Add PAN-OS 9.1 issues

This commit is contained in:
2026-03-31 13:45:22 -05:00
parent b67fb014a5
commit 9a10566267
20 changed files with 4027 additions and 2 deletions
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 9.1.12-h6
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 9.1.13-h5
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,177 @@
---
type: Addressed
product: PAN-OS
version: 9.1.13
---
## WF500-5513
Fixed an issue where cloud queries failed, which generated system logs. The issue occurred because a hash was not found in the cloud.
## PAN-184445
Fixed an issue where, after upgrading Panorama, when **Share Unused Address and Service Objects with Devices** was unchecked, address objects using tags to dynamic address groups were removed after a full commit.
## PAN-181802
Fixed an issue where a memory utilization condition resulted in the web interface responding more slowly than expected and management server restarting.
## PAN-181309
Fixed an issue where Panorama was inaccessible due to the configd process not responding.
## PAN-180338
Fixed an issue where the CTD loop count wasn't accurately incremented.
## PAN-179274
Fixed an issue on high availability configurations where, after upgrading to PAN-OS 9.1.10, PAN-OS 10.0.6, or PAN-OS 10.1.0, the high availability (HA1) and HA1-Backup link stayed down. This issue occurred when the peer firewall IP address was in a different subnet.
## PAN-179164
Fixed an issue where a web-proxy port number was added to the destination URL when captive portal authentication was run.
## PAN-177907
Fixed an issue where, after rebooting the firewall, FQDN address objects referred in rules in a virtual system (vsys) did not resolve when the vsys used a custom DNS proxy.
## PAN-177626
Fixed an issue where aggressive situations caused on-chip descriptor exhaustion.
## PAN-177551
A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)).
## PAN-176054
Fixed an intermittent issue where users did not have access to resources due to a host information profile (HIP) check failure that was caused by the HIP data not being synced between the management plane and the dataplane.
## PAN-175628
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the firewall was unable to monitor AUX1 and AUX2 interfaces through SNMP.
## PAN-175211
Fixed a memory leak issue in the (mgmtsrvr) process.
## PAN-174781
Fixed an issue where the firewall did not send an SMTP 541 error message to the email client after detecting a malicious file attachment.
## PAN-174709
Fixed an out-of-memory (OOM) condition that occurred due to multiple parallel jobs being created by the scheduled log export feature.
## PAN-174244
Fixed an issue where a sudden increase in URL data approached the maximum cache capacity of the firewall.
## PAN-173469
Fixed an intermittent issue where websites were blocked and categorized as not resolved.
## PAN-173373
```caveat
VM-Series firewalls in NSX-T deployments only
```
Fixed an issue where deployments dropped packets with the counter pan_netx_send_pkt error.
## PAN-172837
Fixed an intermittent issue where the firewall didn't generate block URL logs for URLs even though the websites were blocked in the client device.
## PAN-172295
Fixed an issue where a HIP database cache loop caused high CPU utilization on a process (useridd) and caused IP address-to-user mapping redistribution failure.
## PAN-172243
Fixed an issue where NetFlow traffic triggered a packet buffer leak.
## PAN-172056
```caveat
VM-Series firewalls only
```
The logging rate limit was improved to prevent log loss.
## PAN-170997
Fixed an issue where FQDN service routes were not installed after a system reboot.
## PAN-170952
Fixed script issues that caused diagnostic data to not be collected after path monitor failure.
## PAN-169212
Fixed an issue where information level logs caused configd logs to fill.
## PAN-168452
Fixed an issue where DNS signatures did not trigger.
## PAN-168400
Fixed an issue where, after installing Cloud Services plugin 2.0, the **Plugin cloud_services** status (**Dashboard > High Availability**) displayed as **Mismatch**.
## PAN-163030
Fixed an issue where restarting the devsrvr process caused new GlobalProtect connections to fail with the error message required client certificate not found. This issue occurred due to a key mismatch between the dataplane and the management plane.
## PAN-161297
Fixed an interoperability issue with other vendors when IKEv2 used SHA2-based certificate authentication.
## PAN-160419
Fixed an issue where the following error message displayed in the system log after restarting the firewall: dns-signature initialization from file storage failed, start with empty cache.
## PAN-159295
Fixed an issue where scheduled configuration export files saved in the /tmp folder weren't periodically purged, which caused the root partition to fill up.
## PAN-159214
Fixed an issue where a .txt file was corrupted, which caused the web interface to not display the requested information.
## PAN-159210
Fixed an issue where timed-out DNS Security queries produced incorrect system log entries indicating cloud service connection refused. With this fix, timed-out queries are correctly logged as cloud query timeout.
## PAN-158541
Fixed an OOM condition on the dataplane on FIPS-mode firewall decryption that used DHE ciphers.
## PAN-158280
Fixed an issue where SMB sessions were discarded with the following error message: ctd out of resource.
## PAN-153019
Fixed an issue where the following error message appeared: Error: pan_tdb_load_sml_dfa_serialize(pan_tdb_ser.c:2424): pan_util_file_to_buf /opt/pancfg/mgmt/content//cache/common//sml_dfa.cache.ser error, even though the cache file got regenerated if it was missing.
## PAN-151749
Fixed an issue where Panorama did not show warnings of the last commit job.
## PAN-146734
Fixed an issue where, when a Panorama-pushed configuration was referenced in a local configuration, commits failed after updating the master key on the firewall, which resulted in the following error message: Invalid candidate configuration. Master key change aborted....
## PAN-145833
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the firewall stopped recording dataplane diagnostic data in dp-monitor.log after a few hours of uptime.
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 9.1.15-h1
---
## PAN-204118
Fixed an issue where browser sessions stopped responding device group template admin users with access domains that had many device groups or templates.
## PAN-199500
Fixed an issue where, when many NAT policy rules were configured, the pan_comm process stopped responding after a configuration commit due to a high number of debug messages.
## PAN-196874
Fixed an issue where, when the firewall accepted ICMP redirect messages on the management interface, the firewall did not clear the route from the cache.
## PAN-202247
Fixed an issue with firewalls in HA configurations where the firewall dropped IKE SA connections if the peer firewall received an INVALID_SPI message. This occurred even though no IKE SA was associated with the SPI in the received INVALID-SPI payload.
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 9.1.16-h4
---
## PAN-237871
```caveat
WF-500 appliances and PAN-DB private cloud deployments only
```
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 9.1.17-h1
---
## PAN-239241
Extended the root certificate for WildFire appliances to December 31, 2032.
@@ -0,0 +1,57 @@
---
type: Addressed
product: PAN-OS
version: 9.1.18
---
## PAN-242561
Fixed an issue where GlobalProtect tunnels disconnected shortly after being established when SSL was used as the transfer protocol.
## PAN-240688
Fixed an issue where LSVPN tunnels did not come up and did not switch tunnel monitoring up.
## PAN-234596
Fixed an issue on firewalls in active/passive high availability (HA) configurations where the passive firewall incorrectly became active after a reboot.
## PAN-221208
Fixed an issue where the tunnel monitor was unable to remain up when Zone Protection with Strict IP was enabled and NAT Traversal was applied.
## PAN-217465
Fixed an issue where the Panorama web interface became unresponsive and displayed the error message **504 Gateway Not Reachable**.
## PAN-212860
Fixed an issue where changes to the SD-WAN database did not remove the old entries.
## PAN-205255
Fixed a rare issue that caused the dataplane to restart unexpectedly.
## PAN-201269
Fixed an issue where commits failed with the error message IPv6 addresses are not allowed because IPv6-firewalling is disabled when Security policy rules had an address group with more than 1000 FQDN address objects.
## PAN-199214
Fixed an intermittent issue where downloading threat pcap via XML API failed with the following error message: /opt/pancfg/session/pan/user_tmp/XXXXX/YYYYY.pcap does not exist.
## PAN-196457
Fixed an issue where extraneous logs displayed in the Traffic log when Security policy rule settings were changed.
## PAN-195342
Fixed an issue on Panorama where, when you attempted to context switch from a managed firewall on PAN-OS 10.1.7 or an earlier release back to Panorama, the context switch failed with the following error message: Could not find start token '@start@.
## PAN-180948
Fixed an issue where an external dynamic list fetch failed with the error message Unable to fetch external dynamic list. Couldn't resolve host name. Using old copy for refresh.
## PAN-159508
Fixed an IPSec tunnel memory leak issue where IPSec tunnels failed during rekey.
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 9.1.19
---
## PAN-245041
Fixed an issue where the WF-500 appliance returned an error verdict for every sample in FIPS mode.
## PAN-231658
Fixed an issue where DNS resolution failed when interfaces were configured as DHCP and a DNS server was provided via DHCP while also statically configured with DNS servers.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 9.1.2-h1
---
## PAN-144073
Fixed an issue where on the Panorama management server, hub and branch firewall latency, jitter, and packet loss data was not updated when monitoring SD-WAN link performance (**Panorama** > **SD-WAN** > **Monitoring**).
