Initial prototype
This commit is contained in:
@@ -1,2 +1,4 @@
|
||||
# firewallissues
|
||||
An alternative view of issues documented by our favorite firewall vendor
|
||||
|
||||
Inspired by (https://www.reddit.com/user/Pixi888/)[Pixi888's] creation (https://bugidsearch.com/)[bugidsearch.com].
|
||||
@@ -0,0 +1,177 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.1
|
||||
---
|
||||
|
||||
## GPC-21022
|
||||
|
||||
Fixed an issue where the GlobalProtect re-authentication prompt appeared in the background instead of the foreground after deploying Okta FastPass.
|
||||
|
||||
## GPC-20895
|
||||
|
||||
Fixed an issue where a macOS GlobalProtect app user was able to modify or add a new portal even though the portal agent configuration specified Allow User to Change Portal Address = NO and Allow user to Sign Out from GlobalProtect App = No .
|
||||
|
||||
## GPC-20864
|
||||
|
||||
Fixed an issue where the GlobalProtect embedded browser login window did not stay pinned to the front of all open windows on Windows and MAC computers.
|
||||
|
||||
## GPC-20839
|
||||
|
||||
Fixed an issue where a macOS user was unable to connect to the GlobalProtect app.
|
||||
|
||||
## GPC-20722
|
||||
|
||||
Fixed an issue in the GlobalProtect macOS client where the UI incorrectly displayed a "Not Connected" status and a "Connect" button while the user was in the process of connecting to a new gateway.
|
||||
|
||||
## GPC-20645
|
||||
|
||||
Fixed an issue where the GlobalProtect macOS app was stuck in connecting stage when the macOS computer woke from sleep and the user had to restart the computer.
|
||||
|
||||
## GPC-20601
|
||||
|
||||
Fixed an issue where users unable to connect to GlobalProtect after upgrading from version 6.2.2 to 6.2.3 via JAMF.
|
||||
|
||||
## GPC-20595
|
||||
|
||||
Fixed an issue where GlobalProtect users were unable to connect after upgrading to 6.2.3-270 and received a Y our internet access is blocked error during SAML authentication using the embedded browser.
|
||||
|
||||
## GPC-20527
|
||||
|
||||
Fixed an issue where the Conditional Connect method configured for the GlobalProtect app did not work as expected when the user shifted from external network (home) to an internal network (office). Users had to reboot the system to resolve this issue.
|
||||
|
||||
## GPC-20463
|
||||
|
||||
Fixed an issue where the GlobalProtect status panel is not disabled at startup when the Display Status Panel at Startup parameter is set to no.
|
||||
|
||||
## GPC-20442
|
||||
|
||||
Fixed an issue on appliances running PanOS 10.1.11-h1 and GlobalProtect 6.0.10-811 where the tunnel status failed to update to connected immediately after establishment. This problem was specific to IPv4-only clients connecting to dual-stack (IPv4 + IPv6) GlobalProtect gateways or portals.
|
||||
|
||||
## GPC-20427
|
||||
|
||||
Fixed an issue where the GlobalProtect client on Windows 11 devices displayed an error message "The parameter is incorrect" when attempting to connect to a firewall running PAN-OS 10.1.13 with SAML authentication enabled.
|
||||
|
||||
## GPC-20374
|
||||
|
||||
Fixed an issue where users were unable to connect to GlobalProtect if they accidentally clicked decline on the Terms of Service page.
|
||||
|
||||
## GPC-20157
|
||||
|
||||
Fixed an issue where the gateway location was not correctlydisplayed in the Connections panel.
|
||||
|
||||
## GPC-20143
|
||||
|
||||
Fixed an issue where the user was redirected to the Authentication page twice on the default browser for both portal and gateway authentication when SAML was configured.
|
||||
|
||||
## GPC-20114
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the certificate information was incorrect during the portal login phase causing authentication failure.
|
||||
|
||||
## GPC-20112
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected Real time protection status for Kaspersky Endpoint Security, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-20091
|
||||
|
||||
Fixed an issue where pre-logon failed when the computer was rebooted, when the machine store had an expired and active certificate.
|
||||
|
||||
## GPC-20080
|
||||
|
||||
Fixed an issue where the GlobalProtect logs displayed different event messages for Windows and macOS devices when the Allow User to Disable GlobalProtect App was set to Allow with Passcode for the GlobalProtect app.
|
||||
|
||||
## GPC-20060
|
||||
|
||||
Fixed an issue where it was possible for the GlobalProtect enforcer to be disabled when there was a network change during portal authentication.
|
||||
|
||||
## GPC-20040
|
||||
|
||||
Fixed an issue where GlobalProtect did not re-check for internal gateways when using cached portal configuration and an external network was previously detected.
|
||||
|
||||
## GPC-19991
|
||||
|
||||
Fixed an issue where client certificate authentication between embedded browser and IdP (SAML) fails.
|
||||
|
||||
## GPC-19966
|
||||
|
||||
Fixed an issue where the embedded browser was unable to load the Microsoft IdP login page for the users to authenticate to the GlobalProtect app.
|
||||
|
||||
## GPC-19901
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the app got disconnected and reconnected intermittently.
|
||||
|
||||
## GPC-19889
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows machine and Connect Before Logon (CBL) was configured for the app, the app did not start properly when the user logged on to the device.
|
||||
|
||||
## GPC-19840
|
||||
|
||||
Fixed an issue where Mac computers did not display all gateways in the Search Gateway tab.
|
||||
|
||||
## GPC-19833
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices, the Smart card (Yubikey) authentication did not work when the device woke up from sleep mode.
|
||||
|
||||
## GPC-19753
|
||||
|
||||
Fixed an issue where the GlobalProtect icon could not be selected using the keyboard.
|
||||
|
||||
## GPC-19751
|
||||
|
||||
Fixed an issue where the programmatic and visual label for the GlobalProtect form field was not announced.
|
||||
|
||||
## GPC-19686
|
||||
|
||||
Fixed an issue where translation errors were observed in the GlobalProtect app for French localization.
|
||||
|
||||
## GPC-19659
|
||||
|
||||
Fixed an issue where macOS users were connected to the GlobalProtect app before they agreed to their company’s terms of service.
|
||||
|
||||
## GPC-19513
|
||||
|
||||
Fixed an issue where the GlobalProtect app was trying to use the old portal's authorization cookie to login instead of the newly migrated portal. This happened when the user changed from secondary portal to primary portal or vice versa without signing out.
|
||||
|
||||
## GPC-19475
|
||||
|
||||
Fixed an issue where users got connection errors in an embedded browser after the computer woke up from sleep or when the user switched gateways.
|
||||
|
||||
## GPC-19433
|
||||
|
||||
Fixed an issue where a small white blank page randomly popped up on the device screen distracting the users. This issue occurred while the device was connected to GlobalProtect app.
|
||||
|
||||
## GPC-19373
|
||||
|
||||
Fixed an issue where the HIP remediation pop up is displayed even when the user is disconnected.
|
||||
|
||||
## GPC-18991
|
||||
|
||||
Fixed an issue where the proxy auto-configuration (PAC) files were not restored as expected after a system reboot or when the user disconnected the GlobalProtect app.
|
||||
|
||||
## GPC-18728
|
||||
|
||||
Fixed an issue where the ‘I Agree’ option on the GlobalProtect app Welcome page did not work as expected when the user selected the option using a keyboard.
|
||||
|
||||
## GPC-18702
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices, the “Allow Manually upgrade failed when the user tried to upgrade the GlobalProtect app version from 6.0.5 to 6.0.7.
|
||||
|
||||
## GPC-18647
|
||||
|
||||
Fixed an issue where the user reported an issue using the Report an Issue option on the GlobalProtect app and the issue was not reported as expected.
|
||||
|
||||
## GPC-17820
|
||||
|
||||
Fixed an issue where Firefox was not supported for proxied traffic in Tunnel and Proxy mode or proxy mode.
|
||||
|
||||
## GPC-17727
|
||||
|
||||
Fixed an issue where when the GlobalProtect app was connected in Tunnel and Proxy mode or proxy mode, SSH traffic could not be sent over the proxy.
|
||||
|
||||
## GPC-16975
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the screen reader did not announce the name of the GlobalProtect gateway when the gateway was marked with the star symbol.
|
||||
|
||||
## GPC-15750
|
||||
|
||||
Fixed an issue where a hyperlink in a HIP notification opened in the GPO-disabled Internet Explorer 11 browser instead of the default browser.
|
||||
@@ -0,0 +1,191 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.2
|
||||
---
|
||||
|
||||
## GPC-22087
|
||||
|
||||
Fixed an issue where the GlobalProtect app was unable to validate the certificate from OCSP.
|
||||
|
||||
## GPC-22080
|
||||
|
||||
Fixed an issue where the OCSP requests were being rejected by the OCSP responder with a HTTP 400 Bad Request error due to the absence of the Host header in the OCSP request.
|
||||
|
||||
## GPC-21938
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app version 6.3.x was installed on devices running macOS, the HIP check failed to detect ESET Endpoint Security version 8.
|
||||
|
||||
## GPC-21918
|
||||
|
||||
Fixed an issue where, when the patch management category was excluded for HIP checks, HIP checks were still happening for missing patches which consumed CPU resources on users' machine.
|
||||
|
||||
## GPC-21838
|
||||
|
||||
Fixed an issue in which the GlobalProtect app, when installed on Windows devices, caused a duplicate page to open in the system default browser (Chrome) when the user clicked the hyperlink on the Welcome page with fedmandate on the embedded browser.
|
||||
|
||||
## GPC-21836
|
||||
|
||||
Fixed an issue in GlobalProtect 6.3.1 for macOS where the Refresh Connection option was missing during the Connecting state, specifically for users who upgraded from version 6.3.0.
|
||||
|
||||
## GPC-21778
|
||||
|
||||
Fixed an issue where the GlobalProtect IPSec tunnel got disconnected on GlobalProtect app version 6.2.5 when gpupdate /force command was used to update policy.
|
||||
|
||||
## GPC-21774
|
||||
|
||||
Fixed an issue where the GlobalProtect ARM64 installers for 6.2.5 version did not display the Digital Signatures tab.
|
||||
|
||||
## GPC-21771
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected Malware Definition Date for Trend Micro Deep Security Agent, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21733
|
||||
|
||||
Fixed an issue where all the added portals got deleted from the portal list except the connected portal when the GlobalProtect app was upgraded from version 6.2.4 to 6.2.5-788. Users had to manually add them again to resolve the issue.
|
||||
|
||||
## GPC-21604
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and were connected to the internal gateway, the app did not display the Disconnect option under Settings.
|
||||
|
||||
## GPC-21571
|
||||
|
||||
Fixed an issue where the hyperlink in HIP notification opened up in Webview2 instead of the default browser.
|
||||
|
||||
## GPC-21565
|
||||
|
||||
Fixed an issue where the SAML embedded browser did not remember the username after sign-out, even when the user had selected the check box Remember Me on the SAML embedded browser.
|
||||
|
||||
## GPC-21542
|
||||
|
||||
Fixed an issue where GlobalProtect got stuck in connecting and failed the connection after some time.
|
||||
|
||||
## GPC-21443
|
||||
|
||||
Fixed an issue where GlobalProtect crashed when the PanGPS service was stopped.
|
||||
|
||||
## GPC-21414
|
||||
|
||||
Fixed an issue where the SAML authentication page would occasionally fail to appear due to the usage of a previous SAML pre-login cookie.
|
||||
|
||||
## GPC-21399
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the HIP check for the built-in firewall shows N/A incorrectly.
|
||||
|
||||
The value should be either Yes or No.
|
||||
|
||||
## GPC-21370
|
||||
|
||||
Fixed an issue where the HIP check could not detect Trellix Firewall Status, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21332
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected Real Time Protection status for Avast and XProtect, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21320
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect Kaspersky Endpoint Security antimalware application which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21301
|
||||
|
||||
Fixed an issue where, when the user upgraded the GlobalProtect app version to 6.2.4 with SAML authentication, users were unable to connect to GlobalProtect intermittently when Enforcer is enabled.
|
||||
|
||||
## GPC-21247
|
||||
|
||||
Fixed an issue where GlobalProtect HIP set the Filevault encryption status to unencrypted on macOS running devices, which denied access to the end-point machines.
|
||||
|
||||
## GPC-21222
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check incorrectly detected the Real Time Protection Status and Last Full Scan for Avast application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21206
|
||||
|
||||
Fixed an issue where the GlobalProtect service exited when the user logs off or put the computer in sleep mode.
|
||||
|
||||
## GPC-21174
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect Real time protection status for Acronis Cyber Protection Agent, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21130
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect app failed to reconnect and continued to stay in the Connecting state after the device woke up from Modern Standby mode.
|
||||
|
||||
## GPC-21106
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP check did not detect Real Time Protection status for Malwarebytes antimalware application, which caused the device to fail the HIP check.
|
||||
|
||||
## GPC-21043
|
||||
|
||||
Fixed an issue where the GlobalProtect app got stuck in connecting stage after authentication when the app was upgraded to 6.2.4 version.
|
||||
|
||||
## GPC-20983
|
||||
|
||||
Fixed an issue where the GlobalProtect app was installed on devices running macOS, the GlobalProtect got stuck in Connecting state when the device woke up from sleep mode.
|
||||
|
||||
## GPC-20967
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed with the Conditional Connect method, users had to click the Connect button twice to connect to an external gateway after a system reboot.
|
||||
|
||||
## GPC-20943
|
||||
|
||||
Fixed an issue where the GlobalProtect enforcer blocked DHCP packets.
|
||||
|
||||
## GPC-20838
|
||||
|
||||
Fixed an issue where the HIP report was not completed within the allowed time.
|
||||
|
||||
## GPC-20807
|
||||
|
||||
Fixed an issue where the HIP report for Symantec Encryption Desktop shows the encryption state as unencrypted.
|
||||
|
||||
## GPC-20779
|
||||
|
||||
Fixed an issue where Windows regional settings were not respected by Webview 2 on SAML embedded browser resulting in regional language(French, German, Chinese, Spanish, and Japanese) not loading properly in embedded browser.
|
||||
|
||||
## GPC-20700
|
||||
|
||||
Fixed an issue where macOS users had to enter the SAML username and password each time they refreshed or rebooted their computer. This issue occurred more frequently when they used Safari as the default browser or used the embedded browser.
|
||||
|
||||
## GPC-20674
|
||||
|
||||
Fixed an issue where all GlobalProtect portals except for the currently connected portal were deleted during the upgrade from 6.2.2 to 6.2.3 or from 6.2.3 to 6.3.0.
|
||||
|
||||
## GPC-20492
|
||||
|
||||
Fixed an issue where the PanGPS process crashed due to exception code 0xC0000374.
|
||||
|
||||
## GPC-20466
|
||||
|
||||
Fixed an issue where the tunnel gets broken during modern standby when using Enforce GlobalProtect for Network Access and the enforcer gets re-enabled only after the user resumes working on the computer.
|
||||
|
||||
## GPC-20441
|
||||
|
||||
Fixed an issue where HIP reports are sometimes not available on the firewall for newly connected users.
|
||||
|
||||
## GPC-20322
|
||||
|
||||
Fixed an issue where users were unable to install GlobalProtect 6.2 on windows 11 ARM64 devices.
|
||||
|
||||
## GPC-20191
|
||||
|
||||
Fixed an issue where the PanGPA executable version 6.1.2.83 did not work as expected on Windows devices.
|
||||
|
||||
## GPC-20168
|
||||
|
||||
Fixed an issue where it was possible to do a privilege escalation and\or login bypass when using a 3rd party credential provider with GlobalProtect.
|
||||
|
||||
## GPC-18943
|
||||
|
||||
Fixed an issue where when Endpoint Traffic enforcement feature was enabled, certain traffic was going through the physical adapter and not getting blocked as per the rules set.
|
||||
|
||||
## GPC-18695
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app version 6.0.7 was installed on devices running macOS, the "Allow with Passcode option did not work as expected when the user tried to disable the GlobalProtect app with the configured passcode.
|
||||
|
||||
## GPC-18671
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect macOS install package created an unused /Library/Application folder.
|
||||
|
||||
## GPC-18452
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on Windows devices, the app did not start right away after a system reboot.
