` + (`` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround. +- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled. + admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes` + or + admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no` + Both commands result in Panorama reporting that the controller nodes are in sync. + +## PAN-71329 + +Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **** > **Clientless VPN** > **Applications**). + +**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications. + +## PAN-70906 + +If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface. + +**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal. + +## PAN-69505 + +When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**). + +## PAN-41558 + +When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan. + +**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic. + +## PAN-40079 + +The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality. + +## PAN-39636 + +Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**. + +**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report. + +## PAN-38255 + +When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command. + +## PAN-31832 + +The following issues apply when configuring a firewall to use a hardware security module (HSM): + +- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay. +- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds. diff --git a/web/data/products.json b/web/data/products.json index 05ba5c1..023ecd9 100644 --- a/web/data/products.json +++ b/web/data/products.json @@ -407,8 +407,15 @@ "9.1.0_2026-03-16.md", "9.1.1_2026-03-16.md", "9.1.2_2026-03-16.md", + "9.1.2-h1_2026-03-31.md", "9.1.3_2026-03-16.md", + "9.1.3-h1_2026-03-31.md", + "9.1.4_2026-03-31.md", + "9.1.5_2026-03-31.md", + "9.1.6_2026-03-31.md", "9.1.7_2026-03-16.md", + "9.1.8_2026-03-31.md", + "9.1.9_2026-03-31.md", "9.1.10_2026-03-16.md", "9.1.11_2026-03-16.md", "9.1.11-h2_2026-03-16.md", @@ -418,25 +425,34 @@ "9.1.12_2026-03-16.md", "9.1.12-h3_2026-03-16.md", "9.1.12-h4_2026-03-16.md", + "9.1.12-h6_2026-03-31.md", "9.1.12-h7_2026-03-16.md", + "9.1.13_2026-03-31.md", "9.1.13-h1_2026-03-16.md", "9.1.13-h3_2026-03-16.md", "9.1.13-h4_2026-03-16.md", + "9.1.13-h5_2026-03-31.md", "9.1.14_2026-03-16.md", "9.1.14-h1_2026-03-16.md", "9.1.14-h4_2026-03-16.md", "9.1.14-h7_2026-03-16.md", "9.1.14-h8_2026-03-16.md", "9.1.15_2026-03-16.md", + "9.1.15-h1_2026-03-31.md", "9.1.16_2026-03-16.md", "9.1.16-h3_2026-03-16.md", + "9.1.16-h4_2026-03-31.md", "9.1.16-h5_2026-03-16.md", - "9.1.17_2026-03-16.md" + "9.1.17_2026-03-16.md", + "9.1.17-h1_2026-03-31.md", + "9.1.18_2026-03-31.md", + "9.1.19_2026-03-31.md" ], "known": [ "9.1.1_2026-03-16.md", "9.1.2_2026-03-16.md", "9.1.3_2026-03-16.md", + "9.1.4_2026-03-31.md", "9.1.5_2026-03-16.md", "9.1.6_2026-03-16.md", "9.1.7_2026-03-16.md", @@ -445,10 +461,13 @@ "9.1.10_2026-03-16.md", "9.1.11_2026-03-16.md", "9.1.12_2026-03-16.md", + "9.1.13_2026-03-31.md", + "9.1.14_2026-03-31.md", "9.1.15_2026-03-16.md", "9.1.16_2026-03-16.md", "9.1.17_2026-03-16.md", - "9.1.18_2026-03-16.md" + "9.1.18_2026-03-16.md", + "9.1.19_2026-03-31.md" ] }, "9.0": {