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 9.1.3-h1
---
## PAN-150172
Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
@@ -0,0 +1,309 @@
---
type: Addressed
product: PAN-OS
version: 9.1.4
---
## WF500-5320
Fixed an issue where the WF-500 cluster did not synchronize verdicts after successful verdict recheck queries with the WildFire global cloud.
## PAN-151197
Fixed an issue where a process (authd) restarted when an administrator authenticated to the firewall with an Active Directory (AD) account. This issue occurred when LDAP was configured with FQDN, used DHCP instead of a static management IP address, and used the management interface to connect to the LDAP server.
## PAN-150172
Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
## PAN-150170
```caveat
and PAN-149822
```
A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)).
## PAN-150013
```caveat
and PAN-149822
```
A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)).
## PAN-149377
A fix was made to address a vulnerability regarding information exposure through log files in PAN-OS that made it possible for configuration secrets for HTTP, email, and SNMP trap v3 log forwarding server profiles to be logged to the logrcvr.log system log ([CVE-2021-3032](https://security.paloaltonetworks.com/CVE-2021-3032)).
## PAN-148806
A fix was made to address an uncontrolled resource consumption vulnerability in PAN-OS that allowed for a remote unauthenticated user to upload temporary files through the management web interface that were not properly deleted after the request was finished. An attacker could disrupt the availability of the management web interface by repeatedly uploading files until available disk space was exhausted ([CVE-2020-2039](https://security.paloaltonetworks.com/CVE-2020-2039)).
## PAN-148676
Fixed an issue where the panlogs directory reached 100% utilization on the firewall due to early calculation of the .size file.
## PAN-148522
Fixed an issue for PAN-DB where certain situations caused performance issues.
## PAN-147996
```caveat
PA-7000b Series firewalls only
```
Fixed a buffer overflow issue.
## PAN-147399
Fixed an issue where Panorama in Legacy mode rebooted due to multiple process (reportd) restarts.
## PAN-147258
Fixed an issue with one-way audio for inbound voice calls due to incorrect source port translation.
## PAN-147203
Fixed an issue where API calls did not return the output for the operational command for running configurations.
## PAN-146837
A fix was made to address a vulnerability involving information exposure through log files where sensitive fields were recorded in the configuration log without masking on PAN-OS software when the after-change-detail custom syslog field was enabled for configuration logs and the sensitive field appeared multiple times in one log entry. The first instance of the sensitive field was masked but subsequent instances were left in clear text ([CVE-2020-2043](https://security.paloaltonetworks.com/CVE-2020-2043)).
## PAN-146624
Fixed an issue where exporting logs from the web interface did not generate a system log entry.
## PAN-146531
Fixed an issue where conversion from Panorama mode to logger mode was enabled even when an admin user named admin did not exist in the configuration, which caused access to the appliance to be lost.
## PAN-146086
Fixed an issue for Amazon Web Services (AWS) types C5 and M5 where Panorama was unable to use NMVe storage.
## PAN-145942
After upgrading to certain PAN-OS 8.1 and 9.0 versions, for certain configurations using dynamic routing without graceful restart and with Bidirectional Forwarding Detection (BFD) enabled, there was a longer traffic hit after an HA failover compared to previous versions. This was due to BFD incorrectly timing admin-down messages for the failover event.
## PAN-145929
Fixed an issue where, after upgrading the passive firewall, the stream control transmission protocol (SCTP) sessions synced from the active firewall did not retain the rule information, and, after failover, SCTP stateful inspection did not work.
## PAN-145422
Fixed an issue where a process (all_pktproc) restarted while processing SSL VPN sessions.
## PAN-145302
Fixed an issue where the high availability (HA) peer device did not preserve its import configuration when the mode was active/active and VR sync was disabled.
## PAN-145142
Fixed an issue where Panorama running 9.0.8 allowed a user with the admin role Device Group and Template to create templates and template stacks.
## PAN-144882
Fixed an issue where the firewall generated critical system logs: Fsck failed for Logging Raid Disk Pair after downgrading from PAN-OS 9.0 to PAN-OS 8.1.
## PAN-144804
Fixed an issue where the firewall generated GPRS tunneling protocol (GTP) logs for invalid GTP packets. This fix also implements a counter, flow_gtp_invalid_ver, where the invalid packets are counted.
## PAN-144670
Fixed an issue where the multi-factor authentication (MFA) timestamp was not redistributed across the virtual system (vsys) when the IP address-to-user mapping type was UIA.
## PAN-144613
Fixed an issue where, when previewing device group configurations from Panorama, invalid messages were returned. With this fix, the configuration preview no longer returns invalid messages.
## PAN-144492
Fixed an issue where traffic matched an incorrect URL filtering profile due to a similarity in the MD5 hashes between the URL filtering profiles.
## PAN-143705
Fixed an issue where delicensing a large number of devices from Panorama failed.
## PAN-143686
Fixed an issue where a firewall running in FIPS mode was unable to download the GlobalProtect datafile even when a GlobalProtect license was installed and valid.
## PAN-143644
Fixed an issue where traffic did not match an FQDN address group based policy.
## PAN-143090
Fixed an issue where the firewall silently dropped TCP out-of-order packets.
## PAN-142927
Fixed an issue where the locked users list grew too large, which caused 100% CPU usage on a process (authd). With this fix, locked users will be purged hourly if the lockout time for that user has expired.
## PAN-142853
Fixed an issue on Panorama where commits failed, referring to a portion of the configuration that was not changed.
## PAN-142523
Fixed an issue where application-based SD-WAN policy match did not work if application traffic was subjected to SSL decryption.
## PAN-141515
Fixed an issue where a service object with a destination port that is pushed from Panorama displays as **[object Object]** on the firewall.
## PAN-141099
Fixed an issue where the HTTP/2 stream method was no longer valid after overloading the same pointer to point to either the HTTP/2 stream or the proxy flow.
## PAN-140747
Fixed an issue where the firewall failed to establish SFTP firewall-server connections when SSH decryption was enabled.
## PAN-140494
Added a mechanism to detect corrupted or incorrect formats received on dataplane CPU. Such packets are dropped, and a counter, pkt_recv_bad_group, is incremented.
## PAN-140272
Fixed an issue where RADIUS authentication failed when using an ampersand (&) in the RADIUS shared secret.
## PAN-139764
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak, which caused a process (configd) to restart.
## PAN-139680
Fixed an issue where dynamic route updates triggered an unintentional refresh of the DHCP client interface IP address, which led to the removal and re-addition of the default route associated with the DHCP client IP address and caused traffic disruption.
## PAN-139587
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where high and continuous CPU utilization was seen on dataplanes after IPSec Encapsulating Security Payload (ESP) rekeying occurred for multiple tunnels.
## PAN-139365
```caveat
PA-7000 Series firewalls only
```
Enhanced latency-sensitive protocols processing. With this fix, the following latency-sensitive control traffic will be prioritized: BGP, Bidirectional Forwarding Detection (BFD), LACP, OSPF, OSPFv3, Protocol Independent Multicast (PIM), and Internet Group Management Protocol (IGMP).
## PAN-139264
Fixed an issue where the Elasticsearch cluster status displayed in yellow due to a missing replica serial number.
## PAN-139172
Fixed an issue where response pages generated from the firewall used the SMAC and DMAC addresses from the original packet, which caused a MAC flap on connected switches.
## PAN-138584
Fixed an issue that prevented the addition of a secondary logging disk for a VM-Series firewall deployed on Amazon Web Services (AWS) using Nitro server instance types.
## PAN-137770
Fixed an issue where the dataplane restarted due to a loop in DoS protection source-destination IP address classification.
## PAN-137661
Fixed an issue where certain packets destined to untagged subinterfaces were silently dropped on multi-dataplane platforms.
## PAN-137138
Fixed an issue where a process (configd) consistently restarted with the following error message: virtual memory limit exceeded, restarting due to a dynamic updates push from Panorama to multiple firewalls.
## PAN-136844
Fixed an issue for S11 traffic where if the Modify Bearer Request message came after 30 seconds of Create Session Response message, the firewall dropped the Modify Bearer Request packet. This fix increases this time to 90 seconds.
## PAN-136650
Fixed an issue where a Log Collector remained in an out-of-sync state after configuring an IP address (local or public) on an additional Ethernet interface.
## PAN-135889
Fixed an issue where GTP-U tunnel session was setup incorrectly on receiving Modify Bearer Requests/ Responses with multiple Bearer Context for different EBIs
## PAN-135887
Fixed an issue where the inner GTP-U flows were installed using incorrect zones, which led to traffic issues if the firewall was in line for the S1-U interface.
## PAN-135673
Fixed an issue where the firewall kept its connection to Cortex Data Lake even after the configuration had been disabled and the license was expired.