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.3-h1
|
||||
---
|
||||
|
||||
## GPC-23277
|
||||
|
||||
Fixed an issue where the GlobalProtect macOS client intermittently experienced connection timeouts while browsing the internet in proxy mode (when disconnected from the VPN tunnel). Ping operations were successful, but website access through a browser was slow or failed.
|
||||
|
||||
## GPC-23237
|
||||
|
||||
Fixed an issue where the GlobalProtect macOS client restarted on opening a zoom session in transparent proxy mode.
|
||||
|
||||
## GPC-23215
|
||||
|
||||
Fixed an issue where the traffic stopped passing through the GlobalProtect app on macOS devices after upgrading to GP 6.2.8 and when the computer screen was locked.
|
||||
|
||||
## GPC-23161
|
||||
|
||||
Fixed an issue where the GlobalProtect app stopped working after a session change.
|
||||
|
||||
## GPC-23139
|
||||
|
||||
Fixed an issue where, after a disconnection event, the GlobalProtect agent could not connect to either the transparent proxy or the IPsec tunnel until the client device was rebooted.
|
||||
|
||||
## GPC-23117
|
||||
|
||||
Fixed an issue where after installing GlobalProtect on macOS devices, the host ID displayed the device's MAC address instead of the UID, and the GlobalProtect agent icon flickered.
|
||||
|
||||
## GPC-23077
|
||||
|
||||
Fixed an issue where HIP reports were not sent to the GlobalProtect gateway when transparent proxy is enabled, resulting in rules not being matched.
|
||||
|
||||
## GPC-22777
|
||||
|
||||
Fixed an issue where GlobalProtect entered proxy mode after the computer woke from sleep but failed to apply the configured proxy settings, resulting in a lost proxy connection.
|
||||
@@ -0,0 +1,359 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: GlobalProtect
|
||||
version: 6.3.3
|
||||
---
|
||||
|
||||
## GPC-23046
|
||||
|
||||
Fixed an issue where users experienced connectivity problems when GlobalProtect was used in a WiFi network with captive portal.
|
||||
|
||||
## GPC-23010
|
||||
|
||||
Fixed an issue where HIP checks incorrectly detected the macOS built-in firewall as disabled, causing HIP checks to fail.
|
||||
|
||||
## GPC-22847
|
||||
|
||||
Fixed an issue where GlobalProtect did not detect Qualys for patch management.
|
||||
|
||||
## GPC-22771
|
||||
|
||||
Fixed an issue where the Host Information Profile (HIP) check failed to detect the installed version of Norton anti-malware.
|
||||
|
||||
## GPC-22763
|
||||
|
||||
Fixed an issue where GlobalProtect prompted for credentials instead of using authoverride cookie when authenticating to the best available gateway.
|
||||
|
||||
## GPC-22740
|
||||
|
||||
Fixed an issue where macOS computers displayed both the new and old versions of the GlobalProtect welcome page.
|
||||
|
||||
## GPC-22688
|
||||
|
||||
Fixed an issue for proxy-only mode where customers were unable to access websites when the computer woke up from sleep
|
||||
|
||||
## GPC-22638
|
||||
|
||||
Fixed an issue where Global Protect HIP did not detect the drive state when using Trellix Drive Encryption 8.0.
|
||||
|
||||
## GPC-22616
|
||||
|
||||
Fixed an issue where the Digital Guardian Agent was not detected by the GlobalProtect client, causing DLP HIP checks to fail.
|
||||
|
||||
## GPC-22610
|
||||
|
||||
Fixed an issue where, after an upgrade, GlobalProtect restarted and failed to connect to the portal
|
||||
|
||||
## GPC-22589
|
||||
|
||||
Fixed an issue where the Report an Issue functionality did not send the troubleshooting log to the administrator’s Strata Logging Service instance.
|
||||
|
||||
## GPC-22547
|
||||
|
||||
Fixed an issue where the installed OWSPAT version was not supported with the CrowdStrike Falcon version, resulting in HIP object match failures.
|
||||
|
||||
## GPC-22544
|
||||
|
||||
Fixed an issue where the GlobalProtect client did not send the HIP report causing user-IP mapping to be cleared and resulting in traffic drop.
|
||||
|
||||
## GPC-22542
|
||||
|
||||
Fixed an issue where the embedded browser shown as part of SAML authentication was blank.
|
||||
|
||||
## GPC-22487
|
||||
|
||||
Fixed an issue where Norton 360 was not compatible with GlobalProtect causing the device to fail the HIP check.
|
||||
|
||||
## GPC-22450
|
||||
|
||||
Fixed an issue where users were unable to use smartcard authentication with embedded browser.
|
||||
|
||||
## GPC-22448
|
||||
|
||||
Fixed an issue where the GlobalProtect client could crash after it was connected to a gateway.
|
||||
|
||||
## GPC-22443
|
||||
|
||||
Fixed an issue where the GlobalProtect agent showed as connected even when the virtual adapter was down.
|
||||
|
||||
## GPC-22406
|
||||
|
||||
Fixed an issue where the GlobalProtect credential provider was not set as the default after installation and reboot.
|
||||
|
||||
## GPC-22381
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report did not include Cortex XDR installed on the client machine.
|
||||
|
||||
## GPC-22353
|
||||
|
||||
Fixed an issue where a comment was not visible in the GlobalProtect logs when GlobalProtect was disabled with-comment.
|
||||
|
||||
## GPC-22297
|
||||
|
||||
Fixed an issue where the Customer was getting "A valid client certificate is required for authentication" even though they had a valid client certificate installed.
|
||||
|
||||
## GPC-22295
|
||||
|
||||
Fixed an issue where GlobalProtect client for macOS could not navigate away from a hyperlink on the welcome page when the welcome page was opened in the embedded browser.
|
||||
|
||||
## GPC-22264
|
||||
|
||||
Fixed an issue where the GlobalProtect HIP report did not detect the last full scan time for Avast antivirus software.
|
||||
|
||||
## GPC-22245
|
||||
|
||||
Fixed an issue where transparent upgrade from GlobalProtect version 6.2.4 or 6.2.5 to version 6.2.6 failed on some Windows endpoints with error 1618.
|
||||
|
||||
## GPC-22237
|
||||
|
||||
Fixed an issue where GlobalProtect shut down unexpectedly on Windows 11 devices running multiple versions of GlobalProtect 6.3. The issue was caused by the firewall sending invalid IPv6 packets to GlobalProtect, which did not have a validation method before processing.
|
||||
|
||||
## GPC-22235
|
||||
|
||||
Fixed an issue where users were unable to connect to the app after the system woke up from sleep mode.
|
||||
|
||||
## GPC-22233
|
||||
|
||||
Fixed an issue where the users were unable to connect the GlobalProtect app after performing the resolution of CVE-2024-5921. The app displayed the following error, “The certificate CN name mismatch.”
|
||||
|
||||
## GPC-22155
|
||||
|
||||
Fixed an issue where the GlobalProtect app got stuck in the Connecting stage when the app was upgraded to 6.3.2-525 version. Users had to reboot the system to resolve this issue.
|
||||
|
||||
## GPC-22126
|
||||
|
||||
Fixed an issue where GlobalProtect version 6.2.6-838 was stuck intermittently during the connection process.
|
||||
|
||||
## GPC-22123
|
||||
|
||||
Fixed an issue where the GlobalProtect app got stuck and users faced connection issues after the system woke up from sleep mode even though the internet connection was stable.
|
||||
|
||||
## GPC-22092
|
||||
|
||||
Fixed an issue where the GlobalProtect app failed to validate the server certificate when the portal or gateway sent only the leaf certificate.
|
||||
|
||||
## GPC-22061
|
||||
|
||||
Fixed an issue where the GlobalProtect client displayed an error when using an ECDSA certificate with explicit EC parameters in FIPS mode.
|
||||
|
||||
## GPC-22054
|
||||
|
||||
Fixed an issue where after GlobalProtect was upgraded from version 6.3.0 to 6.3.1, users were stuck in connecting state.
|
||||
|
||||
## GPC-22046
|
||||
|
||||
Fixed an issue where when the GlobalProtect app was installed on devices running macOS and the app version was upgraded to 6.2.5, end users were unable to connect the app. The app got stuck in the Connecting state and displayed the following message, “You are redirected to an embedded browser to authenticate and connect.”
|
||||
|
||||
## GPC-22043
|
||||
|
||||
Fixed an issue where Okta push notification shows incorrect Windows OS, when Okta SAML authentication is enabled in GlobalProtect.
|
||||
|
||||
## GPC-22028
|
||||
|
||||
Fixed an issue where the disconnect reason for macOS users was getting cached.
|
||||
|
||||
## GPC-21988
|
||||
|
||||
Fixed an issue where the GlobalProtect Client displayed a download prompt or was updated even with an "upgrade disallow" configuration.
|
||||
|
||||
## GPC-21960
|
||||
|
||||
Fixed an issue where the HIP check failed to detect the Norton anti-malware version 24.11.9615.0.
|
||||
|
||||
## GPC-21955
|
||||
|
||||
Fixed an issue where the HIP notification pop-up on macOS looked different from that on Windows.
|
||||
|
||||
## GPC-21950
|
||||
|
||||
Fixed an issue where the GlobalProtect connection on MacOS Sequoia 15+ was unstable.
|
||||
|
||||
## GPC-21857
|
||||
|
||||
Fixed an issue where, when the GlobalProtect debug build was installed on the device, the device was immediately locked and users were unable to enter their login credentials in the Window Login screen. Users had to reboot their system to resolve this issue.
|
||||
|
||||
## GPC-21775
|
||||
|
||||
Fixed an issue where GlobalProtect users on macOS were disconnected immediately after sending the HIP report.
|
||||
|
||||
## GPC-21755
|
||||
|
||||
Fixed an issue where GlobalProtect users with enforcer enabled were able to access applications that were not in the enforcer exception list.
|
||||
|
||||
## GPC-21743
|
||||
|
||||
Fixed an issue where a user was randomly prompted with a \"Login Successful\" message when connecting to GlobalProtect (GP), even though GP was not connected.
|
||||
|
||||
## GPC-21737
|
||||
|
||||
Fixed an issue where the SAML redirection page opened up on end user
|
||||
|
||||
computers even though they did not have internet connectivity.
|
||||
|
||||
## GPC-21721
|
||||
|
||||
Fixed an issue, where the GlobalProtect app got stuck in Connecting status when the device woke up from sleep mode.
|
||||
|
||||
## GPC-21695
|
||||
|
||||
Fixed an issue where the GlobalProtect embedded browser could not utilize a new PIV certificate for SAML authentication if multiple certificates were available.
|
||||
|
||||
## GPC-21677
|
||||
|
||||
Fixed an issue where GlobalProtect configured for Always-on Pre-logon may not display the captive portal page if there is a delay with network access or Internet connectivity.
|
||||
|
||||
## GPC-21653
|
||||
|
||||
Fixed an issue where the GlobalProtect virtual adapter was not set up correctly.
|
||||
|
||||
## GPC-21639
|
||||
|
||||
Fixed an issue where the GlobalProtect macOS client did not extend the session even though the user clicked the Extend Session button.
|
||||
|
||||
## GPC-21636
|
||||
|
||||
Fixed an issue where the users were unable to login Windows 11 using the User Principal Name (UPN) when GPCP was selected with GlobalProtect app version 6.2.4 and 'Interactive logon: Don't display last signed-in' was enabled in their Entra ID - group policy.
|
||||
|
||||
## GPC-21627
|
||||
|
||||
Fixed an issue where the Report an Issue feature failed to work for a specific user whose username contained Japanese character.
|
||||
|
||||
## GPC-21615
|
||||
|
||||
Fixed an issue where the GlobalProtect agent (wa_3rd_party_host_64.exe) modified the __PSLockDownPolicy registry key from 4 (secure language mode) to 0 (full language mode) after a reboot.
|
||||
|
||||
## GPC-21583
|
||||
|
||||
Fixed an issue where the change password message was truncated in the GlobalProtect agent UI.
|
||||
|
||||
## GPC-21527
|
||||
|
||||
Fixed an issue where the firewall did not exclude the APIPA (169.254.0.0/16) range from GlobalProtect when the Endpoint Traffic Policy Enforcement feature was enabled with the exclude option. As a result, traffic to the APIPA range was sent over GlobalProtect instead of the local interface.
|
||||
|
||||
## GPC-21482
|
||||
|
||||
Fixed an issue where some users were unable to connect to portal access, the PANGPA did not work as expected and multiple GlobalProtect instances were opened.
|
||||
|
||||
## GPC-21468
|
||||
|
||||
Fixed an issue where HIP reports were not sent during modern standby mode.
|
||||
|
||||
## GPC-21467
|
||||
|
||||
Fixed an issue where the Transparent Upgrade with Proxy only mode did not work as expected and no tunnel was established with the gateway.
|
||||
|
||||
## GPC-21454
|
||||
|
||||
Fixed an issue where GlobalProtect Connect Before Logon connection allowed GlobalProtect to be disconnected on first time login.
|
||||
|
||||
## GPC-21453
|
||||
|
||||
Fixed an issue where the GlobalProtect app window displayed "static" instead of the connected gateway name.
|
||||
|
||||
## GPC-21437
|
||||
|
||||
Fixed an issue where users were unable to connect to Prisma Access via GlobalProtect.
|
||||
|
||||
## GPC-21413
|
||||
|
||||
Fixed an issue where the GlobalProtect Credential Provider did not reset focus on the password field when the user entered the wrong password
|
||||
|
||||
## GPC-21375
|
||||
|
||||
Fixed an issue where username from SAML assertion did not match the config selection criteria because the Windows SSO username was used instead of the SAML username.
|
||||
|
||||
## GPC-21355
|
||||
|
||||
Fixed an issue GlobalProtect pre-logon was stuck in connecting state after a reboot.
|
||||
|
||||
## GPC-21284
|
||||
|
||||
Fixed an issue where the GlobalProtect gateway did not receive the HIP reports from the user correctly due to which the end users were unable to access the resources even when the sessions were active.
|
||||
|
||||
## GPC-21267
|
||||
|
||||
Fixed an issue where, when the user installed the GlobalProtectARM installer from the Customer Support Portal (CSP) and the user opened GlobalProtect using the Start menu, the icon file (PanGPA.ico) was opened instead of the executable (PanGPA.exe) file.
|
||||
|
||||
## GPC-21240
|
||||
|
||||
Fixed an issue where, when the GlobalProtect app was installed on devices running macOS Sonoma 14.5, the app used the old FQDN names and got stuck in the "Connecting" status instead of prompting the user to enter the portal FQDN name.
|
||||
|
||||
## GPC-21161
|
||||
|
||||
Fixed an issue where the notifications for the feature "Login Lifetime Expiration" and "Notify Before Lifetime Expires" were not displayed on the GlobalProtect client running version 6.2.4.
|
||||
|
||||
## GPC-21131
|
||||
|
||||
Fixed an issue where the users were unable to access the Advanced Logging Settings screen of the GlobalProtect app using the ctrl + tab key combination on the keyboard. The screen reader did not announce the Keyboard options correctly.
|
||||
|
||||
## GPC-21090
|
||||
|
||||
Fixed an issue where GlobalProtect only displayed ADEM information for approximately 120 users even though more than 600 ADEM users were connected to GlobalProtect.
|
||||
|
||||
## GPC-21024
|
||||
|
||||
Fixed an issue where a HIP notification configured as "pop-up-message" for pre-logon does not show up. The pop up window is blank.
|
||||
|
||||
## GPC-21005
|
||||
|
||||
Fixed an issue where after submitting the SAML credentials, a blank screen was displayed and GlobalProtect got stuck in that stage.
|
||||
|
||||
## GPC-20992
|
||||
|
||||
Fixed an issue where the Teams application does not connect to the server for macOS.
|
||||
|
||||
## GPC-20991
|
||||
|
||||
Fixed an issue where the Windows Registry value (ext-key-usage-oid-for-client-cert) on \HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings was deleted during the upgrade from GlobalProtect version 6.2.2 to version 6.2.4. This makes the GlobalProtect client unable to select a certificate by itself.
|
||||
|
||||
## GPC-20977
|
||||
|
||||
Fixed an issue where conditional connect was not set and GlobalProtect connected to an external gateway on the internal network instead of connecting to an internal gateway on the internal network.
|
||||
|
||||
## GPC-20813
|
||||
|
||||
Fixed an issue where GlobalProtect 6.3.0 on macOS was blocking multicast traffic on the local network interface.
|
||||
|
||||
## GPC-20783
|
||||
|
||||
Fixed an issue where, when the embedded browser was used, the password field did not work as expected when users typed their passwords in the field. Users had to click inside the password field before entering their password.
|
||||
|
||||
## GPC-20736
|
||||
|
||||
Fixed an issue where users are being logged out from GlobalProtect when the device wakes up from modern standby and network discovery happens.
|
||||
|
||||
## GPC-20632
|
||||
|
||||
Fixed an issue where GLobalProtect was stuck in connecting mode after the customer manually selected a gateway that hit the maximum user limit. This was a multi-gateway environment with SAML/CAS authentication method.
|
||||
|
||||
## GPC-20550
|
||||
|
||||
Fixed an issue where Zoom and Outlook apps intermittently stop connecting on macOS with an error "You are unable to connect to Zoom. Please check your network connection and try again" when the apps are excluded under both domains and applications
|
||||
|
||||
## GPC-20514
|
||||
|
||||
Fixed an issue where the remote users using GlobalProtect with Connect Before Logon (CBL) were unable to reset their password when using the app with an embedded browser.
|
||||
|
||||
## GPC-20461
|
||||
|
||||
Fixed an issue where the GlobalProtect agent version 6.1.4 would only establish a connection via SSL to an IPv6 gateway. The IPSec tunnel was not established or connected.
|
||||
|
||||
## GPC-20416
|
||||
|
||||
Fixed an issue where there is no network discovery once the laptop came out of standby.