## PAN-135134
Fixed an issue where using a session_proxy() without checking that it actually is a proxy led to a dataplane process restart.
## PAN-134029
Fixed an intermittent issue on the firewall where H.225 VOIP signaling packets dropped.
## PAN-132285
Fixed an intermittent issue where a Security policy with **Send ICMP Unreachable** enabled for certain drop or reset sessions caused a process (all-pktproc) to restart.
## PAN-131474
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where the connection details for a scheduled configuration export were logged in system logs ([CVE-2021-3037](https://security.paloaltonetworks.com/CVE-2021-3037)).
## PAN-129461
Fixed an issue where excessive next hop FPGA exceptions occurred when an ARP request or response was lost in the network in an ECMP configuration, which blocked subsequent ARP learning due to a full queue.
## PAN-128650
Fixed an issue where selecting **Preview Changes** under a specific device group resulted in the following error message: Parameter device group missing.
## PAN-123279
Fixed an issue where a process (configd) stopped responding after upgrading Panorama to 8.1.9 from 8.0.16 due to 8.0 WildFire appliance register requests.
## PAN-115896
Fixed an issue where the static route path monitoring status was not viewable from the CLI or web interface and failed with the following error message: failed to execute op command.
## PAN-114761
Fixed an issue where the log receiver failed to establish connections to Cortex Data Lake when it was unable to validate Cortex Data Lake certificates.
## PAN-114264
Fixed an issue where sessions were offloaded as the application identification was performed when you configured a custom application with **Continue scanning for other application**.
## PAN-113767
Fixed an issue where the firewall silently dropped packets when security profiles were attached and FPGA enabled AHO and DFA.
## PAN-112972
Fixed an issue where scheduled reports were not generated as expected when you added groups in a query builder.
## PAN-111333
An enhancement was made to increase the pattern match limit to recognize applications and threats accurately.
## PAN-110685
Fixed a rare issue where an incorrect User-ID™ match to the respective LDAP group caused a security policy mismatch.
## PAN-109894
Fixed an issue where, when DHCP requests were sent from a subinterface configured as a DHCP client, packets dropped due to improper handling of the ARP reply for the DHCP requests.
## PAN-103865
Fixed an issue where the firewall did not detect user credentials when the number of users exceeded 60,000. To leverage this fix, you must upgrade Windows agents to User-ID agent <8.1.11 | 9.0.4> or a later User-ID agent <8.1 | 9.0> release.
## PAN-101484
A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2038](https://security.paloaltonetworks.com/CVE-2020-2038)).
@@ -0,0 +1,421 @@
---
type: Addressed
product: PAN-OS
version: 9.1.5
---
## PAN-154092
Added an enhancement that provides an option to increase Data Plane Development Kit (DPDK) ring size and DPDK queue number for VM-Series firewalls deployed on ESXi.
## PAN-152699
Fixed an issue where the firewall added a redundant 0\r\n packet while processing Clientless VPN traffic.
## PAN-152285
Fixed an issue where certain GPRS tunneling protocol (GTP-U) sessions that could not complete installation still occupied the flow table, which led to higher session table usage.
## PAN-151203
Fixed an issue where the firewall dropped certain GTPv1 Update PDP Context packets.
## PAN-151164
Fixed an issue where logs weren't able to be migrated from PA-5200 Series firewalls manually via the CLI.
## PAN-151057
Fixed an issue where upgrading the capacity license on a virtual machine (VM) high availability (HA) pair resulted in both firewalls going into a non-functional state instead of only the higher capacity license firewall.
## PAN-150750
```caveat
PA-5200 and PA-7000 Series firewalls only
```
Fixed an intermittent issue where the firewall dropped packets when two or more GTP packets on the same GTP tunnel were very close to each other.
## PAN-150748
Fixed an issue where the firewall silently dropped GTPv2-C Delete Session Response packets.
## PAN-150746
Fixed an issue where the firewall dropped GTP packets with Delete Bearer messages for EBI 6 if they were received within two seconds of receiving the Delete Bearer messages for EBI 5.
## PAN-150243
Fixed an issue where after a successful commit, the candidate configuration was not updated to running configuration when initiated by an API-privileges-only custom role based administrator.
## PAN-149839
```caveat
PA-7000 Series firewalls only
```
Added CLI commands to enable/disable resource-control groups and CLI commands to set an upper memory limit of 8G on a process (mgmtsrvr). To enable resource-control groups, use debug software resource-control enable and to disable them, use debug software resource-control disable. To set the memory limit, use debug management-server limit-memory enable, and to remove the limit, use debug management-server limit-memory disable. For the memory limit change to take effect, the firewall must be rebooted.
## PAN-149813
Fixed an issue where the reply to an XML API call from Panorama was in a different format after upgrading to PAN-OS 8.1.14-h1 and later releases, which caused automated systems to fail the API call.
## PAN-149770
Fixed an issue with debug file handling that led to a process (mgmtsrvr) restart.
## PAN-149480
Fixed an issue where, if Panorama was connected to log collectors running an earlier release, a custom report query from Panorama, which includes new fields not supported in prior releases, triggered a restart on a process (reportd).
## PAN-149426
Fixed an issue where non-superuser administrators with all rights enabled were unable to **Review Policies** or **Review Apps** for downloaded or installed content versions.
## PAN-149325
Fixed an issue on Panorama where the web interface took more time than expected to load changes when the virtual router was large or when there was a large configuration change request from the web interface.
## PAN-149296
Fixed an issue on Panorama where system and configuration logs of dedicated Log Collectors did not show up on Panorama appliances in Management Only mode.
## PAN-149008
Fixed an issue where the CLI command Show config running following the CLI command set cli op-command-xml-output on produces an unreadable output.
## PAN-149005
Fixed an issue where XML API failed to fetch logs larger than 10MB.
## PAN-148564
Fixed an issue where Panorama stopped showing new logs when url_category_list was in the URL payload format of the HTTP(S) server profile used to forward URL logs from the Panorama Log Collector.
## PAN-148087
Fixed an issue where the object identifier (OID) being polled for the component hrStorageUsed was not unique after a PAN-OS upgrade.
## PAN-147741
Fixed an issue where an API call for correlated events did not return any events.
## PAN-147595
Fixed an issue where, after a policy commit and session rematch, stream control transmission protocol (SCTP) logs for an existing SCTP session still showed old rule information.
## PAN-147285
Fixed an issue where host information profile (HIP) details were not available on Panorama even when a HIP redistribution configuration was in place.
## PAN-146878
Fixed an issue where TCP traffic dropped due to TCP sequence checking in an HA active/active configuration where traffic was asymmetric.
## PAN-146841
Fixed an issue in Panorama where a commit-all to the managed firewalls failed with the following error message: invalid object reference when address objects were uploaded using an external script.
## PAN-146787
Fixed an issue where traffic incorrectly matched URL based authentication policies.
## PAN-146650
A fix was made to address an authentication bypass vulnerability in the GlobalProtect SSL VPN component of PAN-OS that allowed an attacker to bypass all client certificate checks with an invalid certificate. As a result, the attacker was able to authenticate as any user and gain access to restricted VPN network resources when the gateway or portal was configured to rely only on certificate-based authentication ([CVE-2020-2050](https://security.paloaltonetworks.com/CVE-2020-2050)).
## PAN-146623
Fixed an issue where a GlobalProtect client in a system with umlaut diacritics serial number was unable to log in to the GlobalProtect gateway.
## PAN-146506
Fixed an issue where memory usage on a process (useridd) was high, which caused the process to restart on the firewall acting as the User-ID redistribution agent. This issue occurred when multiple clients requested IP address-to-user mappings at the same time.
## PAN-146284
Fixed an issue where Application and Threat Content installation failed on the firewall with the following error message: Error: Threat database handler failed.
## PAN-146117
Fixed an issue on the firewalls where memory usage on a process (devsrvr) increased after running the show object dynamic-address-group all CLI command.
## PAN-146115
Fixed an issue where GlobalProtect IPsec connections flapped when the peer address to the gateway changed due to NAT.
## PAN-146107
Fixed an issue where memory allocation failure caused a process (pan_comm) to restart several times, which caused the firewall to restart.
## PAN-145823
Fixed an issue where BGP learned routes were incorrectly populated with a VR error as a next hop.
## PAN-145757
Fixed an issue on the firewalls where a process (all_pktproc) restarted while processing Session Traversal Utilities for NAT (STUN) over TCP.
## PAN-145752
Fixed an issue where exporting policies to PDF or CSV files did not include all policies and contained duplicates.
## PAN-145721
Fixed an issue where Application Command Center (ACC) data did not load when accessed from the **Top Applications** widget in the **Dashboard**.
## PAN-145507
Fixed an issue on the firewalls where traffic originating from a GlobalProtect user did not match HIP-based Security policies using the cached HIP report. Instead, the traffic was denied until the GlobalProtect agent submitted a new HIP report about 20 seconds later.
## PAN-145305
Fixed an issue where an inconsistent PAN-DB cloud connection caused the firewall to negotiate the incorrect version and decode the cloud responses with the incorrect format.
## PAN-145133
A fix was made to address a vulnerability in the PAN-OS signature-based threat detection engine that allowed an attacker to evade threat prevention signatures using specifically crafted TCP packets ([CVE-2020-1999](https://security.paloaltonetworks.com/CVE-2020-1999)).
## PAN-145041
Fixed an issue on the firewalls where a process (all_task) stopped responding.
## PAN-144919
Fixed an issue on an M-600 appliance where the Panorama management server stopped receiving new logs from firewalls because delayed log purging caused log storage on the Log Collectors to reach maximum capacity.
## PAN-144448
Fixed an issue with the automated correlation engine that caused firewalls to stop generating correlated event logs for the beacon-heuristics object (ID 6005).
## PAN-144232
Fixed an issue where, when any change was made to an authentication profile, the LDAP server or local user database in a shared context removed the user group mapping information from the firewall.
## PAN-143959
Fixed an issue on Panorama where a custom administrator with all rights enabled was not able to display the content of the external dynamic list (EDL) on the Panorama web interface.
## PAN-143809
Fixed an issue where Log Collectors had problems ingesting logs for older days received at a high rate.
## PAN-143796
Fixed an issue where commits failed on the firewall due to memory allocation failure. Configuration memory can be checked using the debug dataplane show cfg-memstat statistics CLI command.
## PAN-143010
```caveat
PA-7000 Series firewalls only
```
Fixed an issue with intermittent packet loss for GlobalProtect SSL tunnel traffic.
## PAN-142562
Fixed an issue on Panorama where creating certificates took longer than expected, which caused configuration lock timeouts.
## PAN-142363
Fixed an issue where a process (mprelay) stopped responding and invoked an out-of-memory (OOM) killer condition and displayed the following error messages: `tcam full` and pan_plfm_fe_cp_arp_delete.
## PAN-142219
Fixed an issue where a Panorama log query did not work for closed indices.
## PAN-141980
Fixed an issue where random member ports in a link aggregate group failed to join the aggregate group due to the following error: Link speed mismatch.
## PAN-141895
Fixed an issue that prevented GTP tunnel session timeout values from being configured via the web interface.
## PAN-141793
Fixed an issue where Panorama did not show correct logs filtered with not, leq, and geq.
## PAN-141717
Fixed an issue where an administrative user using custom admin roles and without access to the **Device** tab was unable to expand the detailed views of **Monitor > Logs**.
## PAN-141551
Fixed an issue where SSH service restart management did not take effect in the SSH management server profile.
## PAN-141296
Fixed an issue where a large certificate chain transmission delayed the decryption process and did not populate the mutual authentication cache.
## PAN-140900
Fixed an issue where IP address-to-tag mapping entries had negative time-to-live (TTL) values instead of being removed after expiry.
## PAN-140883
Fixed an issue where, after rebooting the firewall, the SNMP object identifier (OID) for TCP connections per second (panVsysActiveTcpCps / .1.3.6.1.4.1.25461.2.1.2.3.9.1.6.1) returned 0 until another OID was pulled. Additionally, after a restart of a daemon (snmpd), if the above OID was called before other OIDs, there was an approximate 10 second delay in populating the data pulled by each OID.
## PAN-140736
Fixed an issue where configuration synchronization failed in an HA configuration.
## PAN-140382
Fixed an issue where the Host Evasion Threat ID signature did not trigger for the initial session even after the DNS response was received before the session expired.
## PAN-140227
```caveat
PA-7000 Series firewalls only
```
Fixed a rare issue where the firewall rebooted due to path monitoring failure on the Log Processing Card (LPC).
## PAN-140173
Fixed an issue where a high number of groups in group mapping caused a process (useridd) to exit.
## PAN-140100
Fixed an issue where **Detailed Log View** (**Monitor > Logs > Traffic**) did not display the URL filtering logs as expected on HTTP/2 stream sessions.
## PAN-140084
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate was set as 2.
## PAN-139991
Fixed an issue where the web interface and the CLI were inaccessible, which caused the following error message to display on the web interface: Timed out while getting config lock.
## PAN-139233
Fixed an issue where HIP reports failed to show up via the web interface or the CLI.
## PAN-139136
Fixed an issue where a large number of groups in group mappings caused a process (useridd) to exit.
## PAN-138427
Fixed an issue where pushing a configuration from a Panorama management server running PAN-OS 9.0 to a firewall running PAN-OS 8.1 produced a HTTP/2 warning. To leverage this fix, update both Panorama and the firewall to PAN-OS 9.1.5.
## PAN-137663
Fixed a cosmetic issue where misleading App-ID and rule shadowing warnings populated after a commit.
## PAN-137157
Fixed an issue where Panorama became inaccessible with the following error message: Timed out while getting config lock.
## PAN-135989
Fixed an issue where the serial number was unknown for VM-Series firewalls after upgrading from PAN-OS 8.0 to PAN-OS 8.1.
## PAN-135354
Fixed an issue where the paths between the control plane and the dataplanes in network processing cards (NPCs) stalled in the dataplane-to-control plane direction due to the Ring Descriptor entries becoming out of sync on each side. This produced unrecoverable data path monitoring failures, which caused the chassis to become nonfunctional.
## PAN-135071
Fixed an issue in Panorama where the template stack drop-down was missing templates when using access domain. This issue is fixed only for existing template stacks.
## PAN-134907
Fixed an issue where IP tags were not evaluated in the filter evaluation criteria when Dynamic Address Groups were configured.
## PAN-134745
Fixed an issue where Panorama commits failed due to a process (useridd) running on high file descriptors as a large number firewalls connect to Panorama for User-ID redistribution.
## PAN-134226
Fixed an issue where **AdminStatus** for HA1 and High Speed Chassis Interconnect (HSCI) interfaces were incorrectly reported.
## PAN-133934
Fixed an intermittent issue where user-to-IP address mappings were not redistributed to client firewalls.
## PAN-131750
Fixed an issue where a configuration push from Panorama to the firewall showed the **Commit All** status as completed even though the job was still being processed.
## PAN-130955
Fixed an issue where templates on the secondary Panorama appliance were out of sync with the primary Panorama appliance due to an empty content-preview node.
## PAN-130389
```caveat
PA-220 firewalls only
```
Fixed an issue where rx-broadcast and rx-multicast interface counters were not increasing even broadcast and/or multicast traffic was being received.
## PAN-130357
Fixed a memory leak issue where virtual memory used by the SNMP process started to slowly increase when the request was sent with a request-id of 0.
## PAN-129376
```caveat
PA-800 Series firewalls only
```
Fixed an issue that prevented ports 9-12 from being powered down by hardware after being requested to do so.
## PAN-129234
Fixed an issue where syslog connection failures were frequently reported in system logs.
## PAN-128048
Fixed an issue where certificate-based authentication with IKEv2 IPSec tunnels failed to establish with some third-party vendors.
## PAN-126353
Fixed an issue where the XML API used to retrieve hardware status periodically failed with a 200 OK message and no data.
## PAN-125218
A fix was made to address an information exposure vulnerability in Panorama that disclosed the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performed a context switch ([CVE-2020-2022](https://security.paloaltonetworks.com/CVE-2020-2022)).
## PAN-124681
A fix was made to address a vulnerability where Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls were not cleared before the data frame was created ([CVE-2021-3031](https://security.paloaltonetworks.com/CVE-2021-3031)).
## PAN-121035
Added support of high powered module PAN-QSFP28-100GBASE-ER4.
## PAN-120245
Fixed an issue on Panorama where WildFire cloud content download failed for content deployment to the WF-500 appliance.
## PAN-119982
Fixed an issue where template variable view failed to display some template variables when the **Device Priority** type variable was configured.
## PAN-115541
Fixed an issue where removing a cipher from an SSL/TLS profile did not take effect if it was attached to the management interface.
## PAN-112449
Fixed an issue that caused a daemon (snmpd) to hang when sending a Simple Network Management Protocol (SNMP) GET request for LcLogUsageTable on a Panorama appliance in Management Only mode.
## PAN-110423
Fixed an issue where mounting failure occurred and root partition reached 100%.
## PAN-110168
Fixed an issue where the firewall and Panorama web interface did not present HSTS headers to your web browser.
## PAN-103018
Fixed an issue where, when defining the match criteria for dynamic address groups on Panorama, the boolean AND/OR operators did not function properly.
@@ -0,0 +1,305 @@
---
type: Addressed
product: PAN-OS
version: 9.1.6
---
## PAN-154166
```caveat
VM-500 and later firewalls only
```
A new CLI command was added to increase the number of threads for handling incoming GlobalProtect connection requests when there is a high login rate and a slow authentication response from an external server.