|
||||
|
||||
## GPC-20386
|
||||
|
||||
Fixed an issue where Windows users experienced a blue screen of death issue due to a race condition between Microsoft IPSEC extension and GlobalProtect. The issue happens only when IKE extensions are enabled via IPSEC GPO on the endpoint along with GlobalProtect.
|
||||
|
||||
## GPC-20292
|
||||
|
||||
Fixed an issue where the Azure VDI RDP connection disconnects when using enforcer.
|
||||
|
||||
## GPC-20168
|
||||
|
||||
Fixed an issue where it was possible to do a privilege escalation and\or login bypass when using a 3rd party credential provider with GlobalProtect
|
||||
|
||||
## GPC-18106
|
||||
|
||||
Fixed an issue where the GlobalProtect app intermittently did not send the HIP report to the Prisma Access gateway due to a timeout issue.
|
||||
@@ -0,0 +1,23 @@
|
||||
{
|
||||
"type": "Known",
|
||||
"product": "GlobalProtect",
|
||||
"version": "6.3.3",
|
||||
"issues": [
|
||||
{
|
||||
"id": "GPC-21982",
|
||||
"description": "IPv6 traffic on the Windows client does not follow the routing table and leaks through the physical adapter.",
|
||||
"platforms": [
|
||||
"Windows",
|
||||
"MacOS"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "GPC-20983",
|
||||
"description": "When a Windows computer resumes from sleep, the GlobalProtect app remains stuck in the connecting stage.",
|
||||
"platforms": [
|
||||
"Windows",
|
||||
"MacOS"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.0-h1
|
||||
---
|
||||
|
||||
## PAN-237871
|
||||
|
||||
(WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
@@ -0,0 +1,73 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.0
|
||||
---
|
||||
|
||||
## PAN-233557
|
||||
|
||||
Fixed an issue where, after using Panorama to configure per policy persistent DIPP, downgrading the firewall using Panorama and then upgrading the firewall back to a later PAN-OS release, the global DIPP configuration was not successfully converted b ack to the per policy persistent DIPP rules.
|
||||
|
||||
## PAN-230359
|
||||
|
||||
Fixed an issue where SAML authentication failed with the error message Failed to verify signature against certificate when ds:KeyName was in the IdP metadata.
|
||||
|
||||
## PAN-227639
|
||||
|
||||
Fixed an issue where the ACC displayed an incorrect DNS-base application traffic byte count.
|
||||
|
||||
## PAN-227376
|
||||
|
||||
Fixed an issue where a memory overrun caused the all_task process to stop responding.
|
||||
|
||||
## PAN-227368
|
||||
|
||||
Fixed an issue where GlobalProtect users could not connect the app to a portal or gateway and GlobalProtect Clientless VPN users were unable to access applications when authentication took longer than 20 seconds.
|
||||
|
||||
## PAN-226418
|
||||
|
||||
A CLI command was added to address an issue where long-lived sessions aged out even when there was ongoing traffic.
|
||||
|
||||
## PAN-226198
|
||||
|
||||
Fixed an issue on Panorama where the configd process repeatedly restarted when attempting to make configuration changes.
|
||||
|
||||
## PAN-225920
|
||||
|
||||
Fixed an issue where duplicate predict sessions didn't release NAT resources.
|
||||
|
||||
## PAN-225886
|
||||
|
||||
Fixed an issue where if you enabled explicit proxy mode for the web proxy, intermittent errors and unexpected TCP reconnections may have occurred.
|
||||
|
||||
## PAN-225169
|
||||
|
||||
Added a CLI command to view Strata Logging Service queue usage.
|
||||
|
||||
## PAN-224772
|
||||
|
||||
Fixed a high memory usage issue with the mongodb process that caused an OOM condition.
|
||||
|
||||
## PAN-224145
|
||||
|
||||
Fixed an issue in multi-vsys environments where, when Panorama was on a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release, commits failed on the firewall when inbound inspection mode was configured in the decryption policy rule.
|
||||
|
||||
## PAN-223457
|
||||
|
||||
Fixed an issue where, if the number of group queries exceeded the Okta rate limit threshold, the firewall cleared the cache for the groups.
|
||||
|
||||
## PAN-221126
|
||||
|
||||
Fixed an issue where email server profiles (Device > Server Profiles > Email and Panorama > Server Profiles > Email) to forward logs as email notifications were not forwarded in a readable format.
|
||||
|
||||
## PAN-218555
|
||||
|
||||
Fixed an issue where the firewall did not receive dynamic address updates pushed from Panorama during initial registration to Panorama.
|
||||
|
||||
## PAN-213931
|
||||
|
||||
Fixed an issue where the logrcvr process cache was not in sync with the mapping on the firewall.
|
||||
|
||||
## PAN-206913
|
||||
|
||||
Fixed an issue where, when DHCPv6 client was configured on firewalls in active/passive HA configurations, releasing the IPv6 address from the client released the IPv6 address from only the active firewall.
|
||||
@@ -0,0 +1,145 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.10-h10
|
||||
---
|
||||
|
||||
## PAN-306502
|
||||
|
||||
Fixed an issue where TLS connection failure occurred when traffic was over TLS1.2 or below, header insertion was enabled on the firewall, send TLS handshake to CTD was enabled, and traffic hit a decryption policy rule configured with the no-decrypt action.
|
||||
|
||||
## PAN-306306
|
||||
|
||||
```caveat
|
||||
Panorama appliances in FIPS-CC mode only
|
||||
```
|
||||
|
||||
Fixed interdevice TLS communication failures that occurred with RSA and RSA-PSS signature algorithms across multiple layer 7 application services.
|
||||
|
||||
## PAN-306226
|
||||
|
||||
Fixed an issue where the TLS handshake did not complete and the session did not go through. This occurred if the HTTP header insertion applied to an HTTP CONNECT request passing through the firewall, the scan-handshake feature was enabled, the session matched a decryption policy rule with the decrypt action, and if the TLS client hello was in a single packet and TLS 1.2 or below.
|
||||
|
||||
## PAN-304496
|
||||
|
||||
Fixed an issue where, after unregistering an IP tag and registering a different IP tag for the same IP address via XML API, the dynamic address group membership was not updated on the dataplane, which resulted in Security policy rules being enforced incorrectly.
|
||||
|
||||
## PAN-303954
|
||||
|
||||
Fixed an issue where, when configuring Safenet HSMs in HA and authentication HSM manually, the second HSM server failed to authenticate due to the firewall overwriting the first HSM server's certificate with the second HSM server's certificate.
|
||||
|
||||
## PAN-303051
|
||||
|
||||
Fixed an issue on Panorama where a memory leak occurred related to the reportd process due to retaining memory that was temporarily used for report generation instead of releasing the memory for reuse, which resulted in continuous accumulation and memory exhaustion.
|
||||
|
||||
## PAN-301801
|
||||
|
||||
Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
|
||||
|
||||
## PAN-300637
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall unexpectedly rebooted due to repeated varrcvr process restarts.
|
||||
|
||||
## PAN-300548
|
||||
|
||||
Fixed an issue where using the IKEv2 multiplier setting for VPN re-authentication resulted in the firewall not re-authenticating at the expected intervals when both sides initiated rekeying. The internal re-authentication counter incremented when the local side triggered the rekey, but not when the peer side triggered it.
|
||||
|
||||
## PAN-297975
|
||||
|
||||
Fixed an issue where Panorama was unable to push the Trusted Root CA configuration to Log Collectors via a Collector Group push due to the Log Collector not supporting the trusted-root-CA configuration.
|
||||
|
||||
## PAN-297708
|
||||
|
||||
Fixed an issue where a long-lived session with many Machine Learning (ML) model triggers caused a memory leak of feature states associated with the ML model runs. This resulted in Spyware_State failure increases, allocation max outs, and impaired policy matching.
|
||||
|
||||
## PAN-297610
|
||||
|
||||
Fixed an issue where the firewall became unresponsive after an upgrade due to the fsck command scanning drive partitions in parallel with the root partition, which caused the process to take an extended amount of time.
|
||||
|
||||
## PAN-297295
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall repeatedly restarted due to high packet rates on the synthetic path in DPDK mode.
|
||||
|
||||
## PAN-297005
|
||||
|
||||
Fixed an issue where exporting custom reports resulted in empty CSV files.
|
||||
|
||||
## PAN-296977
|
||||
|
||||
Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in Network > Interfaces.
|
||||
|
||||
## PAN-296397
|
||||
|
||||
Fixed an issue on the Panorama web interface where previewing changes after a commit to shared objects were not accurately displayed in the push scope.
|
||||
|
||||
## PAN-295578
|
||||
|
||||
Fixed an issue where GlobalProtect HIP data file download and installation failed with the error message An error occurred while processing request. Please try again after some time or contact support or No ETAG from response due to a script exiting prematurely.
|
||||
|
||||
## PAN-294307
|
||||
|
||||
Fixed an issue on Panorama where a configd SIGSEGV crash occurred when renaming objects within policy rules, objects, or zones.
|
||||
|
||||
## PAN-291009
|
||||
|
||||
Fixed an issue where, after a web server returned a 401 or 403 error, the firewall was unable to decrypt HTTP/2 traffic, and the firewall rejected all subsequent streams from the client.
|
||||
|
||||
## PAN-290665
|
||||
|
||||
Fixed an issue with firewalls enabled with Security profiles where certain traffic conditions caused high dataplane CPU utilization and packet buffer exhaustion, which caused LACP flapping conditions.
|
||||
|
||||
## PAN-288158
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall became inaccessible via the web interface and SSH and remained in an initializing state.
|
||||
|
||||
## PAN-288097
|
||||
|
||||
Fixed an issue where on the firewall where the routed process stopped responding after changing the MTU or any link state parameters when OSPF and PIM were enabled on the same interface.
|
||||
|
||||
## PAN-284866
|
||||
|
||||
Fixed an issue where the LFC failed to validate Certificate Revocation Lists (CRL) for SSL syslog connections, which caused a failure to forward logs to external syslog servers.
|
||||
|
||||
## PAN-280725
|
||||
|
||||
Fixed an issue where all_pktproc process repeatedly restarted, which caused dataplane failure and loss of connectivity, including PAN-DB URL resolution. This occurred after a commit push from Panorama and resulted in the firewall becoming non-functional due to internal path monitoring failure and configuration memory exhaustion.
|
||||
|
||||
## PAN-278126
|
||||
|
||||
Fixed an issue where the number of registered IP Tags on Panorama did not match the number of registered IP Tags on the managed firewalls due to a change in file format between PAN-OS releases.
|
||||
|
||||
## PAN-276484
|
||||
|
||||
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
|
||||
|
||||
## PAN-276321
|
||||
|
||||
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as unknown, which prevented access to resources based on AD group membership.
|
||||
|
||||
## PAN-274086
|
||||
|
||||
Fixed an issue where the firewall incorrectly assembled SIP NOTIFY and REFER messages when processing SIP TCP packets that contained a partial content-body from a previous SIP message and a complete header and content-body from the next SIP message.
|
||||
|
||||
## PAN-272245
|
||||
|
||||
Fixed an issue where the dnsproxy process stopped responding due to memory corruption caused by a race condition when the allow list downloading was impacted by a configuration change.
|
||||
|
||||
## PAN-257616
|
||||
|
||||
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
||||
|
||||
## PAN-241694
|
||||
|
||||
Fixed an issue where memory leaks related to the devsrvr process occurred when downloading and pushing updates from the App-ID Cloud Engine to the dataplane.
|
||||
@@ -0,0 +1,207 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.10-h12
|
||||
---
|
||||
|
||||
## PAN-309392
|
||||
|
||||
Fixed an issue where the scroll bar did not appear when editing Destination Addresses for Policy Based forwarding policy rules.
|
||||
|
||||
## PAN-309379
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding on DPCs, which prevented logs from being forwarded.
|
||||
|
||||
## PAN-308085
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where, after resizing the VM, the HA2 link became unstable. Frequent keep-alive failures occurred, and HA2 keep-alive packets were simultaneously transmitted to multiple destination MAC addresses and the peer firewall's interface MAC). This issue occurred on firewalls with Accelerated Networking enabled.
|
||||
|
||||
## PAN-308060
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the BFD session went down and did not recover even though the BGP remained in an established state, which caused the firewall to cease route learning and advertisement with the peer, even though BGP keep-alives were exchanged correctly.
|
||||
|
||||
## PAN-307795
|
||||
|
||||
Fixed an issue where Panorama incorrectly generated system logs indicating a lost connection to its peer after an upgrade even when High Availability was not configured.
|
||||
|
||||
## PAN-305835
|
||||
|
||||
Fixed an issue where firewalls with Memory Integrity Checking Architecture enabled rebooted unexpectedly due to accessing an invalid memory address. This occurred because the forwarding data structure index exceeded its designed limit.
|
||||
|
||||
## PAN-305412
|
||||
|
||||
Fixed an issue where the Logging Service License Status displays a license failure when the license status transitions from valid to expired and then back to valid even when the connection to the Security Logging Service (SLS) was working.
|
||||
|
||||
## PAN-305301
|
||||
|
||||
Fixed an issue where the timing of GlobalProtect lifetime expiry or inactivity logout notifications used for GlobalProtect SSL tunnels could cause the pan_task process to stop responding and the dataplane to restart.
|
||||
|
||||
## PAN-304636
|
||||
|
||||
Fixed an issue where BGP aggregate routes were not created and discard routes were not installed in the routing table.
|
||||
|
||||
## PAN-303959
|
||||
|
||||
Fixed an issue where traffic is incorrectly identified as unknown-tcp/unknown-udp due to App-ID resource leak and eventually dropped.
|
||||
|
||||
## PAN-303627
|
||||
|
||||
Fixed an issue where, after committing a configuration change, the firewall experienced traffic issues, pan_task crashes, and LACP interface failures.
|
||||
|
||||
## PAN-303559
|
||||
|
||||
Fixed an issue where, after manuallly creating a device telemetry bundle, the hour_cli_output.txt file within the bundle had a file size of 0 bytes. This occurred when checking the bundle content after enabling device telemetry and setting the device telemetry upload endpoint.
|
||||
|
||||
## PAN-302551
|
||||
|
||||
Fixed an issue where the firewall displayed as disconnected in the SLS due to the serial number not being retrieved
|
||||
|
||||
## PAN-301975
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the passive firewall incorrectly triggered PBP alerts even with low packet rates.
|
||||
|
||||
## PAN-301937
|
||||
|
||||
Fixed an issue where Microsoft Defender for Cloud detected cleartext SSH private keys in the /var/appweb and /etc/appweb directories on PA-VM firewalls deployed in Azure.
|
||||
|
||||
## PAN-301912
|
||||
|
||||
Fixed an issue where Panorama stopped responding when deploying dynamic updates to managed devices.
|
||||
|
||||
## PAN-301600
|
||||
|
||||
Fixed an issue on the firewall where, after upgrading Panorama, OSPF adjacencies remained in the exchange start state, which resulted in an incomplete routing table.
|
||||
|
||||
## PAN-301456
|
||||
|
||||
Fixed an issue on Panorama where the debug system reset-ztp CLI command was unavailable.
|
||||
|
||||
## PAN-301409
|
||||
|
||||
Fixed an issue where Panorama failed to perform a selective push to a managed device when device tags were added or modified on the policy rules. The selective push failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
||||
|
||||
## PAN-300837
|
||||
|
||||
Fixed an issue where firewalls experienced multiple reboots due to the pan_task process restarting with a SIGSEGV signal. This occurred because the client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||
|
||||
## PAN-299751
|
||||
|
||||
Fixed an issue where the firewall was unable to connect to the Subscription License Service (SLS) due to a public and private key pair mismatch with the device certificate.
|
||||
|
||||
## PAN-299622
|
||||
|
||||
Fixed an issue where the MFA timestamp was not redistributed between standalone firewalls behind an Azure load balancer after upgrading, which resulted in users being prompted to reauthenticate multiple times.
|
||||
|
||||
## PAN-298907
|
||||
|
||||
Fixed an issue on PA-VM in AWS where, in a two-arm deployment integrated with Gateway Load Balancer (GWLB), the firewall did not preserve the GENEVE source port for internet traffic, resulting in increased latency. The fix ensures the firewall preserves the outer UDP source port of GENEVE encapsulation when sending traffic back to GWLB.
|
||||
|
||||
## PAN-297263
|
||||
|
||||
```caveat
|
||||
PA-5220 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the ikemgr process crashed intermittently, causing IPSec tunnels to go down randomly. The fix ensures that the IKE security association data structures are accessed in a thread-safe manner. This prevents the ikemgr process from referencing an invalid memory pointer during teardown operations and provides stability.
|
||||
|
||||
## PAN-296208
|
||||
|
||||
Fixed an issue where the firewall did not accept address groups in the filter condition of a Log Forwarding Match list.
|
||||
|
||||
## PAN-295796
|
||||
|
||||
Fixed an issue where the firewall intermittently failed to forward VXLAN GARP packets, which led to connectivity issues for wireless clients in environments that used VXLAN tunnels for wireless access points.
|
||||
|
||||
## PAN-292447
|
||||
|
||||
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
|
||||
## PAN-291067
|
||||
|
||||
Fixed an issue where the devsrvr process periodically exceeded its virtual memory limit and restarted, which led to intermittent outages.