## PAN-154114
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where secrets in PAN-OS XML API requests were logged in cleartext in the web server logs when the API was used incorrectly ([CVE-2021-3036](https://security.paloaltonetworks.com/CVE-2021-3036)).
## PAN-154093
Fixed an issue where a process (httpd) restarted during Security Assertion Markup Language (SAML) logout sessions initiated from the IdP.
## PAN-153983
Fixed an issue where the IPSec encapsulation sequence was not properly synced to the dataplanes on a high availability (HA) active/passive cluster.
## PAN-153874
Fixed a capacity issue caused by high operational activity and large configurations on Panorama. This fix increased the virtual memory limit on the configd process to 32GB.
## PAN-153868
Fixed an issue where firewall forwarding logs to Cortex Data Lake displayed **License** as gray and device connectivity as **Error** under **Logging Service Status**.
## PAN-153813
Fixed an issue where the proxy configuration did not get honored, which caused certificate revocation list (CRL) checks from the firewall to fail.
## PAN-153673
Fixed an issue where traffic logs were not shown due to a thread timeout that was causing the reading of the logs from the dataplane to slow.
## PAN-153440
Fixed an issue where firewalls repeatedly connected and disconnected to Cortex Data Lake due to a probing issue.
## PAN-153436
Added CLI commands to increase thread limits to reduce task thread exhaustion on a process (configd).
## PAN-153111
Fixed an issue where packet buffer unavailability caused host-bound sessions to remain in an opening state in the dataplane.
## PAN-152706
Fixed an intermittent issue where Panorama did not retrieve firewall logs from Cortex Data Lake.
## PAN-152440
Fixed an issue where the syntax on GlobalProtect DNS suffixes was not validated.
## PAN-152282
Fixed an issue where platforms using AHO for content and application inspection run into dataplane process (all_pktproc) restarts.
## PAN-152253
Fixed an issue where the Destination NAT with **DNS Rewrite** enabled and set to **forward** did not work when the destination IP address was a single IP address instead of an IP range.
## PAN-152106
Fixed an issue where a process (genindex.sh) caused the management plane CPU usage to remain high for a longer period of time than expected.
## PAN-152027
Fixed an issue with URL Filtering where websites that were previously in the malicious category but have since been cleared remained in the malicious category in the dataplane cache. These websites were moved to the benign category only after you manually cleared the cache.
## PAN-152017
Fixed an issue where a VM-Series firewall on Amazon Web Services (AWS) failed on first reboot after enabling FIPS mode
## PAN-151692
Fixed a permission issue where a Panorama administrator was unable to download or install dynamic updates (**Panorama > Device Deployment**).
## PAN-151149
Fixed an issue where certificates, custom logos, and SAML metadata were unable to be uploaded from the web interface using a Chromium-based browser running version 84 or later.
## PAN-150613
Fixed an issue that caused a process (mprelay) to stop responding when committing changes in the Netflow Server Profile configuration (**Device > Server Profiles > Netflow**).
## PAN-150305
Fixed an issue where the output for show user ip-user-mapping-mp all, when called via XML API, was written to a file instead of returned via the API.
## PAN-149912
Fixed an issue where FIB entries were unexpectedly removed due to miscommunication between internal processes.
## PAN-149696
Fixed an intermittent issue where the GlobalProtect portal stopped responding with a 502 Bad Gateway response page when trying to access the portal URL using a web browser.
## PAN-149295
Fixed an issue where the Safe Search Block Page was visible for a few seconds when browsing HTTP2 websites, which resulted in latency when browsing.
## PAN-149248
Fixed an issue that prevented Panorama from pushing dynamic content to VM-Series firewalls configured with a pay-as-you-go (PAYG) license.
## PAN-149217
Fixed an issue where overridden TCP timeout values for service-based sessions did not take effect, and sessions timed out according to default application values.
## PAN-149054
Fixed an issue in Panorama where a commit-all to managed firewalls failed after renaming a device group.
## PAN-149006
Fixed an issue on VM-Series firewalls deployed on Google Cloud Platform (GCP) where traffic was backhauled after a reboot when the policy-based forwarding (PBF) enforced symmetric return with a next hop feature was enabled and interface IP addresses were learned via DHCP.
## PAN-149001
Fixed an issue where, when using certificate profiles configured under specific virtual systems (vsys), the GlobalProtect **Machine Certification Check** and **HIP Object** fail during a client certificate check.
## PAN-148441
Fixed an issue where required processes were not automatically restarted on the Log Processing Card (LPC) or the Log Forwarding Card (LFC).
## PAN-147847
Fixed an issue where traffic didn't hit the intended Security policy if SSL forward proxy was enabled and service was set to **application-default**.
## PAN-147796
Fixed an issue on the firewalls with an IPsec/Encapuslating Security Payload (ESP) traffic with GlobalProtect gateway configuration where multiple processes (flow_ctrl, pktlog_forwarding, and all_task) restarted, which caused the device to reboot.
## PAN-147529
Fixed an issue where **ValidateAll** jobs were incorrectly logged as **CommitAll** in the configuration log of the firewall.
## PAN-147305
Fixed an issue where a process (useridd) stopped responding to requests.
## PAN-147298
```caveat
PA-7050 and PA-7080 firewalls with 100G NPC only
```
Fixed an issue where jumbo frames brought down the Network Processing Card (NPC) when traffic traversed the firewall at a high rate.
## PAN-147130
Fixed an issue where user-to-IP address mapping that was redistributed between virtual systems (vsys) was not removed when the XML API unique identifier (UID) payload was set to timeout=Never.
## PAN-147036
Fixed an issue where TCP connections got stuck between the firewall and the Log Collector if some packets were dropped on the path between the two appliances.
## PAN-146763
Fixed a configuration issue on a multi-vsys where the configured interface service route for email schedule reports was not being used.
## PAN-146215
```caveat
FPP offload based hardware model only
```
Fixed an issue where, when UDP traffic that was received on a tunnel had back-to-back client-to-server packets, random packets dropped.
## PAN-145996
An update was made to change the following system log message: DO NOT CHOOSE WMI in Active-Directory FOR YOUR USE CASE IF SEE THIS LOG AGAIN IN <number> SECONDS to Please change server monitor(log server) Transport Protocol from WMI to WinRM for better performance. This update also reduces the severity from **High** to **Informational**.
## PAN-145524
Fixed an issue where **ACC > GlobalProtect Activity** on Panorama in management only mode with a dedicated log collector did not display any reports.
## PAN-145475
Fixed an issue where the firewall sent Bidirectional Forwarding Detection (BFD) packets with the final bit always set to on. With this fix, the final bit is cleared after the first response.
## PAN-145385
Fixed a rare issue where HTTP/2 sessions matched to an incorrect policy.
## PAN-145188
Fixed an issue on Panorama in PAN-DB mode where content updates did not successfully install, which caused the cloud state to degrade.
## PAN-144723
A new CLI command, debug proxy fast-session-delete enable yes, was added to better handle SSL-decrypted sessions where TCP port numbers were reused before the TIME_WAIT period expired.
## PAN-144410
Debug logs were added to detect an out-of-memory (OOM) condition that caused the management server to restart.
## PAN-143332
```caveat
PA-800 Series firewalls only
```
Fixed an issue where the deployment of the Master Key through the web interface failed.
## PAN-142867
Fixed an issue where service session timeout override was not used for custom applications and the default value was chosen instead.
## PAN-140492
Fixed an issue on the firewall where, with SSL forward proxy feature enabled, random file downloads over a decrypted session would stall or hang in the middle.
## PAN-139007
Fixed an issue where **URL Filtering** logs were misaligned when exported from the firewall due to the presence of a comma in the **User-Agent** field of the logs.
## PAN-138995
Fixed an issue where even after disabling **Tasks** in the web interface of an **Admin Role Profile**, the **Task Manager** panel appeared during a commit.
## PAN-138926
Fixed an issue where an improperly formatted GlobalProtect Portal from the CLI was able to be created, which prevented it from being seeing in the web interface.
## PAN-138573
Fixed an issue where the keyword **[Disabled]** was missing from the disabled policies exported in CSV/PDF format.
## PAN-137741
Fixed an issue where the data for a botnet report was deleted before the botnet report was completed.
## PAN-137671
Fixed an issue where testing and confirming server connections from **Panorama > Server profiles > HTTP > Test Server Connection** did not work.
## PAN-136652
```caveat
PA-3200 Series and PA-800 Series firewalls only
```
Fixed an issue where you were unable to disable auto negotiation on small form-factor pluggable (SFP) ports.
## PAN-135228
Fixed an issue where **Destination_Interface** (**Templates > Network > QoS > QoS Interface > Clear Text Traffic**) was not available when configuring QoS using the Panorama web interface.
## PAN-134909
Fixed an issue where region information was not called due to a mismatch in uppercase and lowercase letters in the region name.
## PAN-134840
Fixed an issue where pre-logon users failed authentication if the cookie was expired, instead of using certificate authentication.
## PAN-134467
Fixed an issue with the GlobalProtect portal where pre-logon authentication failed when agent Config Selection Critiera was configured on the firewall.
## PAN-134251
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where unplugging cables from Quad Small Form-factor Pluggable (QSFP) interfaces on 100G NPC causes path monitoring failures.
## PAN-133774
Fixed an issue where the **Logging Services Status** was incorrect. This was caused by the namespace of the daemons that were running not being updated correctly.
## PAN-133388
Fixed an issue where an HA configuration went out of sync when the HA sync job was queued and processed during an ongoing content installation job on the passive firewall.
## PAN-132055
Fixed an issue where a process (mgmtsrvr) was unresponsive when the number of active file descriptors was greater than 1024.
## PAN-132053
Added an enhancement to improve handling for firewall management web interface sessions that timeout so that the message Your session has expired does not display. Now, the web interface will present a timeout page that presents a button to redirect back to the login page.
## PAN-121484
Fixed an issue where the dataplane sent positive acknowledgments to predict-status checks from FPP when the corresponding predict was deleted, which caused SIP and RTSP applications to perform less than the expected achievable performance.
## PAN-110511
Fixed an issue where a passive Panorama appliance reported that device groups were out of sync despite a successful HA sync from the active Panorama appliance. This issue occurred when the address objects defined in the device group were in use under the corresponding template.
## PAN-109877
Fixed an issue where BGP flapped continuously with Jumbo Frames enabled on the firewall.
@@ -0,0 +1,337 @@
---
type: Addressed
product: PAN-OS
version: 9.1.8
---
## PAN-161121
Fixed an issue on the Panorama management server that caused invalid reference errors when attempting to delete an address object (**Objects > Addresses**) after removing the address object reference from an address group (**Objects > Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
## PAN-160376
Fixed an issue where, for local administrators using an authentication profile, the **save filter** (**Monitor > Logs**) option was grayed out.
## PAN-158650
Fixed an issue where several operations and processes stopped responding due to a deadlock issue between the CLI thread and the Terminal Server (TS) agent message processing the thread.
## PAN-158638
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
## PAN-158293
Fixed an issue where a sudden increase in packet buffer descriptors disrupted traffic.
## PAN-158122
Fixed an issue where SNMP readings reported 0 for dataplane interface packet statistics when using PacketMMAP mode. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
## PAN-157786
Fixed an issue where the **Device > Setup** page was blank after downgrading from a PAN-OS 10.0 release to a PAN-OS 9.1 release.
## PAN-157319
```caveat
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
```
Fixed an issue where GlobalProtect logs showed the incorrect client version and did not show event ID information.
## PAN-157168
Fixed an issue where a process (mprelay) stopped responding when displaying debug PDT commands
## PAN-157049
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the firewall processed internal path monitoring packets more slowly than expected when processing large amounts of traffic, which caused the dataplane to restart.
## PAN-156891
Fixed an issue where some zip files did not download and the following error message displayed: resources-unavailable.
## PAN-156716
Fixed an issue where the firewall sent ARP replies without checking the ingress interface when the requested IP address was configured as a destination NAT (DNAT) address.
## PAN-155665
Fixed an issue where, if an authentication profile was configured with an authorization type of **none**, users were inappropriately prompted for a password. Since the authentication type was set to **none**, any input was successful. This issue occurred when **Allow Authentication with User Credentials OR Client Certificate** was set to **no**.
## PAN-155326
Fixed an issue where the BGP **AS Number** template variable was not referenceable from the web interface.
## PAN-155294
Fixed an issue where iPad devices did not display Captive Portal multi-factor authentication (MFA) pages correctly when using Okta for push notifications.
## PAN-155124
Fixed an issue where IP address-to-username mapping did not correctly sync to the secondary active firewall in an active/active HA configuration if a logout and a log in event occurred within the same second.
## PAN-154899
Fixed an out-of-memory (OOM) issue on the firewalls that caused LACP, BGP, and OSPF to go down, resulting in the firewall not receiving LACPDU messages.
## PAN-154844
Fixed an issue where commits and autocommits repeatedly failed due to an OOM condition that disrupted the processes pan_task and devsrvr.
## PAN-154812
Fixed a memory leak issue related to a process (configd) that was caused by log queries filtering by address.
## PAN-154591
Fixed an issue where NULL users in panGlobalProtectGetConfig were not checked for before calling strcmp().
## PAN-154391
Fixed an issue where a Log Collector did not forward correlation logs to the syslog server over TCP.
## PAN-154365
Fixed an issue where Security policy rules targeted by tags incorrectly displayed as deleted when previewing commit changes.
## PAN-153814
Fixed an issue where the firewall displayed the URL Filtering Safe Search Block Page on the specific site only, even when the traffic was matched to a specific rule that did not have any URL filtering policies.
## PAN-153705
Fixed an issue where packets were not evenly distributed among a process (pan_tasks), which caused latency and poor performance.
## PAN-153631
Fixed an issue where the firewalls did not generate traffic logs for implicitly allowed applications.
## PAN-153614
Fixed an issue where user-based policies did not correctly match if the same user was included in both a policy with the username in NetBIOS format and another policy with the username in FQDN format.
## PAN-153294
Fixed an issue on the firewall where a GlobalProtect username authenticated via Kerberos was unnecessarily normalized to SAMAccountName format.
## PAN-153261
Fixed an issue where not all fragmented packets were transmitted, which caused increased packet buffer usage.
## PAN-152998
Fixed an issue where the User-ID process CPU usage remained high when a large number of Terminal Server (TS) agents were configured but only a few were connected.
## PAN-152813
Fixed an issue with configuration memory leaks on Panorama that caused a process (configd) to restart.
## PAN-152677
```caveat
VM-Series firewalls on Azure only
```
Fixed an issue where packet buffers showed high values when Data Plane Development Kit (DPDK) was enabled.
## PAN-152648
Fixed an issue where multiple all_pktproc processes stopped responding, which caused the dataplane to restart.
## PAN-152103
Fixed a memory leak issue where a process (dnsproxy) did not properly release memory after use.
## PAN-151997
Fixed an issue where the option to sinkhole was not displayed in the ACC filter drop-down (**ACC > Threat Activity > Global filters > Action**).
## PAN-151888
Fixed an issue where remote users were able to save log filters, which created a local user with the same username. With this fix, remote users cannot save a log filter.
## PAN-151808
Fixed an issue where an EDL refresh job did not complete when the configuration for EDL servers used certificate profiles, due to the large server certificates.
## PAN-151803
Fixed an issue on Panorama where commits failed when using device-id as a template variable.
## PAN-151503
Fixed an intermittent issue where memory was not fully freed after a Panorama commitAll completion on the firewall.
## PAN-151218
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the crashinfo file was not generated after a process (all_pktproc) stopped responding on the dataplane before path monitoring triggered a device reboot.
## PAN-150867
An enhancement was made to enable additional logging during kernel panic/oops that helps identify the cause.
## PAN-150798
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
## PAN-150534
Fixed an issue where authentication logs with the subtype SAML were not forwarded to the syslog server.
## PAN-150467
Fixed a memory leak issue with a unified query that caused a process (mprelay) to restart due to an OOM condition.
## PAN-150085
Fixed an issue where a process (configd) stopped responding which caused context switches to slow.
## PAN-150008
Fixed an issue on the firewall where configuring auto-tagging based on URL filtering logs resulted in tags being added to source IP addresses and not matching the log forwarding filter match criteria.
## PAN-149283
Fixed an issue where editing device log forwarding in the collector group then filtering specific firewalls and adding new firewalls caused the old firewalls to disappear from the log forwarding preferences list.
## PAN-148800
Fixed an issue where the firewall used port 1080 to reach dns.service.paloaltonetworks.com when web-proxy was configured.
## PAN-148549
Fixed an issue where newly created interface management profiles were unable to be linked to subinterfaces.
## PAN-148359
Fixed an issue where SD-WAN server-to-client symmetric return did not function correctly in certain circumstances. This issue intermittently affected path selection of parent/child applications, such as FTP.
## PAN-147254
jQuery was updated to 3.5.1.
## PAN-147221
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
## PAN-145733
Fixed an issue where the SNMP INDEX for panZoneTable on the PAN-COMMON-MIB.my file did not work as expected, which led to entries in panZoneTable not being uniquely identified.
## PAN-145417
Debug commands were added to address an issue where the firewall connect to Cortex Data Lake due to the Online Certificate Status Protocol (OSCP) message missing the nextUpdate value in the OSCP response.
## PAN-144975
Fixed an intermittent issue where a high traffic load in a Layer 2 deployment caused SNMP and Panorama health monitoring failures.