|
||||
|
||||
## PAN-290241
|
||||
|
||||
Fixed an issue where the useridd process became unresponsive, which caused User-ID CLI commands to time out.
|
||||
|
||||
## PAN-290235
|
||||
|
||||
Fixed an issue where the dscd process crashed continuously on MIPS platforms (for example, PA-850 firewalls) due to a runtime error related to an invalid memory address or nil pointer dereference. This was caused by a golang library upgrade in CIE that is incompatible with the MIPS platform.
|
||||
|
||||
## PAN-289652
|
||||
|
||||
Fixed an issue related to external URL lists where pushing configuration changes from Panorama failed.
|
||||
|
||||
## PAN-288427
|
||||
|
||||
Fixed an issue on Panorama where commit jobs were not queued and the system reported that the useridd was not connected.
|
||||
|
||||
## PAN-287921
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the maximum registered IP address for was incorrectly set to 100,000 instead of the expected 500,000.
|
||||
|
||||
## PAN-285208
|
||||
|
||||
Fixed an issue where the firewall did not automatically recover after a machine check exception (MCE) occurred.
|
||||
|
||||
## PAN-283237
|
||||
|
||||
Fixed an issue where traffic logs incorrectly displayed the action as allow for traffic matching a Security policy rule configured with the action set to deny. This issue occurred due to the child session being used for policy rule lookup when a configuration update triggered a rematch if the FTP-data application was not in the rule.
|
||||
|
||||
## PAN-281588
|
||||
|
||||
Fixed an issue where packet buffer depletion occurred due to the a high number of tcp_pkt_queued packets when Jumbo was enabled.
|
||||
|
||||
## PAN-277464
|
||||
|
||||
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the SSL Command and Control action was not either allow or alert and server hello packets were out of order.
|
||||
|
||||
## PAN-269535
|
||||
|
||||
Fixed an issue where the mib ID returned an incorrect value via SNMP.
|
||||
|
||||
## PAN-263691
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a memory leak in the all_task process.
|
||||
|
||||
## PAN-262831
|
||||
|
||||
```caveat
|
||||
PA-5400f Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where the all_task process stopped responding, which caused the firewall to restart.
|
||||
|
||||
## PAN-255654
|
||||
|
||||
Fixed an issue where, when QoS was enabled on aggregate interfaces, the maximum aggregate interface throughput was capped, which limited network traffic. This occurred even with default QoS settings and no configured egress max-bandwidth.
|
||||
|
||||
## PAN-236794
|
||||
|
||||
Fixed an issue where SNMP walk reported incorrect interface speeds.
|
||||
|
||||
## PAN-185731
|
||||
|
||||
Fixed an issue where the firewall was unable to parse the URL path and host when the host header was located in a different packet, which resulted in the firewall not logging the URL path in the first packet. The fix is disabled by default. The following CLI commands can be used to enable/disable the feature:set system setting ctd url-crosspkt-host-path-caching enableset system setting ctd url-crosspkt-host-path-caching disableset system setting ctd url-crosspkt-host-path-caching default
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching enable
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching disable
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching default
|
||||
@@ -0,0 +1,319 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.10-h1
|
||||
---
|
||||
|
||||
## PAN-241230
|
||||
|
||||
Fixed an issue where the SNMP get request status value for Panorama connections was incorrect.
|
||||
|
||||
## PAN-253187
|
||||
|
||||
```caveat
|
||||
PA-5450 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the class of service (CoS) priority bit was not modified, causing access points to lose connectivity to the wireless controller when traffic was routed through the firewall.
|
||||
|
||||
## PAN-253778
|
||||
|
||||
```caveat
|
||||
PA-7500 Series firewalls in a cluster configuration only
|
||||
```
|
||||
|
||||
Fixed an issue where users were able to enable or disable certain configurations.
|
||||
|
||||
## PAN-290239
|
||||
|
||||
```caveat
|
||||
PA-455 firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, the TCP session for syslog forwarding did not resume after the syslog server service was disabled and then re-enabled, which caused logs to be dropped. This occurred when the syslog server was down for more than 16 minutes.
|
||||
|
||||
## PAN-290088
|
||||
|
||||
Fixed an issue where a memory leak occurred related to the configd process when pushing configurations from Panorama to a firewall. This occurred when the configurations contained shared policy rules.
|
||||
|
||||
## PAN-289304
|
||||
|
||||
```caveat
|
||||
PA-7500 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where SNMP polling failed due to the snmpd process becoming unresponsive to incoming requests, which resulted in high CPU usage.
|
||||
|
||||
## PAN-289102
|
||||
|
||||
Fixed a race condition issue related to predict processing on multi-core platforms, which resulted in a dataplane restart and traffic loss.
|
||||
|
||||
## PAN-288930
|
||||
|
||||
Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.
|
||||
|
||||
## PAN-288893
|
||||
|
||||
```caveat
|
||||
Firewalls in multi-vsys configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where HTTP/2 traffic failed due when one virtual system (vsys) had a decryption policy rule enabled and another vsys had a no-decrypt policy rule for the same session.
|
||||
|
||||
## PAN-288363
|
||||
|
||||
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
|
||||
|
||||
## PAN-287838
|
||||
|
||||
```caveat
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue on the web interface where resetting the rule hit counter for multiple policy rules failed with the error message Failed to reset rule-hit job.
|
||||
|
||||
## PAN-287818
|
||||
|
||||
Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_ restore_timeout not initiating when the accumulation session_init failed.
|
||||
|
||||
## PAN-287734
|
||||
|
||||
Fixed an issue where Scan ERR: Internal Err 1002 messages were unexpectedly generated when WIF shared memory use was high.
|
||||
|
||||
## PAN-287621
|
||||
|
||||
Added debug logs for an issue where a slow IP address pool NAT leak occurred when persistent NAT was enabled, which led to NAT IP pool exhaustion.
|
||||
|
||||
## PAN-287584
|
||||
|
||||
Fixed an issue on the web interface where the address object pop up window only displayed a maximum of four address objects in the policy rule even after expanding the window.
|
||||
|
||||
## PAN-287056
|
||||
|
||||
Fixed an issue where BGP export policy rules with next-hop matching failed to block the advertisement of static routes, and the firewall incorrectly matched the egress interface IP address instead of the original next-hop IP address of the static route, which caused the deny rule to fail.
|
||||
|
||||
## PAN-287023
|
||||
|
||||
Fixed an issue where a large number of logs caused the logrcvr process to stop responding.
|
||||
|
||||
## PAN-286857
|
||||
|
||||
Fixed an issue where only failed Kerberos authentication events were logged in auth.log, and successful authentication events were not logged.
|
||||
|
||||
## PAN-286848
|
||||
|
||||
Fixed an issue where ECMP incorrectly balanced sessions across links based on the configured metric, which led to an imbalance in traffic distribution and resulted in traffic assignment shifting disproportionately to routes with lower metrics.
|
||||
|
||||
## PAN-286443
|
||||
|
||||
Fixed an issue where, after an upgrade, the firewall was unable to be managed via HTTPS or SSH.
|
||||
|
||||
## PAN-286306
|
||||
|
||||
Fixed an issue where, when getting transceiver information from ESCC for SFP 25G modules, the transceiver code was incorrectly updated with Unknown instead of 25GBase-SR.
|
||||
|
||||
## PAN-285894
|
||||
|
||||
Fixed an issue where the all_task process stopped responding, which caused the firewall to reboot unexpectedly, and traffic failures occurred.
|
||||
|
||||
## PAN-285818
|
||||
|
||||
Fixed an issue where a tool was needed to display leaked NAT port numbers without requiring a forced synchronization.
|
||||
|
||||
## PAN-284908
|
||||
|
||||
Fixed an issue where retrieving filenames from OneDrive resulted in a cache miss.
|
||||
|
||||
## PAN-284067
|
||||
|
||||
Fixed an issue where the devsrvr process experienced OOM conditions due to the show running application statistics CLI command, which caused the firewall to reboot.
|
||||
|
||||
## PAN-284003
|
||||
|
||||
Fixed an issue where clients did not receive a valid response when when searching a website due to a compression error.
|
||||
|
||||
## PAN-283979
|
||||
|
||||
Fixed an issue where the firewall became non-functional due to high root partition use.
|
||||
|
||||
## PAN-283813
|
||||
|
||||
Fixed an issue on Panorama where the web interface performance was slower than usual when retrieving read-only configurations from Panorama.
|
||||
|
||||
## PAN-282394
|
||||
|
||||
Fixed an issue where a firewall was only able to display a maximum of 14 permitted IP addresses from a Panorama Template Variable.
|
||||
|
||||
## PAN-282277
|
||||
|
||||
Fixed an issue where an OOM condition on the logrcvr process caused interface flapping, and the interface unexpectedly went down and then recovered without intervention.
|
||||
|
||||
## PAN-281509
|
||||
|
||||
```caveat
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where log exports were slower than expected or failed when filtering logs after an upgrade, which resulted in timeouts or delays in displaying logs on the web interface.
|
||||
|
||||
## PAN-280101
|
||||
|
||||
Fixed an issue where set and edit commands took longer than expected when adding address objects with a large number of dynamic groups due to the completion cache being enabled. With this fix, the completion cache is disabled by default.
|
||||
|
||||
## PAN-279706
|
||||
|
||||
```caveat
|
||||
M-600 appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama did not update all panreplay database entries after performing a commit and full push to all devices.
|
||||
|
||||
## PAN-279500
|
||||
|
||||
Fixed an issue where TLS connections failed to establish in asymmetric routing environments if the firewall did not see server-to-client (s2c) packets of the TLS handshake.
|
||||
|
||||
To use this fix, run the following CLI command: debug dataplane set ssl-decrypt accumulate-client-hello asym-disable yes.
|
||||
|
||||
## PAN-278836
|
||||
|
||||
Fixed an issue where, after an upgrade, GlobalProtect attempted to use the embedded browser instead of the default browser for gateway authentication even when it was configured to use the default browser.
|
||||
|
||||
## PAN-278812
|
||||
|
||||
Fixed an issue where authentication to GlobalProtect failed with the error message User not in allowed list.
|
||||
|
||||
## PAN-278150
|
||||
|
||||
Fixed an issue where the firewall removed the Authentication Key Identifier (AKID) from the certificate during SSL decryption, which caused Python 3.13 to fail with a certificate verification error.
|
||||
|
||||
## PAN-277808
|
||||
|
||||
Fixed an issue where the eproxy process stopped responding when running a long duration test using IXload with hybrid SWG SAML authentication bypass for HTTPS payloads, which caused the proxy to become unreachable.
|
||||
|
||||
## PAN-277617
|
||||
|
||||
Fixed an issue where deleting the NTP server address caused a commit validation error. This occurred when the configuration included both primary and secondary NTP servers and the secondary server was removed.
|
||||
|
||||
## PAN-277234
|
||||
|
||||
Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none.
|
||||
|
||||
## PAN-276920
|
||||
|
||||
Fixed an issue where web-advertisement traffic was not immediately blocked which resulted in pages loading indefinitely.
|
||||
|
||||
## PAN-276678
|
||||
|
||||
Fixed an issue where Panorama became unresponsive while performing a dynamic address update without a lock.
|
||||
|
||||
## PAN-275451
|
||||
|
||||
```caveat
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where sequence numbers were lost when forwarded from Panorama, which resulted in missing or lost logs.
|
||||
|
||||
## PAN-275133
|
||||
|
||||
Fixed an issue where HTTP 503 server errors occurred while browsing websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
|
||||
|
||||
## PAN-275047
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, the firewall was unable to send logs to the Strata Logging Service (SLS) when using a specific proxy server, and the SSL connection status displayed as failed when attempting to forward logs through the web proxy.
|
||||
|
||||
## PAN-274797
|
||||
|
||||
Fixed an issue where a DPC on slot 3 failed intermittently due to the pktlog_forwarding process restarting, which resulted in an unexpected HA failover.
|
||||
|
||||
## PAN-273964
|
||||
|
||||
Fixed an issue where SNMP scans to a firewall timed out after upgrading to a PAN-OS 10.2 release.
|
||||
|
||||
## PAN-272395
|
||||
|
||||
Fixed an issue where informational logs caused the distributord process log file to be frequently overwritten.
|
||||
|
||||
## PAN-272175
|
||||
|
||||
Fixed an issue where session rematch caused ACE cloud application traffic to match the wrong policy.
|
||||
|
||||
## PAN-271810
|
||||
|
||||
Fixed an issue where auto-negotiation advertised and negotiated 10/100 half and full duplex.
|
||||
|
||||
## PAN-271432
|
||||
|
||||
Fixed an issue where the firewall was unable to decrypt SSL traffic when using forward proxy and HSM with an ECDSA signing certificate.
|
||||
|
||||
## PAN-271425
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue with SSL inbound decryption on firewalls on a vwire setup with asymmetric routing.
|
||||
|
||||
To use this fix, enter the CLI command set system setting ssl-decrypt ha-vwire-mac-learn global yes on both firewalls in an HA pair.
|
||||
|
||||
## PAN-269700
|
||||
|
||||
Fixed an issue where commits to service connection firewalls from Panorama failed.
|
||||
|
||||
## PAN-269057
|
||||
|
||||
Fixed an issue where the routed process stopped responding due to accessing freed memory from a hash table when the route vectors were resized. This occurred when a large number of static routes were configured.
|
||||
|
||||
## PAN-268787
|
||||
|
||||
Fixed an issue where users were unable to log in to Panorama and the following error message was displayed: Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of devices.
|
||||
|
||||
## PAN-268313
|
||||
|
||||
Fixed an issue where the Priority Code Point (PCP) bits in the VLAN header were not reset to 0 when a packet was received from one Layer 3 tagged interface and forwarded to another, which resulted in dropped packets.
|
||||
|
||||
To use this fix, run the CLI command set force-vlan-pcp-reset yes and reboot the firewall.
|
||||
|
||||
## PAN-267759
|
||||
|
||||
Fixed an issue where Prisma Access gateway downloads were slower than expected.
|
||||
|
||||
## PAN-267328
|
||||
|
||||
Fixed an issue where the all_task process stopped responding, which caused the firewall to stop processing traffic.
|
||||
|
||||
## PAN-264708
|
||||
|
||||
Fixed an issue where a selective push was blocked when a configuration load was done.
|
||||
|
||||
## PAN-259727
|
||||
|
||||
```caveat
|
||||
Panorama appliances in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama became unresponsive and displayed a 504 gateway timeout error when accessing the web interface or the CLI.
|
||||
|
||||
## PAN-253778
|
||||
|
||||
```caveat
|
||||
PA-7500 Series firewalls in a cluster configuration only
|
||||
```
|
||||
|
||||
Fixed an issue where users were able to enable or disable certain configurations.
|
||||
|
||||
## PAN-253187
|
||||
|
||||
```caveat
|
||||
PA-5450 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the class of service (CoS) priority bit was not modified, causing access points to lose connectivity to the wireless controller when traffic was routed through the firewall.
|
||||
|
||||
## PAN-241230
|
||||
|
||||
Fixed an issue where the SNMP get request status value for Panorama connections was incorrect.
|
||||
@@ -0,0 +1,339 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.10-h4
|
||||
---
|
||||
|
||||
## PAN-298241
|
||||
|
||||
Fixed an issue where the NAT IP address pool was exhausted, which led to intermittent connectivity issues with call applications and outbound call failures. This occurred due to the firewall not properly releasing NAT dynamic ports back to the address pool.
|
||||
|
||||
## PAN-296992
|
||||
|
||||
Fixed an issue where Panorama managed firewalls with no defined log collector group continually attempted to establish a logging connection to Panorama, which resulted in excessive system log messages.
|
||||
|
||||
## PAN-296519
|
||||
|
||||
Fixed an issue where a stream receiving a reconnect signal with an associated error in Wifclient caused the entire pool to close, which resulted in a complete disconnection.
|
||||
|
||||
## PAN-295644
|
||||
|
||||
Fixed an issue where Cloud Data Lake (CDL) log forwarding streams intermittently displayed as inactive.
|
||||
|
||||
## PAN-295385
|
||||
|
||||
Fixed an issue where syslog forwarding dropped due to FQDN resolution failures.
|
||||
|
||||
## PAN-295342
|
||||
|
||||
Fixed an issue where the pan_comm process stopped responding due to insufficient time allocated to read file descriptors when processing long messages.
|
||||
|
||||
## PAN-295049
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding due to memory allocation errors during Redis communication.
|
||||
|
||||
## PAN-294488
|
||||
|
||||
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the Subject Common Name, Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
|
||||
|
||||
## PAN-294436
|
||||
|
||||
Fixed an issue where polling failed for ethernet interfaces due to the physical port counters read from the MAC being 0.
|
||||
|
||||
## PAN-294179
|
||||
|
||||
Fixed an issue on Panorama where commit versions did not display correct data in the config audit page even after a refresh.
|
||||
|
||||
## PAN-293985
|
||||
|
||||
```caveat
|
||||
Firewalls with Hub vsys (virtual system) configurations enabled only
|
||||
```
|
||||
|
||||
Fixed an issue where, when using the Hub vsys feature to redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP policy enforcement failed intermittently on the active secondary firewall. This occurred when traffic destined for specific non-Hub vsys was routed to the active secondary, and the HIP query was not triggered due to an incorrect check for the HIP mask in the Hub vsys.
|
||||
|
||||
## PAN-293842
|
||||
|
||||
Fixed an issue where the hybrid-SWG service proxy stopped working after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to establish the listening interface.
|
||||
|
||||
## PAN-293673
|
||||
|
||||
Fixed an issue where the firewall stopped all tasks due to an OOM condition caused by a scheduled log export using FTP to an external FTP server.
|
||||
|
||||
## PAN-293511
|
||||
|
||||
Fixed an issue where renaming a BGP filtering profile in Panorama does not update the corresponding BGP peer group in the virtual router, leading to commit failures.
|
||||
|
||||
## PAN-292242
|
||||
|
||||
Fixed an issue on M-200 and logging appliances where traffic logs were intermittently truncated when forwarded using a TCP syslog configuration. This issue occurred during the log forwarding stage due to intermittent syslog drops caused by exceeding the forwarding queue capacity.
|
||||
|
||||
## PAN-292228
|
||||
|
||||
Fixed an issue where, after configuring dual stack GlobalProtect with both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with the error message flow-basic error; packet dropped, tunnel resolution failure.
|
||||
|
||||
## PAN-292202
|
||||
|
||||
Fixed an issue where the system logs repeatedly displayed the alert Clearing snmpd.log due to log overflow due to the SNMP counters rolling over.
|
||||
|
||||
## PAN-291940
|
||||
|
||||
Fixed an issue where the firewall established multiple TCP connections to a syslog server, which caused logs to be dropped. This occurred because the firewall established a new TCP session for each transfer and the sessions were not closed, which resulted in a continuous increase in connections over time.
|
||||
|
||||
## PAN-291792
|
||||
|
||||
```caveat
|
||||
PA-7050 firewalls on vwire instances only
|
||||
```
|
||||
|
||||
Fixed an issue where Bidirectional Forwarding Detection (BFD) echo packets were dropped due to the firewall dropping packets with the same source and destination IP addresses.
|
||||
|
||||
## PAN-291785
|
||||
|
||||
Fixed an issue where the all_task process stopped responding.
|
||||
|
||||
## PAN-291631
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall frequently rebooted.
|
||||
|
||||
## PAN-291456
|
||||
|
||||
Fixed an issue where the custom completer for device groups and templates received the device group name and template name from the running configuration instead of the candidate configuration.
|
||||
|
||||
## PAN-291283
|
||||
|
||||
Fixed an issue on Panorama where a memory leak associated with the configd process occurred during commits, which caused the configd process to restart and the commit to fail.
|
||||
|
||||
## PAN-290919
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where file download speeds and performance was slower than expected for Prisma Access mobile users when SSL decryption was enabled.
|
||||
|
||||
To use this fix, run the CLI command debug dataplane set ssl-decrypt fptcp-rto min <100-500>.
|
||||
|
||||
## PAN-290691
|
||||
|
||||
Added the CLI command set system setting ctd h323_rtp_predict timeout to increase the maximum timeout limit from 3600 seconds to 65535 seconds.
|
||||
|
||||
## PAN-290449
|
||||
|
||||
Fixed an issue where, when multiple scheduled vulnerability reports were sent in the same email, only the first attached report was displayed.
|
||||
|
||||
## PAN-289803
|
||||
|
||||
Fixed an issue on the firewall where AIPOs and ADEM licenses failed when SD-WAN or GlobalProtect licenses were not present.
|
||||
|
||||
## PAN-289406
|
||||
|
||||
Fixed an issue where, when redistributing User-ID information between firewalls, the receiving firewall incorrectly received and stored duplicate Host Information Profile (HIP) profiles. This occurred when a GlobalProtect gateway redistributed User-ID and HIP information through an intermediate firewall.
|
||||
|
||||
## PAN-289383
|
||||
|
||||
Fixed an issue where the MPLS interface eth1/6 went down and remained down, even after replacing the SFP with a supported one and adjusting duplex and speed settings.
|
||||
|
||||
## PAN-289226
|
||||
|
||||
```caveat
|
||||
Firewalls in HA active/passive configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewalls experienced high dataplane CPU use when NAT64 was enabled. This occurred due to NAT64 traffic not being offloaded and unnecessary HA session updates being sent for every NAT64 packet.
|
||||
|
||||
## PAN-289109
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected during configuration operations and a configuration lock time out occurred during a commit.
|
||||
|
||||
## PAN-288988
|
||||
|
||||
Fixed an issue on Panorama where, after logging in to the web interface as the ZTP installer administrator, the web interface was blank.
|
||||
|
||||
## PAN-288432
|
||||
|
||||
Fixed an issue where, when Advanced Routing Engine was enabled firewalls configured with multiple logical routers, static routes were preferred over eBGP routes even though the static routes had a higher administrative distance.
|
||||
|
||||
## PAN-288426
|
||||
|
||||
```caveat
|
||||
M-600 Panorama appliances in Log Collector mode in a Log Collector group only
|
||||
```
|
||||
|
||||
Fixed an issue where the reportd and logd processes stopped responding, which resulted in the Panorama server not receiving logs from firewalls configured under the Log Collector group.
|
||||
|
||||
## PAN-287842
|
||||
|
||||
Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
|
||||
|
||||
## PAN-287688
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
|
||||
|
||||
## PAN-287611
|
||||
|
||||
Fixed an issue where, after upgrading, the firewall incorrectly calculated the UDP checksum for RTP traffic after NAT and Security policy application, which led to dropped packets and silent calls in applications.
|
||||
|
||||
## PAN-287601
|
||||
|
||||
Fixed an issue on Panorama where commits took longer than expected.
|
||||
|
||||
## PAN-287154
|
||||
|
||||
Fixed an issue on the firewall where the show advanced-routing bgp loc-rib-detail CLI command incorrectly displayed no BGP route when multiple BGP peers were enabled. With this fix, the CLI command requires a peer name to be specified to display local RIB details.
|
||||
|
||||
## PAN-286931
|
||||
|
||||
Fixed an issue where syslog forwarding in PAN-OS 11.1 and later releases did not support service routes when performing certificate validation over TLS.
|
||||
|
||||
## PAN-286899
|
||||
|
||||
Fixed an issue where the device-group-tags CLI command used an unnecessary configuration read lock.
|
||||
|
||||
## PAN-286615
|
||||
|
||||
Fixed an issue where the firewall double-freed shared memory when the shared memory usage reached 100% when sending large payloads. This occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced WildFire (AWF), or Advanced URL Filtering were enabled.
|
||||
|
||||
## PAN-286299
|
||||
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tab became read-only.
|
||||
|
||||
## PAN-286231
|
||||
|
||||
Fixed an issue where a simultaneous selective push from Panorama to multiple firewalls with different base configurations resulted in configuration corruption, which caused the firewall to go down.
|
||||
|
||||
## PAN-285436
|
||||
|
||||
Fixed an issue where a selective push from Panorama caused the firewall Security policy rules to be removed on firewalls associated with the device group. This occurred when the base configuration version chosen for the selective push preceded the device configuration import operation, which caused the imported configuration to not be included in the pushed configuration.
|
||||
|
||||
## PAN-265111
|
||||
|
||||
Fixed an issue where fragmented SSL hello packets were reordered when going out of the SC/ZTT towards the datacenter.
|
||||
|
||||
## PAN-260827
|
||||
|
||||
Fixed an issue where the firewall consumed excessive CPU while processing traffic for a workload running on a GKE cluster, which caused reduced throughput.
|
||||
|
||||
## PAN-251035
|
||||
|
||||
Fixed an issue where selective push operations did not push certificate changes to the firewall.
|
||||
|
||||
## PAN-284283
|
||||
|
||||
Fixed an issue on Palo Alto Networks firewalls running PAN-OS 11.1.6 where the CLI command traceroute ipv4 yes host <host> failed with a missing argument error message.
|
||||
|
||||
## PAN-284117
|
||||
|
||||
```caveat
|
||||
Panorama appliances in Log Collector mode only
|
||||
```
|
||||
|
||||
Fixed an issue where the vm_agent process restarted after an upgrade.
|
||||
|
||||
## PAN-282854
|
||||
|
||||
Fixed an issue where the Elasticsearch cluster did not start after deploying dedicated log collectors in a multi-collector environment.
|
||||
|
||||
## PAN-282578
|
||||
|
||||
Fixed an issue where ping commands from both the management plane and dataplane interfaces incorrectly prioritized IPv6 addresses over IPv4 addresses, even when IPv6 was disabled. This caused connectivity issues when pinging FQDNs that resolved to IPv6 addresses.
|
||||
|
||||
## PAN-281721
|
||||
|
||||
Fixed an issue where the firewall generated high-severity system alerts indicating that the configuration size exceeded the maximum recommended size, even when the configuration size was within the expected limits.
|
||||
|
||||
## PAN-281488
|
||||
|
||||
Fixed an issue where searching configuration logs for an audit_uuid did not return a result if the rule was created with a clone operation.
|
||||
|
||||
## PAN-281096
|
||||
|
||||
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to all, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
|
||||
|
||||
## PAN-279901
|
||||
|
||||
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
|
||||
|
||||
To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes
|
||||
|
||||
## PAN-279829
|
||||
|
||||
Fixed an issue where NAT pool leaks occurred during a test when RTSP traffic hit NAT rules.
|
||||
|
||||
## PAN-279690
|
||||
|
||||
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to unexpectedly restart.
|
||||
|
||||
## PAN-279415
|
||||
|
||||
Fixed an issue where service routes configured to use a data plane interface incorrectly used the management plane interface for traffic transmission. This issue affected syslog and CRL status traffic when a custom service route was not configured.
|
||||
|
||||
## PAN-279366
|
||||
|
||||
Fixed an issue where the firewall used an unnecessary configuration lock when running operational commands.
|
||||
|
||||
## PAN-277178
|
||||
|
||||
Fixed an issue on Panorama where you were unable to delete a shared object due to the rulebase incorrectly referencing the shared object instead of the device group-specific object when the name was used.
|
||||
|
||||
To use this fix, delete the original shared object after cloning it to a device group with the same name.
|
||||
|
||||
## PAN-275272
|
||||
|
||||
Fixed an issue where a dataplane restart was not triggered as expected when internal packet path monitoring failure occurred.
|
||||
|
||||
## PAN-274064
|
||||
|
||||
Fixed an issue on Panorama where the request batch license info CLI command displayed entries for devices that were no longer attached to Panorama.
|
||||
|
||||
## PAN-271545
|
||||
|
||||
Fixed an issue where, when the zone protection option anycast-source was enabled, IPv6 traffic with an interface ID of 0 was dropped even if the subnet was not locally configured on the firewall.
|
||||
|
||||
## PAN-269659
|
||||
|
||||
Fixed an issue on the firewall where you were unable to configure more than 500 DHCP relay servers even though the supported limit was 4096.
|
||||
|
||||
## PAN-268522
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
|
||||
|
||||
## PAN-268002
|
||||
|
||||
Fixed an issue where URL filtering response pages were not displayed for sites that were blocked as a result of SSL/TLS handshake inspection.
|
||||
|
||||
## PAN-267330
|
||||
|
||||
Fixed an issue where the firewall dropped inbount RTP traffic after using Webex Screen Sharing due to the firewall removing the NAT cache when the predict timed out, which caused a new NAT to be established that conflicted with existing sessions. To use this fix, run the CLI command set system setting ctd h323_rtp_predict timeout <120-3600> to increase the timeout limit.
|
||||
|
||||
## PAN-262599
|
||||
|
||||
Fixed an issue where the firewall displayed incorrect policy cache usage and configuration memory usage during a commit, which caused the configuration commit to fail with a CONFIG_UPDATE_START error. This occurred when a large number of External Dynamic Lists (EDLs), shared addresses, and policy rules were configured.
|
||||
|
||||
## PAN-262521
|
||||
|
||||
Fixed an issue where imported certificates were not visible on firewalls with multi-vsys disabled.
|
||||
|
||||
## PAN-257362
|
||||
|
||||
Fixed an issue where GlobalProtect traffic destined for the internet did not follow the path-based forwarding (PBF) rule and was sent out the wrong interface.
|
||||
|
||||
## PAN-255860
|
||||
|
||||
```caveat
|
||||
PA-5200 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the all_pktproc process stopped responding when the firewall was under a heavy traffic load.
|
||||
|
||||
## PAN-201825
|
||||
|
||||
Fixed an issue where firewalls did not use the Application Command and Response (ACR) functionality for cloud management, which caused connections to cloud management to drop after a commit.
|
||||
|
||||
## PAN-174038
|
||||
|
||||
Fixed an issue with firewalls with SD-WAN policy rules and GlobalProtect gateway configurations where enabling GlobalProtect on a loopback interface caused an issue where IPSec tunnel traffic from the gateway to the client dropped intermittently.
|
||||
@@ -0,0 +1,145 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.10-h5
|
||||
---
|
||||
|
||||
## PAN-300906
|
||||
|
||||
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to missing XML-related functions for inline-cloud-proxy and session-distribution commands in dagger files handling.
|
||||
|
||||
## PAN-300096
|
||||
|
||||
Fixed an issue where a local commit on a firewall breaks template stack overrides, preventing the enabling of LACP (Link Aggregation Control Protocol). After a local commit, the LACP enable check was unexpectedly unchecked, causing an outage. Attempting to re-enable LACP through the web interface was unsuccessful, requiring manual removal of the LACP configuration from the Panorama CLI.
|
||||
|
||||
## PAN-299785
|
||||
|
||||
```caveat
|
||||
PA-7500 and PA-5450 firewalls in FIPS-CC mode
|
||||
```
|
||||
|
||||
Fixed an issue where the affected firewalls would boot into maintenance mode when a reboot was initiated from the web interface. This was due to a device reboot triggering a power down to all slots, leading to maintenance mode. A hard reboot would allow the firewall to boot normally.
|
||||
|
||||
## PAN-297972
|
||||
|
||||
Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis pre-filtering signatures, even when Inline Cloud Analysis features were not enabled.
|
||||
|
||||
## PAN-297240
|
||||
|
||||
Fixed an issue where attempting to generate reports in a WildFire FIPS Private Cloud or WF-500 deployment returned 401 errors.
|
||||
|
||||
## PAN-296490
|
||||
|
||||
```caveat
|
||||
FIPS CC mode enabled only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama on GCP reboots every hour after upgrading to 11.1.6-h10. Panorama will run for up to an hour and then crash.
|
||||
|
||||
## PAN-296453
|
||||
|
||||
Fixed an issue where decryption exclusion lists were not working for untrusted certificates, and SSL sessions were still being decrypted even after adding them to the exclusion list. This occurred because the firewall was not adding sessions to the exclude cache until after receiving a non-RFC alert (BadCertificate) from the server. The fix ensures that the first session is added to the exclude cache, allowing subsequent sessions to skip decryption. This issue affects firewalls configured as clients in server-client communication.
|
||||
|
||||
## PAN-295944
|
||||
|
||||
Fixed an issue where static routes remained active in the FIB and RIB even when the associated physical port interface was down, which resulted in traffic being incorrectly routed through a non-operational interface.
|
||||
|
||||
## PAN-295560
|
||||
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors, tunnel logs were not visible in Panorama or Splunk even though traffic and threat logs were received.
|
||||
|
||||
## PAN-295257
|
||||
|
||||
Fixed an issue where, after onboarding a firewall to Panorama, IPsec tunnels displayed IKEv2 in Panorama, even though the tunnels were configured with IKEv1 locally on the firewall.
|
||||
|
||||
## PAN-294893
|
||||
|
||||
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
|
||||
## PAN-294770
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations
|
||||
```
|
||||
|
||||
Fixed an issue on firewalls where, after failover, certain subnets were missing from the Link State Database, which prevented OSPF routes from being immediately learned due to a Type-7 to Type-5 LSA translation conflict in the ABR when the same LSA was advertised by two peers in the NSSA area.
|
||||
|
||||
## PAN-294524
|
||||
|
||||
Fixed an issue where firewalls and Panorama management servers were unable to view or download WildFire reports from a WF-500 appliance, resulting in a 401 error in the report tab.
|
||||
|
||||
## PAN-292393
|
||||
|
||||
Fixed an issue where TFTP file transfers intermittently timed out in active-active HA pairs when the TFTP control channel was processed by one firewall and the data channel was processed by the other. This occurred because the firewall receiving the data channel failed to match the predicted session due to asynchronous processing of HA messages.
|
||||
|
||||
## PAN-291716
|
||||
|
||||
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM) conditions, leading to device crashes and reboots.
|
||||
|
||||
## PAN-291288
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a pan_task process restart related to page allocation failures.
|
||||
|
||||
## PAN-290453
|
||||
|
||||
```caveat
|
||||
PA-7500 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where PA-7500 firewalls experienced silent traffic drops. During migration from PA-7050 to PA-7500 firewalls connected in series, intermittent connection losses occurred for some applications. Traffic leaving the PA-7050 was not received or processed by the PA-7500, even with direct connections and replaced cables/SFPs. Global counters did not indicate any drops on the PA-7500.