## PAN-144887
```caveat
Panorama virtual appliances in high availability (HA) configurations with VMware NSX plugin only
```
Fixed an issue where dynamic address group updates and configuration pushes failed when new plugins were installed or uninstalled, or when a process (configd) was restarted or reinitialized.
## PAN-144594
Fixed an issue where web pages failed to launch over clientless VPN when cookies had the expiry value set to 0 in the packet.
## PAN-143485
Fixed a memory leak issue related to a process (devsrvr).
## PAN-141813
Fixed an issue where multiple daemons restarted due to a management plane ARP overflow.
## PAN-140093
```caveat
PA-220 firewalls only
```
Fixed an issue where the master key was unable to be changed.
## PAN-137205
Fixed an issue where **Review Policies** did not show all related policies.
## PAN-136478
```caveat
PA-7000 Series firewalls
```
where syslog forwarding over TCP did not work in a multi-vsys environment.
## PAN-136073
Fixed an issue where the High Speed Chassis Interconnect (HSCI) port flapped continuously after an upgrade or reboot.
## PAN-134461
Fixed an issue where an admin user authenticated to Panorama with RADIUS and assigned a Device Group and Template Admin role using access domains was unable to add a managed firewall to Panorama and received the following error message: Import failed user <username> does not exist.
## PAN-133886
Fixed an issue where GlobalProtect users were unable to connect to mobile gateways when download of a large CRL failed due to timeouts that resulted in CRL check failures.
## PAN-133863
Fixed an issue where the Panorama Virtual Appliance in Log Collector mode went into maintenance mode due to a process (reportd) not responding.
## PAN-132035
Fixed an issue on Panorama appliances in an active/passive high availability configuration where a managed firewall generated high priority alerts that it failed to connect to the passive Panorama appliance's User-ID agent server. This issue occurred because the firewall was only able to connect to one Panorama User-ID server at a time, and it connected only to the active Panorama appliance's User-ID server.
## PAN-131462
Fixed an issue where the title page of PDF reports did not show the entire Palo Alto Networks logo.
## PAN-129927
```caveat
VM-Series firewalls only
```
Fixed an issue where firewalls with Layer 3 subinterfaces reset Class of Service (CoS) bits in 802.1q.
## PAN-120013
Fixed an issue where secure communication settings were incorrectly synchronized between Panorama appliances in an HA configuration.
## PAN-115494
Fixed an issue where the /opt/pancfg/ partition became full due to a configuration preview operation not responding.
## PAN-114351
Fixed an issue where SSL decryption slowed traffic with the TCP timestamp option enabled.
## PAN-113386
Fixed an issue where an address object with a tag that contained a space character inside quotation marks was not properly processed and assigned to the appropriate Dynamic Address Group.
## PAN-110962
Fixed an issue where a process (*all_pktproc*) stopped responding when SSH decryption was enabled, which caused the dataplane to restart.
## PAN-100693
Fixed an issue where you were unable to process Address Group match criteria when the match name included the double quotation ( " ) character.
@@ -0,0 +1,252 @@
---
type: Addressed
product: PAN-OS
version: 9.1.9
---
## PAN-165194
Fixed an issue where multiple messages were exchanged between secondary and primary Data Plane Development Kit (DPDK) processes, which caused a process (brdagent) to stop responding.
## PAN-164564
Fixed an issue where stats API attempted to get stats from an unavailable port.
## PAN-163538
Fixed an issue on multi-dataplane platforms where traffic through Large Scale VPN (LSVPN) tunnels dropped with the error message tunnel resolution failure.
## PAN-163164
Fixed an issue where the GlobalProtect client used IPv6 during gateway login but used IPv4 during IPsec tunnel creation, which caused it to fallback to SSL.
## PAN-162746
Fixed an issue where DNS over TCP caused a process (dnsproxy) to run out of memory.
## PAN-161745
Fixed an issue where the time-to-live (TTL) value received from the DNS server reset to 0 on DNS secure TCP transactions when anti-spyware profiles were used, which caused DNS dynamic updates to fail.
## PAN-160782
Fixed an issue where the routed process stopped responding when the BGP peer sent AS_PATHs with more than 255 AS numbers in all of the segments combined. There can now be a maximum of 255 AS numbers in an AS_PATH list for a prefix.
## PAN-160744
Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found.
## PAN-160455
Certain invalid URL entries contained in an External Dynamic List (EDL) cause a process (devsrvr) to stop responding ([CVE-2021-3048](https://security.paloaltonetworks.com/CVE-2021-3048)).
## PAN-160434
Fixed an issue where firewalls stopped processing Layer-3-tagged traffic after Panorama pushed VLAN sub-interface configurations to the firewall with the **commit_all** operation.
## PAN-159944
Fixed an issue where a process (dnsproxyd) stopped responding due to an error in the DNS cache operation.
## PAN-159826
Fixed an issue where SSL VPN leaked when the default browser feature on GlobalProtect was not enabled.
## PAN-159135
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
## PAN-158988
Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented.
## PAN-158844
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
## PAN-158774
Fixed an issue where random DNS queries dropped with the counter ctd_dns_wait_pkt_drop when DNS security was enabled.
## PAN-158723
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
## PAN-158328
Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups.
## PAN-158262
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)).
## PAN-158036
Fixed an issue on the firewall where custom application signatures based on PROPFIND http-method didn't trigger if webdav application ID was blocked by a Security policy.
To utilize this fix, you must install content version 8367-6513 or later.
## PAN-157735
Fixed an issue where the new PA-7000100G network processing card (NPC) took 25 minutes to start after rebooting the PA-7080 chassis.
## PAN-157721
Fixed an issue where the firewall dropped GPRS tunneling protocol (GTPv2) Create Session Requests and Responses that had IEs 201 and 202 with the error Abnormal GTPv2-C message with invalid IE.
## PAN-157346
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
## PAN-157271
Fixed an issue where **Panorama > Cloud Services** was visible to users with device group and template admin roles even if the admin role was disabled.
## PAN-156896
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall frequently stopped responding with the following log: CONFIG_UPDATE_INC : Incremental update to DP failed please try to commit force the latest config.
## PAN-156264
Fixed an issue where the firewall displayed **IP address** **Netmask** and **default gateway** as **unknown** on the web interface as well as the CLI.
## PAN-156225
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to later 9.1 releases and from PAN-OS 10.0.0 to PAN-OS 10.0.4.
## PAN-155656
Fixed an issue where multicast RTP traffic triggered unicast RTP Control Protocol (RTCP), and the predict session failed to install, which blocked the parent RTP session from forwarding packets.
## PAN-155147
```caveat
VM-Series firewalls on Microsoft Azure that use accelerated networking interfaces with DPDK mode
```
Fixed an issue where hot plug notifications caused traffic disruption.
## PAN-154557
Fixed an issue that caused a process (useridd) core dump when parsing the Subject Alternative Name from a client certificate sent in the HIP report.
## PAN-154403
Fixed an issue with HIP matching logic for missing patches where previous behavior indicated missing patches when no patches were missing.
## PAN-154376
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
## PAN-154195
Fixed an issue where the firewall dropped VoIP traffic over IPSec with counters flow_predict_convert_rtp_drop and flow_predict_convert_failed.
## PAN-153316
CLI commands were added to address an issue where virtual memory on a process (configd) exceeded the new 32G limit.
- To disable the virtual memory limit, use debug software disable-virt-limit.
- To enable the virtual memory limit, use debug software enable-virt-limit.
## PAN-153286
Fixed an issue on Panorama deployed on Amazon Web Services (AWS) where the Log Collector disk was on Admin disabled state when changing the instance type from m4 to m5.
## PAN-153213
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
## PAN-152497
Fixed an issue where the firewall was unable to create a new GTP-U session when it received Create Session Response messages, which caused the following error message to display in the GTP log: GTPv1 message failed stateful inspection.
## PAN-152458
```caveat
VM-Series firewalls on Microsoft Hyper-V only
```
Fixed an issue where, when upgrading to PAN-OS 9.0.8 or later, ethernet packets dropped after adding VLAN tags during egress from a subinterface. To leverage this fix, set the interface level maximum transmission unit (MTU) to 1496 or less.
## PAN-152003
Fixed an issue where an email client was unable to open an attached file due to removal of part of the file name encoded in UTF-8 by the firewall CTD function for SMTP and NAT sessions.
## PAN-151395
Fixed an issue where the firewall repeatedly logged connection failures to a configured Log Collector.
## PAN-150298
Fixed an issue where Android clients matched HIP objects configured for Apple products.
## PAN-150097
Fixed an issue where hourly URL summary log generation failed.
## PAN-150023
A fix was made to address an improper authentication vulnerability in PAN-OS that enabled a SAML authenticated attacker to impersonate any other user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
## PAN-149501
A fix was made to address a memory corruption vulnerability in the GlobalProtect Clientless VPN that enabled an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication ([CVE-2021-3056](https://security.paloaltonetworks.com/CVE-2021-3056)).