|
||||
|
||||
## PAN-289249
|
||||
|
||||
Fixed an issue where a memory leak occurred on the reportd process when a WildFire update was initiated while device telemetry data collection was in progress. This resulted in an OOM condition.
|
||||
|
||||
## PAN-287803
|
||||
|
||||
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.
|
||||
|
||||
## PAN-287782
|
||||
|
||||
Fixed an issue where firewalls configured in vwire mode modified DSCP values from AF11 to CS0 on traffic passing through the firewall, even when QoS policy rules and DSCP rewrite settings were not configured.
|
||||
|
||||
## PAN-287622
|
||||
|
||||
Fixed an issue where IPv6 traffic was affected after upgrading the firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.
|
||||
|
||||
## PAN-287423
|
||||
|
||||
Fixed an issue where content loading issues occurred on IPv6 websites due to the firewall incorrectly setting the IPv6 header flow label to 0.
|
||||
|
||||
## PAN-285648
|
||||
|
||||
Fixed an issue where the log receiver process crashed on PA-7050 firewalls due to system log processing threads becoming blocked when the queue was full. This resulted in a heartbeat failure.
|
||||
|
||||
## PAN-283053
|
||||
|
||||
Fixed an issue where the firewall experienced high disk space utilization, which caused the firewall to become non-functional.
|
||||
|
||||
## PAN-278322
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not display the correct source user in traffic logs and session details.
|
||||
|
||||
## PAN-277034
|
||||
|
||||
Fixed an issue where WildFire reports were not fully displayed and were not downloadable due to static resources not being found.
|
||||
|
||||
## PAN-267450
|
||||
|
||||
Fixed an issue where the reported process stopped responding with a SIGSEGV at schedule_report_es_response.
|
||||
|
||||
## PAN-260185
|
||||
|
||||
Fixed an issue where a dataplane crash occurred in Inline Cloud Analysis action lookup because there were no vulnerability or antispyware profiles in the security policy rule.
|
||||
|
||||
## PAN-253963
|
||||
|
||||
```caveat
|
||||
Panorama appliances in Panorama mode and Log Collector mode only
|
||||
```
|
||||
|
||||
Fixed an issue where autocommits took longer than expected to complete.
|
||||
@@ -0,0 +1,321 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.10-h7
|
||||
---
|
||||
|
||||
## PAN-303737
|
||||
|
||||
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to session-distribution commands in dagger files handling.
|
||||
|
||||
## PAN-300906
|
||||
|
||||
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to missing XML-related functions for inline-cloud-proxy and session-distribution commands in dagger files handling.
|
||||
|
||||
## PAN-300096
|
||||
|
||||
Fixed an issue where a local commit on a firewall breaks template stack overrides, preventing the enabling of LACP (Link Aggregation Control Protocol). After a local commit, the LACP enable check was unexpectedly unchecked, causing an outage. Attempting to re-enable LACP through the web interface was unsuccessful, requiring manual removal of the LACP configuration from the Panorama CLI.
|
||||
|
||||
## PAN-299815
|
||||
|
||||
Fixed an issue on multi-vsys firewalls where a host was not removed from the quarantine list after receiving a redistribution message from Panorama. This occurred when Panorama was configured to redistribute quarantine messages to a firewall cluster, and the GlobalProtect configuration and redistribution were built out in a vsys other than vsys1.
|
||||
|
||||
## PAN-299785
|
||||
|
||||
```caveat
|
||||
PA-7500 and PA-5450 firewalls in FIPS-CC mode
|
||||
```
|
||||
|
||||
Fixed an issue where the affected firewalls would boot into maintenance mode when a reboot was initiated from the web interface. This was due to a device reboot triggering a power down to all slots, leading to maintenance mode. A hard reboot would allow the firewall to boot normally.
|
||||
|
||||
## PAN-299772
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in active/passive configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an HA failover event, the newly active firewall DHCP client interfaces failed to obtain IP addresses automatically. This occurred because the DHCP client processes did not initiate the necessary DHCP discover or renew requests
|
||||
|
||||
## PAN-299615
|
||||
|
||||
Fixed an issue where, when the Network Packet Broker feature was enabled, forward TLS (non-decrypted) traffic was not working as expected when there were segmented client hellos and a no-decrypt rule existed. This issue occurred when Zone Protection profiles were configured for trust/untrust zones but not attached to NPB zones.
|
||||
|
||||
## PAN-298654
|
||||
|
||||
Fixed an issue where the firewall generate false positive threat logs during updates to a large domain list (EDL) when a DNS lookup for a domain being added or removed occurred during the update process. This resulted in a threat log being generated for a different, unrelated domain that remained on the list.
|
||||
|
||||
## PAN-298505
|
||||
|
||||
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, the vsys ID changed in sequence, causing autocommit failures with validation errors. This occurred when the multi-vsys firewall had virtual systems created and pushed from Panorama, and the vsys ID was not in a correct sequence because the unused vsys was deleted from Panorama and pushed to devices.
|
||||
|
||||
## PAN-297972
|
||||
|
||||
Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis pre-filtering signatures, even when Inline Cloud Analysis features were not enabled.
|
||||
|
||||
## PAN-297797
|
||||
|
||||
Fixed an issue where, during a refresh of a large External Dynamic List (EDL), traffic that matched a domain on the list was incorrectly identified as a different domain, which resulted in false positive threat logs.
|
||||
|
||||
## PAN-297782
|
||||
|
||||
Fixed an issue on Panorama where reassociating a vsys from one device group to another in a multi-vsys environment resulted in another vsys from the same firewall being removed from the original device group. This resulted in the device being moved into the no device groups attached group, a superuser was required to manually reattach the device.
|
||||
|
||||
## PAN-297775
|
||||
|
||||
Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual Systems field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs.
|
||||
|
||||
## PAN-296752
|
||||
|
||||
Fixed an issue where the firewall experienced high management CPU usage and repeatedly rebooted when attempting to retrieve SMART data.
|
||||
|
||||
## PAN-295221
|
||||
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and Threat logs were not forwarded to a Splunk server over UDP.
|
||||
|
||||
## PAN-293848
|
||||
|
||||
Fixed an issue where Panorama failed to push the default value of None for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as None in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
|
||||
|
||||
## PAN-293847
|
||||
|
||||
Fixed an issue where EAL logs for traffic matching the intrazone-default Security policy rule were not forwarded to the IoT Security portal.
|
||||
|
||||
## PAN-297240
|
||||
|
||||
Fixed an issue where attempting to generate reports in a WildFire FIPS Private Cloud or WF-500 deployment returned 401 errors.
|
||||
|
||||
## PAN-296490
|
||||
|
||||
```caveat
|
||||
FIPS CC mode enabled only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama on GCP rebooted every hour after upgrading to an affected release.
|
||||
|
||||
## PAN-296453
|
||||
|
||||
Fixed an issue where decryption exclusion lists were not working for untrusted certificates, and SSL sessions were still being decrypted even after adding them to the exclusion list. This occurred because the firewall was not adding sessions to the exclude cache until after receiving a non-RFC alert (BadCertificate) from the server. The fix ensures that the first session is added to the exclude cache, allowing subsequent sessions to skip decryption. This issue affects firewalls configured as clients in server-client communication.
|
||||
|
||||
## PAN-295944
|
||||
|
||||
Fixed an issue where static routes remained active in the FIB and RIB even when the associated physical port interface was down, which resulted in traffic being incorrectly routed through a non-operational interface.
|
||||
|
||||
## PAN-295560
|
||||
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors, tunnel logs were not visible in Panorama or Splunk even though traffic and threat logs were received.
|
||||
|
||||
## PAN-295484
|
||||
|
||||
Fixed an issue where SD-WAN did not generate system logs with timestamps and reasons for degradation of Direct Internet Access paths.
|
||||
|
||||
## PAN-295470
|
||||
|
||||
Fixed an issue on the firewall where the useridd process continuously increased its memory consumption, which resulted in an OOM condition that caused the firewall to restart.
|
||||
|
||||
## PAN-295257
|
||||
|
||||
Fixed an issue where, after onboarding a firewall to Panorama, IPsec tunnels displayed IKEv2 in Panorama, even though the tunnels were configured with IKEv1 locally on the firewall.
|
||||
|
||||
## PAN-294893
|
||||
|
||||
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
|
||||
## PAN-294770
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations
|
||||
```
|
||||
|
||||
Fixed an issue on firewalls where, after failover, certain subnets were missing from the Link State Database, which prevented OSPF routes from being immediately learned due to a Type-7 to Type-5 LSA translation conflict in the ABR when the same LSA was advertised by two peers in the NSSA area.
|
||||
|
||||
## PAN-294524
|
||||
|
||||
Fixed an issue where firewalls and Panorama management servers were unable to view or download WildFire reports from a WF-500 appliance, resulting in a 401 error in the report tab.
|
||||
|
||||
## PAN-292393
|
||||
|
||||
Fixed an issue where TFTP file transfers intermittently timed out in active-active HA pairs when the TFTP control channel was processed by one firewall and the data channel was processed by the other. This occurred because the firewall receiving the data channel failed to match the predicted session due to asynchronous processing of HA messages.
|
||||
|
||||
## PAN-292261
|
||||
|
||||
Fixed an issue where the firewall repeatedly reported an unreachable syslog server as back online when the server remained unavailable. This resulted in misleading alternating connection status messages in the system logs.
|
||||
|
||||
## PAN-291716
|
||||
|
||||
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM) conditions, leading to device crashes and reboots.
|
||||
|
||||
## PAN-291661
|
||||
|
||||
Fixed an issue on Panorama appliances and Log Collectors where, after an upgrade, Elasticsearch intermittently entered into a Red state before automatically recovering.
|
||||
|
||||
## PAN-291653
|
||||
|
||||
Fixed an issue where the GlobalProtect host ID field was intermittently blank in traffic logs on Prisma Access, even when the user was connected and had the correct host ID information. This occurred when the IP address to host ID entry expired and the entry was re-insterted without the dataplane flag being set.
|
||||
|
||||
## PAN-291288
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a pan_task process restart related to page allocation failures.
|
||||
|
||||
## PAN-290453
|
||||
|
||||
```caveat
|
||||
PA-7500 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where PA-7500 firewalls experienced silent traffic drops. During migration from PA-7050 to PA-7500 firewalls connected in series, intermittent connection losses occurred for some applications. Traffic leaving the PA-7050 was not received or processed by the PA-7500, even with direct connections and replaced cables/SFPs. Global counters did not indicate any drops on the PA-7500.
|
||||
|
||||
## PAN-289859
|
||||
|
||||
```caveat
|
||||
Panorama virtual appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama failed to mount logging disks larger than 2TB due to a partitioning error.
|
||||
|
||||
## PAN-289405
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Added the CLI command no-refresh-discard-session to address an issue where the discarded session time to live (TTL) did not refresh at the default value.
|
||||
|
||||
## PAN-289249
|
||||
|
||||
Fixed an issue where a memory leak occurred on the reportd process when a WildFire update was initiated while device telemetry data collection was in progress. This resulted in an OOM condition.
|
||||
|
||||
## PAN-289067
|
||||
|
||||
Fixed an issue where, after upgrading Panorama in a High Availability (HA) pair, the configuration logs stopped synchronizing from the primary Panorama to the secondary Panorama. This issue occurred because the log forwarding flag was permanently disabled due to the connection state not being active when the log-fwd-ctrl message was received.
|
||||
|
||||
## PAN-288761
|
||||
|
||||
Fixed an issue on the firewall where the logrcvr process stopped responding.
|
||||
|
||||
## PAN-288388
|
||||
|
||||
Fixed an issue where, after an EDL certificate update or repository migration, authentication failures caused the firewall to not fall back to the last successfully cached EDL entries, which led to policy rules that referenced the EDL to not be enforced.
|
||||
|
||||
## PAN-287803
|
||||
|
||||
Fixed an issue where, after upgrading the firewall, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.
|
||||
|
||||
## PAN-287782
|
||||
|
||||
Fixed an issue where firewalls configured in vwire mode modified DSCP values from AF11 to CS0 on traffic passing through the firewall, even when QoS policy rules and DSCP rewrite settings were not configured.
|
||||
|
||||
## PAN-287693
|
||||
|
||||
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when Use Proxy Settings for Private Cloud was enabled.
|
||||
|
||||
## PAN-287622
|
||||
|
||||
Fixed an issue where IPv6 traffic was affected after upgrading the firewall.With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.
|
||||
|
||||
## PAN-287423
|
||||
|
||||
Fixed an issue where content loading issues occurred on IPv6 websites due to the firewall incorrectly setting the IPv6 header flow label to 0.
|
||||
|
||||
## PAN-287314
|
||||
|
||||
Fixed an issue with firewalls in active/passive HA configurations where an OOM condition occurred and caused a failover due to a memory leak associated with the logrcvr process.
|
||||
|
||||
## PAN-285648
|
||||
|
||||
Fixed an issue where the log receiver process crashed on PA-7050 firewalls due to system log processing threads becoming blocked when the queue was full. This resulted in a heartbeat failure.
|
||||
|
||||
## PAN-285169
|
||||
|
||||
Fixed an issue on Panorama where Kerberos superusers were unable to edit policy rules because the target device tab was grayed out.
|
||||
|
||||
## PAN-284872
|
||||
|
||||
Fixed an issue where ENA (Elastic Network Adapter) extended statistics (conntrack allowance metric) were unavailable in DPDK 22.11.x. This metric is now available through AWS Cloudwatch.
|
||||
|
||||
## PAN-283053
|
||||
|
||||
Fixed an issue where the firewall experienced high disk space utilization, which caused the firewall to become non-functional.
|
||||
|
||||
## PAN-282093
|
||||
|
||||
Enhanced the CLI command request legacy reset to delete the legacy certificate files that were being used to connect with the secondary Panorama appliance.
|
||||
|
||||
## PAN-281797
|
||||
|
||||
Fixed an issue where firewalls became unstable and stopped responding, which resulted in an OOM condition.
|
||||
|
||||
## PAN-278322
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not display the correct source user in traffic logs and session details.
|
||||
|
||||
## PAN-277682
|
||||
|
||||
Fixed an issue where moving an address object from a device group to shared and renaming it did not reflect in the address group, which caused commits to fail.
|
||||
|
||||
## PAN-277034
|
||||
|
||||
Fixed an issue where WildFire reports were not fully displayed and were not downloadable due to static resources not being found.
|
||||
|
||||
## PAN-276525
|
||||
|
||||
Resolved multiple issues affecting IPSec tunnels using NAT Traversal (NAT-T) when a Dynamic NAT policy was configured (including Dynamic NAT or DIPP). During rekey events, tunnels could go down or flap due to incorrect session handling. This issue impacted both cluster and standalone deployments.
|
||||
|
||||
## PAN-272539
|
||||
|
||||
```caveat
|
||||
Panorama appliances on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where user to IP address mapping was missing for some users connected to specific Prisma Access gateways, which caused the collection layer Azure firewall to not form the mapping.
|
||||
|
||||
## PAN-271507
|
||||
|
||||
```caveat
|
||||
PA-5450 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the DPC on slot 3 intermittently stopped responding due an all_pktproc restart.
|
||||
|
||||
## PAN-267704
|
||||
|
||||
Fixed an issue where the firewall did not send an ICMP error packet to Envoy when the MSS was exceeded.
|
||||
|
||||
## PAN-267450
|
||||
|
||||
Fixed an issue where the reported process stopped responding with a SIGSEGV at schedule_report_es_response.
|
||||
|
||||
## PAN-262444
|
||||
|
||||
Fixed an issue where the firewall did not refresh the external dynamic list due to the first entry in the list being removed from the global external list and breaking out of the loop.
|
||||
|
||||
## PAN-260185
|
||||
|
||||
Fixed an issue where a dataplane crash occurred in Inline Cloud Analysis action lookup because there were no vulnerability or antispyware profiles in the security policy rule.
|
||||
|
||||
## PAN-258039
|
||||
|
||||
Fixed an issue where the firewall displayed the incorrect rule name when a threat log was generated for Inline Cloud Analyzed CMD Injection Traffic Detection.
|
||||
|
||||
## PAN-255253
|
||||
|
||||
Fixed an issue where the firewall did not establish a syslog connection to the probe VM syslog server in ADEM Regressions.
|
||||
|
||||
## PAN-253963
|
||||
|
||||
```caveat
|
||||
Panorama appliances in Panorama mode and Log Collector mode only
|
||||
```
|
||||
|
||||
Fixed an issue where autocommits took longer than expected to complete.
|
||||
|
||||
## PAN-251715
|
||||
|
||||
Fixed an issue where the firewall closed the SSL connection to the user ID agent.
|
||||
|
||||
## PAN-251646
|
||||
|
||||
Fixed an issue where commits failed with the error message Error: Error unserializing profile objects. This occurred due to memory allocation issues when a large number of scan profiles were configured.
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.10-h9
|
||||
---
|
||||
|
||||
## PAN-297295
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall repeatedly restarted due to high packet rates on the synthetic path in DPDK mode.
|
||||
@@ -0,0 +1,425 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 11.1.10
|
||||
---
|
||||
|
||||
## PAN-307795
|
||||
|
||||
On a standalone Panorama, the system incorrectly generates system logs indicating a lost connection to its peer even when High Availability is not configured. You can safely ignore these logs, as they do not affect operations.
|
||||
|
||||
## PAN-306502
|
||||
|
||||
TLS sessions using version 1.2 or earlier may fail when session traffic matches a decryption policy rule with the no-decrypt action under either of the following conditions:
|
||||
|
||||
If both of these conditions are met, the session is guaranteed to fail.
|
||||
|
||||
If both of these conditions are met, the session is guaranteed to fail.
|
||||
|
||||
If both of these conditions are met, the session is guaranteed to fail.
|
||||
|
||||
Both HTTP header insertion (ObjectsSecurity ProfilesURL FilteringHTTP Header Insertion) and SSL/TLS handshake inspection (DeviceSetupSessionDecryption SettingsSSL Decryption Settings) are enabled.
|
||||
|
||||
Both HTTP header insertion (ObjectsSecurity ProfilesURL FilteringHTTP Header Insertion) and SSL/TLS handshake inspection (DeviceSetupSessionDecryption SettingsSSL Decryption Settings) are enabled.
|
||||
|
||||
Log Successful SSL Handshake is not enabled in the decryption policy rule and neither Block sessions with expired certificates nor Block sessions with untrusted issuers is enabled in the attached decryption profile.
|
||||
|
||||
Log Successful SSL Handshake is not enabled in the decryption policy rule and neither Block sessions with expired certificates nor Block sessions with untrusted issuers is enabled in the attached decryption profile.
|
||||
|
||||
Workaround: Perform one of the following tasks:
|
||||
|
||||
Enable Log Successful SSL Handshake in all no-decrypt decryption policy rules.
|
||||
|
||||
Enable Log Successful SSL Handshake in all no-decrypt decryption policy rules.
|
||||
|
||||
Enable either Block sessions with expired certificates or Block sessions with untrusted issuers in the decryption profiles attached to the no-decrypt decryption policy rules.
|
||||
|
||||
## PAN-305301
|
||||
|
||||
The timing of GlobalProtect lifetime expiry or inactivity logout notifications used for GlobalProtect SSL tunnels may cause the pan_task process to stop responding and the dataplane to restart.
|
||||
|
||||
Workaround: Select Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings and change the value of both Notify Before Lifetime Expires (min) and Notify Before Inactivity Logout (min) to 0.
|
||||
|
||||
## PAN-304756
|
||||
|
||||
After you disable the shared optimization feature in Panorama, ensure that you perform a full configuration push to all managed multi-vsys devices to re-establish a baseline. Failure to include every device group associated with the multi-vsys device during this push might result in incomplete or inconsistent configurations across virtual systems.
|
||||
|
||||
## PAN-304576
|
||||
|
||||
Traffic interruption may occur when inspection of HTTP/2 traffic is enabled.
|
||||
|
||||
Workaround: Disable HTTP/2 server push using the set deviceconfig setting http2 server-push no CLI command.
|
||||
|
||||
## PAN-303959
|
||||
|
||||
Traffic that is incorrectly identified as unknown-tcp/unknown-udp eventually drops due to an App-ID resource limitation issue.
|
||||
|
||||
## PAN-298505
|
||||
|
||||
After upgrading multi-vsys firewalls, the sequence of the virtual system IDs (vsys ID) changes causing auto-commit failures with validation errors. This occurs when the multi-vsys firewall has virtual systems managed by Panorama, and the vsys ID sequence breaks when unused virtual systems are deleted and the changes are pushed to the firewall.
|
||||
|
||||
## PAN-297295
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
After upgrading to an affected release, the firewall restarts continuously because the brdagent process restarts multiple times and exhausts its restart limit, resulting in a segfault error. This issue occurs when a high burst of traffic is sent to the Azure PA-VM (Palo Alto Networks Virtual Machine), and impacts production environments due to the regular reboots.
|
||||
|
||||
Workaround: Migrate the VM instance to Dv5 instance type. On these instance types, SYN packets are not routed to the synthetic path, avoiding this condition. Suggested direct resizing paths are:D3_v2/DS3_v2 to D8ds_v5D4_v2/DS4_v2 to D8ds_v5D5_v2/DS5_v2 to D16ds_v5 Azure VMs with ephemeral storage can only be resized to another type with ephemeral storage.
|
||||
|
||||
D3_v2/DS3_v2 to D8ds_v5
|
||||
|
||||
D4_v2/DS4_v2 to D8ds_v5
|
||||
|
||||
D5_v2/DS5_v2 to D16ds_v5
|
||||
|
||||
Azure VMs with ephemeral storage can only be resized to another type with ephemeral storage.
|
||||
|
||||
Azure VMs with ephemeral storage can only be resized to another type with ephemeral storage.
|
||||
|
||||
Azure VMs with ephemeral storage can only be resized to another type with ephemeral storage.
|
||||
|
||||
## PAN-296977
|
||||
|
||||
When you apply a filter in Network > Interfaces and then try to view Ethernet interface details using the web interface, the web interface becomes unresponsive.
|
||||
|
||||
## PAN-294179
|
||||
|
||||
On the Panorama Config Audit page, some commit versions might display incorrect or missing data. Fields such as, COMMITTED BY , COMMIT DATE , and OBJECT CHANGES might not be visible for some commit versions. Sometimes, commit versions can disappear after a refresh and the commit description field might display corrupted characters.
|
||||
|
||||
## PAN-293673
|
||||
|
||||
When the firewall generates a high volume of logs and attempts to export these logs to an FTP server, it may consume excessive memory leading to all PAN-OS processes crashing.
|
||||
|
||||
## PAN-292202
|
||||
|
||||
The system logs repeatedly displayed the alert `Clearing snmpd.log due to log overflow` due to the SNMP counters rolling over. This is a benign message and does not impact device functionality.
|
||||
|
||||
## PAN-289432
|
||||
|
||||
Generating a certificate with the block-private-key yes command on Panorama fails with the error:
|
||||
|
||||
Could not get parameters for double encryption. This occurred when the certificate was signed by an external Certificate Authority (CA).
|
||||
|
||||
## PAN-290996
|
||||
|
||||
When performing an SNMP walk, the Connections Per Second (CPS) counters incorrectly return a value of 0 for each virtual system (VSYS), despite the firewall actively processing connections.
|
||||
|
||||
## PAN-290235
|
||||
|
||||
The dscd process crashes continuously on MIPS platforms (for example, PA-850 firewalls) due to a runtime error related to an invalid memory address or nil pointer dereference. This occurs when the golang library upgrade in CIE is not compatible with the MIPS platform.
|
||||
|
||||
## PAN-290088
|
||||
|
||||
When pushing configurations from Panorama to a firewall, a memory leak might occur in the firewall's configd process, particularly when the configurations contain shared policies. Each configuration push causes the configd process to consume additional memory that is not released after the commit completes.
|
||||
|
||||
## PAN-289383
|
||||
|
||||
```caveat
|
||||
PA-800 series firewalls only
|
||||
```
|
||||
|
||||
Upgrading firewalls to PAN-OS 11.0 or later causes SFP ports to go non-operational when the firewall uses forced port mode and the connected peer device operates without auto-negotiation.
|
||||
|
||||
Workaround: Enable auto-negotiation on the connected peer firewall.
|
||||
|
||||
## PAN-288097
|
||||
|
||||
Routed process may stop responding after changing MTU or any link parameters when OSPF and PIM are enabled on the same interface.
|
||||
|
||||
## PAN-287056
|
||||
|
||||
A BGP export policy rule that matches on a next hop fails to block the advertisement of static routes, and the firewall incorrectly matches the egress interface IP address instead of the original next-hop IP address of the static route, which causes the deny rule to fail.
|
||||
|
||||
## PAN-286848
|
||||
|
||||
ECMP incorrectly balances sessions across links based on the configured metric, which leads to an imbalance in traffic distribution and results in traffic assignment shifting disproportionately to routes with lower metrics.
|
||||
|
||||
## PAN-286496
|
||||
|
||||
```caveat
|
||||
NGFW Clusters
|
||||
```
|
||||
|
||||
URL-continue and override continue selections will function like a general URL-block action.
|
||||
|
||||
## PAN-286306
|
||||
|
||||
When getting transceiver information from ESCC for SFP 25G modules, the transceiver code incorrectly displays Unknown instead of 25GBase-SR.
|
||||
|
||||
## PAN-286231
|
||||
|
||||
When performing a partial Commit and Push on Panorama, there is a risk that unintended configuration changes might be pushed to a firewall.
|
||||
|
||||
This issue is more likely to occur in the following scenarios:When you run Commit and Push operations as a single action.When you trigger multiple parallel commit-all jobs at the same time.Device groups and templates have different configuration synchronization versions.
|
||||
|
||||
When you run Commit and Push operations as a single action.
|
||||
|
||||
When you run Commit and Push operations as a single action.
|
||||
|
||||
When you trigger multiple parallel commit-all jobs at the same time.
|
||||
|
||||
When you trigger multiple parallel commit-all jobs at the same time.
|
||||
|
||||
Device groups and templates have different configuration synchronization versions.
|
||||
|
||||
Device groups and templates have different configuration synchronization versions.
|
||||
|
||||
Workaround: Perform one of the following steps:
|
||||
|
||||
Perform commit and push as two separate, sequential steps.
|
||||
|
||||
Perform a full push instead of selective push.
|
||||
|
||||
## PAN-285894
|
||||
|
||||
If the Preserve Pre-NAT feature is enabled, dataplane crashes may occur, which could result in firewall reboots.
|
||||
|
||||
Workaround: Disable the Preserve Pre-NAT feature using the set deviceconfig setting preserve-prenat-feature no CLI command.
|
||||
|
||||
## PAN-283429
|
||||
|
||||
When you use custom certificates for the connection between Panorama and a log collector, the automated renewal for the predefined ElasticSearch certificates gets disrupted.
|
||||
|
||||
Workaround: Remove the custom certificates before the ElasticSearch certificates expire. This allows the system to correctly identify and renew the predefined ElasticSearch certificates. After the renewal is complete, re-install the custom certificates.
|
||||
|
||||
## PAN-282854
|
||||
|
||||
The Elasticsearch cluster fails to start after deploying dedicated log collectors in a multi-collector environment.
|
||||
|
||||
## PAN-279901
|
||||
|
||||
When decryption is enabled, segmented Client Hello packets can cause website access issues and memory leaks under the following conditions:
|
||||
|
||||
The segmented Client Hello packets arrive out-of-order
|
||||
|
||||
The segmented Client Hello packets arrive out-of-order
|
||||
|
||||
The segmented Client Hello packets arrive out-of-order and can be reassembled into a complete Client Hello when the first contiguous segment is formed by NGFW
|
||||
|
||||
The segmented Client Hello packets arrive out-of-order and can be reassembled into a complete Client Hello when the first contiguous segment is formed by NGFW
|
||||
|
||||
The first segment of the Client Hello packets is less than 5 bytes
|
||||
|
||||
The first segment of the Client Hello packets is less than 5 bytes
|
||||
|
||||
A decryption policy rule excludes this traffic from decryption and a Security policy rule (URL filtering) denies this session
|
||||
|
||||
A decryption policy rule excludes this traffic from decryption and a Security policy rule (URL filtering) denies this session
|
||||
|
||||
To enable this fix, run the CLI command bug dataplane set ssl-decrypt accumulate-client-hello disjoined yes
|
||||
|
||||
## PAN-279415
|
||||
|
||||
Service routes configured for a data plane interface might incorrectly route traffic through the management plane interface instead. This issue impacts Syslog and CRL status traffic when the service route lacks a specific destination custom service route.
|
||||
|
||||
## PAN-277034
|
||||
|
||||
WildFire reports might not fully display or be downloadable because some static resources fail to load.
|
||||
|
||||
## PAN-276920
|
||||
|
||||
URL filtering response pages may load slowly or fail to display when users request websites that are blocked in the URL Filtering profile (site access for the corresponding URL category is block, continue, or override) attached to the matching Security policy rule. This occurs on an intermittent basis.
|
||||
|
||||
## PAN-275047
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
After an upgrade, the firewall is unable to send logs to the Strata Logging Service (SLS) when using a specific proxy server, and the SSL connection status displays as failed when attempting to forward logs through the web proxy.
|
||||
|
||||
## PAN-262556
|
||||
|
||||
The ElasticSearch cluster health status might continue to remain yellow for an extended period after upgrading to PAN-OS 11.1
|
||||
|
||||
## PAN-260851
|
||||
|
||||
From the NGFW or Panorama CLI, you can override the existing application tag even if Disable Override is enabled for the application (ObjectsApplications) tag.
|
||||
|
||||
## PAN-254240
|
||||
|
||||
In the event of an HSCI flap on an NGFW cluster node, traffic reconvergence takes three to four seconds.
|
||||
|
||||
## PAN-253963
|
||||
|
||||
The auto commit job may take longer than expected to complete when the Panorama management server is in Panorama or Log Collector mode.
|
||||
|
||||
## PAN-251551
|
||||
|
||||
When an NGFW cluster agent crashes and doesn't recover, leader election will take approximately 45 seconds to begin and traffic failover will occur during that time.
|
||||
|
||||
## PAN-250903
|
||||
|
||||
In a congestion scenario on an HSCI port of an NGFW cluster node, the QoS priorities of cross node traffic streams might be reversed if you're using the default QoS profile with class1 to class8 set as high to low.
|
||||
|
||||
## PAN-247974
|
||||
|
||||
LACP flap is expected during a device failover in an NGFW cluster due to an L2 ctrld restart on the new leader node.
|
||||
|
||||
## PAN-234015
|
||||
|
||||
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
||||
|
||||
## PAN-224502
|
||||
|
||||
The autocommit time of the VM-Series firewall running PAN-OS 11.1.0 might take longer than expected.
|
||||
|
||||
## PAN-220180
|
||||
|
||||
Configured botnet reports (MonitorBotnet) are not generated.
|
||||
|
||||
## PAN-207733
|
||||
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls, if the DHCPv6 server goes down, after the lease time expires, the DHCPv6 client should enter SOLICIT state on both the Active and Passive firewalls. Instead, the client is stuck in BOUND state with an IPv6 address having lease time 0 on the Passive firewall.
|
||||
|
||||
## PAN-207611
|
||||
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls, the Passive firewall sometimes crashes.
|
||||
|
||||
## PAN-207442
|
||||
|
||||
For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the active-primary HA peer configuration sync to the secondary-passive HA peer may fail. When the config sync fails, the job Results is Successful (Tasks), however the sync status on the Dashboard displays as Out of Sync for both HA peers.
|
||||
|
||||
Workaround: Perform a local commit on the active-primary HA peer and then synchronize the HA configuration.
|
||||
|
||||
Log in to the Panorama web interface of the active-primary HA peer.
|
||||
|
||||
Log in to the Panorama web interface of the active-primary HA peer.
|
||||
|
||||
Select Commit and Commit to Panorama.
|
||||
|
||||
Select Commit and Commit to Panorama.
|
||||
|
||||
In the active-primary HA peer Dashboard, click Sync to Peer in the High Availability widget.
|
||||
|
||||
In the active-primary HA peer Dashboard, click Sync to Peer in the High Availability widget.
|
||||
|
||||
## PAN-207040
|
||||
|
||||
If you disable Advanced Routing, remove logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent commits fail and SD-WAN devices on Panorama have no Virtual Router name.
|
||||
|
||||
## PAN-206913
|
||||
|
||||
When a DHCPv6 client is configured on HA Active/Passive firewalls, releasing the IPv6 address from the client (using Release in the UI or using the request dhcp client ipv6 release all CLI command) releases the IPv6 address from the Active firewall, but not the Passive firewall.
|
||||
|
||||
## PAN-206909
|
||||
|
||||
The Dedicated Log Collector is unable to reconnect to the Panorama management server if the configd process crashes. This results in the Dedicated Log Collector losing connectivity to Panorama despite the managed collector connection Status (PanoramaManaged Collector) displaying connected and the managed colletor Health status displaying as healthy.
|
||||
|
||||
This results in the local Panorama config and system logs not being forwarded to the Dedicated Log Collector. Firewall log forwarding to the disconnected Dedicated Log Collector is not impacted.
|
||||
|
||||
Workaround: Restart the mgmtsrvr process on the Dedicated Log Collector.
|
||||
|
||||
Log in to the Dedicated Log Collector CLI.
|
||||
|
||||
Log in to the Dedicated Log Collector CLI.
|
||||
|
||||
Confirm the Dedicated Log Collector is disconnected from Panorama.admin> show panorama-status Verify the Connected status is no.
|
||||
|
||||
Confirm the Dedicated Log Collector is disconnected from Panorama.
|
||||
|
||||
admin> show panorama-status Verify the Connected status is no.
|
||||
|
||||
admin> show panorama-status
|
||||
|
||||
admin> show panorama-status
|
||||
|
||||
Verify the Connected status is no.
|
||||
|
||||
Restart the mgmtsrvr process.admin> debug software restart process management-server
|
||||
|
||||
Restart the mgmtsrvr process.