## PAN-147792
Fixed an issue where a process (configd) stopped responding due to a buffer overflow.
## PAN-147783
Checks were added to help prevent the dataplane from restarting.
## PAN-144538
Fixed an issue where locally disabling the rule hit-count feature on Panorama caused a memory leak.
## PAN-144470
Fixed an issue where driver descriptor rings were out of sync in the control plane to dataplane direction, which caused internal path monitoring heartbeat failures.
## PAN-142818
Fixed an issue where the management server restarted due to a telemetry buffer overflow that occurred when generated threat logs had specific signature flags set.
## PAN-142621
Fixed an issue where the firewall was unable to log debug information in case of kernel panic.
## PAN-142473
Fixed an issue where a commit failed with the following error message: Disk quotas add up to more than 100%. Invalid configuration. due to an integration issue.
## PAN-136347
Fixed an issue wherer DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
## PAN-134799
Fixed an issue where packets of the same session were forwarded through a different member of an Aggregate Ethernet (AE) group once the session was offloaded.
## PAN-120423
Support was added for XML API for GlobalProtect logs.
## PAN-113795
Fixed an issue on a firewall configured with GlobalProtect Clientless VPN where a process (*all_pkts*) stopped responding, which caused the dataplane to restart.
## PAN-110429
Fixed an issue with firewalls in a high availability configuration where multiple all_pktproc processes stopped responding due to missing heartbeats, which caused service outages.
@@ -0,0 +1,498 @@
---
type: Known
product: PAN-OS
version: 9.1.13
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-221015
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
`admin>``debug elasticsearch es-restart optional all`
Code copied to clipboard
Unable to copy due to lack of browser support.
Copy
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-186937
```caveat
This issue is now resolved. See PAN-OS 9.1.14 Addressed Issues.
```
The firewall drops Encapsulating Security Payload (ESP) IPsec packets that originate from the same firewall. This behavior occurs when you enable **Strict IP Address Check** in the Zone Protection profile (Packet Based Attack Protection tab, IP Drop section) and the packets source IP address is the same as the egress interface address.
**Workaround**: Disable the **Strict IP Address Check** option in the Zone Protection profile. Alternatively, downgrade to 9.1.11 or earlier or upgrade to 10.0.0 or later if you want to enable the **Strict IP Address Check**.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,512 @@
---
type: Known
product: PAN-OS
version: 9.1.14
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-221015
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
`admin>``debug elasticsearch es-restart optional all`
Code copied to clipboard
Unable to copy due to lack of browser support.
Copy
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197919
```caveat
This issue is now resolved. See PAN-OS 9.1.16 Addressed Issues.
```
When path monitoring for a static route is configured with a new Ping Interval value, that value does not get used as intended.
**Workaround**: Disable and re-enable path monitoring for that static route to change that Ping Interval value.
## PAN-197859
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-194395
```caveat
This issue is now resolved. See PAN-OS 9.1.14-h1 Addressed Issues.
```
The firewall drops all decrypted outbound (SSL Forward Proxy) HTTP/2 traffic after you upgrade to PAN-OS 9.1.14. Dropping this traffic prevents users from loading HTTP/2 web pages and accessing websites that use HTTP/2.
**Workaround**: On the SSL Forward Proxy tab in the Decryption profile attached to the Decryption Policy rule that controls the HTTP/2 traffic, select **Strip ALPN**. When you **Strip ALPN**, the firewall negotiates HTTP/1.1 instead of HTTP/2.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,486 @@
---
type: Known
product: PAN-OS
version: 9.1.19
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-221015
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
`admin>``debug elasticsearch es-restart optional all`
Code copied to clipboard
Unable to copy due to lack of browser support.
Copy
## PAN-197859
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,552 @@
---
type: Known
product: PAN-OS
version: 9.1.4
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151909
```caveat
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
```
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
## PAN-148359
```caveat
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
```
SD-WAN server-to-client symmetric return does not function correctly under certain circumstances, and the issue can also affect path selection of parent/child applications, such as FTP.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-140084
```caveat
This issue is now resolved. See PAN-OS 9.1.5 Addressed Issues.
```
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-121484
```caveat
This issue is now resolved. See PAN-OS 9.1.6 Addressed Issues.
```
The dataplane sends positive acknowledgments to predict-status checks from FPP when the corresponding predict is deleted, which causes SIP and RTSP applications to perform less than the expected achievable performance.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120423
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-103018
```caveat
Panorama plugins
```
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
+21 -2
View File
@@ -407,8 +407,15 @@
"9.1.0_2026-03-16.md", "9.1.0_2026-03-16.md",
"9.1.1_2026-03-16.md", "9.1.1_2026-03-16.md",
"9.1.2_2026-03-16.md", "9.1.2_2026-03-16.md",
"9.1.2-h1_2026-03-31.md",
"9.1.3_2026-03-16.md", "9.1.3_2026-03-16.md",
"9.1.3-h1_2026-03-31.md",
"9.1.4_2026-03-31.md",
"9.1.5_2026-03-31.md",
"9.1.6_2026-03-31.md",
"9.1.7_2026-03-16.md", "9.1.7_2026-03-16.md",
"9.1.8_2026-03-31.md",
"9.1.9_2026-03-31.md",
"9.1.10_2026-03-16.md", "9.1.10_2026-03-16.md",
"9.1.11_2026-03-16.md", "9.1.11_2026-03-16.md",
"9.1.11-h2_2026-03-16.md", "9.1.11-h2_2026-03-16.md",
@@ -418,25 +425,34 @@
"9.1.12_2026-03-16.md", "9.1.12_2026-03-16.md",
"9.1.12-h3_2026-03-16.md", "9.1.12-h3_2026-03-16.md",
"9.1.12-h4_2026-03-16.md", "9.1.12-h4_2026-03-16.md",
"9.1.12-h6_2026-03-31.md",
"9.1.12-h7_2026-03-16.md", "9.1.12-h7_2026-03-16.md",
"9.1.13_2026-03-31.md",
"9.1.13-h1_2026-03-16.md", "9.1.13-h1_2026-03-16.md",
"9.1.13-h3_2026-03-16.md", "9.1.13-h3_2026-03-16.md",
"9.1.13-h4_2026-03-16.md", "9.1.13-h4_2026-03-16.md",
"9.1.13-h5_2026-03-31.md",
"9.1.14_2026-03-16.md", "9.1.14_2026-03-16.md",
"9.1.14-h1_2026-03-16.md", "9.1.14-h1_2026-03-16.md",
"9.1.14-h4_2026-03-16.md", "9.1.14-h4_2026-03-16.md",
"9.1.14-h7_2026-03-16.md", "9.1.14-h7_2026-03-16.md",
"9.1.14-h8_2026-03-16.md", "9.1.14-h8_2026-03-16.md",
"9.1.15_2026-03-16.md", "9.1.15_2026-03-16.md",
"9.1.15-h1_2026-03-31.md",
"9.1.16_2026-03-16.md", "9.1.16_2026-03-16.md",
"9.1.16-h3_2026-03-16.md", "9.1.16-h3_2026-03-16.md",
"9.1.16-h4_2026-03-31.md",
"9.1.16-h5_2026-03-16.md", "9.1.16-h5_2026-03-16.md",
"9.1.17_2026-03-16.md" "9.1.17_2026-03-16.md",
"9.1.17-h1_2026-03-31.md",
"9.1.18_2026-03-31.md",
"9.1.19_2026-03-31.md"
], ],
"known": [ "known": [
"9.1.1_2026-03-16.md", "9.1.1_2026-03-16.md",
"9.1.2_2026-03-16.md", "9.1.2_2026-03-16.md",
"9.1.3_2026-03-16.md", "9.1.3_2026-03-16.md",
"9.1.4_2026-03-31.md",
"9.1.5_2026-03-16.md", "9.1.5_2026-03-16.md",
"9.1.6_2026-03-16.md", "9.1.6_2026-03-16.md",
"9.1.7_2026-03-16.md", "9.1.7_2026-03-16.md",
@@ -445,10 +461,13 @@
"9.1.10_2026-03-16.md", "9.1.10_2026-03-16.md",
"9.1.11_2026-03-16.md", "9.1.11_2026-03-16.md",
"9.1.12_2026-03-16.md", "9.1.12_2026-03-16.md",
"9.1.13_2026-03-31.md",
"9.1.14_2026-03-31.md",
"9.1.15_2026-03-16.md", "9.1.15_2026-03-16.md",
"9.1.16_2026-03-16.md", "9.1.16_2026-03-16.md",
"9.1.17_2026-03-16.md", "9.1.17_2026-03-16.md",
"9.1.18_2026-03-16.md" "9.1.18_2026-03-16.md",
"9.1.19_2026-03-31.md"
] ]
}, },
"9.0": { "9.0": {