|
||||
|
||||
admin> debug software restart process management-server
|
||||
|
||||
admin> debug software restart process management-server
|
||||
|
||||
admin> debug software restart process management-server
|
||||
|
||||
## PAN-197588
|
||||
|
||||
The PAN-OS ACC (Application Command Center) does not display a widget detailing statistics and data associated with vulnerability exploits that have been detected using inline cloud analysis.
|
||||
|
||||
## PAN-197419
|
||||
|
||||
```caveat
|
||||
PA-1400 Series firewalls only
|
||||
```
|
||||
|
||||
In NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a Tag value.
|
||||
|
||||
## PAN-196758
|
||||
|
||||
On the Panorama management server, pushing a configuration change to firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP configurations for SD-WAN as being edited or deleted despite no edits or deletions being made when you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections).
|
||||
|
||||
## PAN-195968
|
||||
|
||||
```caveat
|
||||
PA-1400 Series firewalls only
|
||||
```
|
||||
|
||||
When using the CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI prints an error depending on whether an interface type was selected on the non-PoE port or not. If an interface type, such as tap, Layer 2, or virtual wire, was selected before PoE was configured, the error message will not include the interface name (eg. ethernet1/4). If an interface type was not selected before PoE was configured, the error message will include the interface name.
|
||||
|
||||
## PAN-194978
|
||||
|
||||
```caveat
|
||||
PA-1400 Series firewalls only
|
||||
```
|
||||
|
||||
In NetworkInterfaceEthernet, hovering the mouse over a power over Ethernet (PoE) Link State icon does not display link speed and link duplex details.
|
||||
|
||||
## PAN-187685
|
||||
|
||||
On the Panorama management server, the Template Status displays no synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama.
|
||||
|
||||
Workaround: After the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and select CommitPush to Devices.
|
||||
|
||||
## PAN-187407
|
||||
|
||||
The configured Advanced Threat Prevention inline cloud analysis action for a given model might not be honored under the following condition: If the firewall is set to Hold client request for category lookup and the action set to Reset-Both and the URL cache has been cleared, the first request for inline cloud analysis will be bypassed.
|
||||
|
||||
## PAN-186283
|
||||
|
||||
Templates appear out-of-sync on Panorama after successfully deploying the CFT stack using the Panorama plugin for AWS.
|
||||
|
||||
Workaround: Use CommitPush to Devices to synchronize the templates.
|
||||
|
||||
## PAN-184708
|
||||
|
||||
```caveat
|
||||
Panorama managed firewalls
|
||||
```
|
||||
|
||||
Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if:
|
||||
|
||||
A scheduled report email contains a Report Group (MonitorPDF ReportsReport Group) which includes a SaaS Application Usage report.
|
||||
|
||||
A scheduled report contains only a SaaS Application Usage Report.
|
||||
|
||||
Workaround: To receive a scheduled report email for all other PDF report types:
|
||||
|
||||
Select MonitorPDF ReportsReport Groups and remove all SaaS Application Usage reports from all Report Groups.
|
||||
|
||||
Select MonitorPDF ReportsEmail Scheduler and edit the scheduled report email that contains only a SaaS Application Usage report. For the Recurrence, select Disable and click OK.Repeat this step for all scheduled report emails that contain only a SaaS Application Usage report.
|
||||
|
||||
Repeat this step for all scheduled report emails that contain only a SaaS Application Usage report.
|
||||
|
||||
Commit.() Select CommitCommit and Push
|
||||
|
||||
() Select CommitCommit and Push
|
||||
|
||||
## PAN-184406
|
||||
|
||||
Using the CLI to add a RAID disk pair to an M-700 appliance causes the dmdb process to crash.
|
||||
|
||||
Workaround: Contact customer support to stop the dmdb process before adding a RAID disk pair to a M-700 appliance.
|
||||
|
||||
## PAN-183404
|
||||
|
||||
Static IP addresses are not recognized when "and" operators are used with IP CIDR range.
|
||||
|
||||
## PAN-181933
|
||||
|
||||
If you use multiple log forwarding cards (LFCs) on the PA-7000 series, all of the cards may not receive all of the updates and the mappings for the clients may become out of sync, which causes the firewall to not correctly populate the Source User column in the session logs.
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,193 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.12
|
||||
---
|
||||
|
||||
## PAN-303737
|
||||
|
||||
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to session-distribution commands in dagger files handling.
|
||||
|
||||
## PAN-300916
|
||||
|
||||
Fixed an issue where Panorama management servers failed to forward syslog messages via TLS to a syslog server when DNS resolution for IPv6 addresses failed, and the system did not automatically fall back to IPv4.
|
||||
|
||||
## PAN-300906
|
||||
|
||||
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to missing XML-related functions for inline-cloud-proxy.
|
||||
|
||||
## PAN-300837
|
||||
|
||||
Fixed an issue where firewalls experienced multiple reboots due to the pan_task process restarting with a SIGSEGV signal. This occurred because the client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||
|
||||
## PAN-300612
|
||||
|
||||
```caveat
|
||||
PA-7500 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall incorrectly reported the speed of 400G interfaces as 1G when queried using SNMP
|
||||
|
||||
## PAN-300096
|
||||
|
||||
Fixed an issue where a local commit on a firewall breaks template stack overrides, preventing the enabling of LACP (Link Aggregation Control Protocol). After a local commit, the LACP enable check was unexpectedly unchecked, causing an outage. Attempting to re-enable LACP through the web interface was unsuccessful, requiring manual removal of the LACP configuration from the Panorama CLI.
|
||||
|
||||
## PAN-299815
|
||||
|
||||
Fixed an issue on multi-vsys firewalls where a host was not removed from the quarantine list after receiving a redistribution message from Panorama. This occurred when Panorama was configured to redistribute quarantine messages to a firewall cluster, and the GlobalProtect configuration and redistribution were built out in a vsys other than vsys1.
|
||||
|
||||
## PAN-299785
|
||||
|
||||
```caveat
|
||||
PA-7500 and PA-5450 firewalls in FIPS-CC mode
|
||||
```
|
||||
|
||||
Fixed an issue where the affected firewalls would boot into maintenance mode when a reboot was initiated from the web interface. This was due to a device reboot triggering a power down to all slots, leading to maintenance mode. A hard reboot would allow the firewall to boot normally.
|
||||
|
||||
## PAN-299772
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in active/passive configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an HA failover event, the newly active firewall DHCP client interfaces failed to obtain IP addresses automatically. This occurred because the DHCP client processes did not initiate the necessary DHCP discover or renew requests
|
||||
|
||||
## PAN-298872
|
||||
|
||||
```caveat
|
||||
PA-400 Series firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where ports went down after an HA failover.
|
||||
|
||||
## PAN-298654
|
||||
|
||||
Fixed an issue where the firewall generated false positive threat logs during updates to a large domain list (EDL) when a DNS lookup for a domain being added or removed occurred during the update process. This resulted in a threat log being generated for a different, unrelated domain that remained on the list.
|
||||
|
||||
## PAN-298505
|
||||
|
||||
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, the vsys ID changed in sequence, causing autocommit failures with validation errors. This occurred when the multi-vsys firewall had virtual systems created and pushed from Panorama, and the vsys ID was not in a correct sequence because the unused vsys was deleted from Panorama and pushed to devices.
|
||||
|
||||
## PAN-297972
|
||||
|
||||
Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis prefiltering signatures, even when Inline Cloud Analysis features were not enabled.
|
||||
|
||||
## PAN-297797
|
||||
|
||||
Fixed an issue where, during a refresh of a large External Dynamic List (EDL), traffic that matched a domain on the list was incorrectly identified as a different domain, which resulted in false positive threat logs.
|
||||
|
||||
## PAN-297759
|
||||
|
||||
Fixed an issue on PA-7500 firewalls running in a cluster where sub-interfaces were not discoverable via SNMP, which prevented proper monitoring and statistics collection for sub-interfaces using SNMP-based tools.
|
||||
|
||||
## PAN-297708
|
||||
|
||||
Fixed an issue where a long-lived session with many Machine Learning (ML) model triggers caused a memory leak of feature states associated with the ML model runs. This resulted in Spyware_State failure increases, allocation max outs, and impaired policy matching.
|
||||
|
||||
## PAN-297610
|
||||
|
||||
Fixed an issue where the firewall became unresponsive after an upgrade due to the fsck command scanning drive partitions in parallel with the root partition, which caused the process to take an extended amount of time.
|
||||
|
||||
## PAN-296490
|
||||
|
||||
```caveat
|
||||
FIPS CC mode enabled only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama on GCP rebooted every hour after upgrading to 11.1.6-h10. Panorama will run for up to an hour and then crash.
|
||||
|
||||
## PAN-296453
|
||||
|
||||
Fixed an issue where decryption exclusion lists were not working for untrusted certificates, and SSL sessions were still being decrypted even after adding them to the exclusion list. This occurred because the firewall was not adding sessions to the exclude cache until after receiving a non-RFC alert (BadCertificate) from the server. The fix ensures that the first session is added to the exclude cache, allowing subsequent sessions to skip decryption. This issue affects firewalls configured as clients in server-client communication.
|
||||
|
||||
## PAN-295221
|
||||
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors from PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not forwarded to a Splunk server over UDP.
|
||||
|
||||
## PAN-294893
|
||||
|
||||
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect Security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
|
||||
## PAN-293848
|
||||
|
||||
Fixed an issue where Panorama failed to push the default value of None for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as None in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
|
||||
|
||||
## PAN-292447
|
||||
|
||||
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
|
||||
## PAN-292393
|
||||
|
||||
Fixed an issue where TFTP file transfers intermittently timed out in active-active HA pairs when the TFTP control channel was processed by one firewall and the data channel was processed by the other. This occurred because the firewall receiving the data channel failed to match the predicted session due to asynchronous processing of HA messages.
|
||||
|
||||
## PAN-291716
|
||||
|
||||
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM) conditions, leading to device crashes and reboots.
|
||||
|
||||
## PAN-291174
|
||||
|
||||
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams did not work when connected through GlobalProtect due to the firewall blocking 200 OK responses. This occurred because of incorrect NAT translations for the 200 OK message from the server.
|
||||
|
||||
## PAN-291067
|
||||
|
||||
Fixed an issue where the devsrvr process periodically exceeded its virtual memory limit and restarted, which led to intermittent outages.
|
||||
|
||||
## PAN-290453
|
||||
|
||||
Fixed an issue where PA-7500 firewalls experienced silent traffic drops. During migration from PA-7050 to PA-7500 firewalls connected in series, intermittent connection losses occurred for some applications. Traffic leaving the PA-7050 was not received or processed by the PA-7500, even with direct connections and replaced cables/SFPs. Global counters did not indicate any drops on the PA-7500.
|
||||
|
||||
## PAN-289714
|
||||
|
||||
```caveat
|
||||
Prisma Access only
|
||||
```
|
||||
|
||||
Fixed an issue where persistent commit failures occurred due to a missing transformation script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0.
|
||||
|
||||
## PAN-288388
|
||||
|
||||
Fixed an issue where, after an EDL certificate update or repository migration, authentication failures caused the firewall to not fall back to the last successfully cached EDL entries, which led to policy rules that referenced the EDL to not be enforced.
|
||||
|
||||
## PAN-287803
|
||||
|
||||
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.
|
||||
|
||||
## PAN-287693
|
||||
|
||||
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when Use Proxy Settings for Private Cloud was enabled.
|
||||
|
||||
## PAN-287622
|
||||
|
||||
Fixed an issue where IPv6 traffic was affected after upgrading the firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.
|
||||
|
||||
## PAN-285648
|
||||
|
||||
Fixed an issue where the log receiver process crashed on PA-7050 firewalls due to system log processing threads becoming blocked when the queue was full. This resulted in a heartbeat failure.
|
||||
|
||||
## PAN-285315
|
||||
|
||||
Fixed an issue on Panorama where the log forwarding queue depth was not accurately displayed in the logd.log files.
|
||||
|
||||
## PAN-285169
|
||||
|
||||
Fixed an issue on Panorama where Kerberos superusers were unable to edit policy rules because the target device tab was grayed out.
|
||||
|
||||
## PAN-272245
|
||||
|
||||
Fixed an issue where the dnsproxy process crashed due to memory corruption caused by a race condition when the allow list downloading was impacted by config change.
|
||||
|
||||
## PAN-267704
|
||||
|
||||
Fixed an issue where the firewall did not send an ICMP error packet to Envoy when the MSS was exceeded.
|
||||
|
||||
## PAN-267450
|
||||
|
||||
Fixed an issue where the reportd process stopped responding with a SIGSEGV at schedule_report_es_response.
|
||||
|
||||
## PAN-262444
|
||||
|
||||
Fixed an issue where the firewall did not refresh the external dynamic list due to the first entry in the list being removed from the global external list and breaking out of the loop.
|
||||
|
||||
## PAN-251646
|
||||
|
||||
Fixed an issue where commits failed with the error message Error: Error unserializing profile objects. This occurred due to memory allocation issues when a large number of scan profiles were configured.
|
||||
@@ -0,0 +1,207 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.13-h1
|
||||
---
|
||||
|
||||
## PAN-309392
|
||||
|
||||
Fixed an issue where the scroll bar did not appear when editing Destination Addresses for Policy Based forwarding policy rules.
|
||||
|
||||
## PAN-309379
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding on DPCs, which prevented logs from being forwarded.
|
||||
|
||||
## PAN-308085
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where, after resizing the VM, the HA2 link became unstable. Frequent keep-alive failures occurred, and HA2 keep-alive packets were simultaneously transmitted to multiple destination MAC addresses and the peer firewall's interface MAC). This issue occurred on firewalls with Accelerated Networking enabled.
|
||||
|
||||
## PAN-308060
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the BFD session went down and did not recover even though the BGP remained in an established state, which caused the firewall to cease route learning and advertisement with the peer, even though BGP keep-alives were exchanged correctly.
|
||||
|
||||
## PAN-307901
|
||||
|
||||
Fixed an issue where a leak in decryption counters caused resource exhaustion, which led to a GlobalProtect service outage.
|
||||
|
||||
## PAN-307795
|
||||
|
||||
Fixed an issue where Panorama incorrectly generated system logs indicating a lost connection to its peer after an upgrade even when High Availability was not configured.
|
||||
|
||||
## PAN-305835
|
||||
|
||||
Fixed an issue where firewalls with Memory Integrity Checking Architecture enabled rebooted unexpectedly due to accessing an invalid memory address. This occurred because the forwarding data structure index exceeded its designed limit.
|
||||
|
||||
## PAN-305412
|
||||
|
||||
Fixed an issue where the Logging Service License Status displays a license failure when the license status transitions from valid to expired and then back to valid even when the connection to the Security Logging Service (SLS) was working.
|
||||
|
||||
## PAN-305411
|
||||
|
||||
Fixed an issue where, after creating a logical interface with an assigned IP address and adding it to a virtual router, the connected route for the interface did not appear in the show routing route CLI command output. This occurred even when the interface was up and learning ARP entries.
|
||||
|
||||
## PAN-305301
|
||||
|
||||
Fixed an issue where the timing of GlobalProtect lifetime expiry or inactivity logout notifications used for GlobalProtect SSL tunnels could cause the pan_task process to stop responding and the dataplane to restart.
|
||||
|
||||
## PAN-304756
|
||||
|
||||
Fixed an issue on Panorama where, after you disabled the shared optimization feature, a full configuration push to multi-vsys devices caused a validation error.
|
||||
|
||||
## PAN-304636
|
||||
|
||||
Fixed an issue where BGP aggregate routes were not created and discard routes were not installed in the routing table.
|
||||
|
||||
## PAN-304075
|
||||
|
||||
Fixed an issue where the firewall did not detect evasions due to TCP checksum offloading not being enabled.
|
||||
|
||||
## PAN-303959
|
||||
|
||||
Fixed an issue where traffic was incorrectly identified as unknown-tcp/unknown-udp due to App-ID resource leak and eventually dropped.
|
||||
|
||||
## PAN-303954
|
||||
|
||||
Fixed an issue where, when configuring Safenet HSMs in HA and authentication HSM manually, the second HSM server failed to authenticate due to the firewall overwriting the first HSM server's certificate with the second HSM server's certificate.
|
||||
|
||||
## PAN-303627
|
||||
|
||||
Fixed an issue where, after committing a configuration change, the firewall experienced traffic issues, pan_task crashes, and LACP interface failures.
|
||||
|
||||
## PAN-303559
|
||||
|
||||
Fixed an issue where, after manually creating a device telemetry bundle, the hour_cli_output.txt file within the bundle had a file size of 0 bytes. This occurred when checking the bundle content after enabling device telemetry and setting the device telemetry upload endpoint.
|
||||
|
||||
## PAN-302983
|
||||
|
||||
Fixed an issue where, after committing changes on Panorama, a shared post-rule moved to the end of the post shared rulebase on the managed device instead of remaining at the top.
|
||||
|
||||
## PAN-302551
|
||||
|
||||
Fixed an issue where the firewall displayed as disconnected in the SLS due to the serial number not being retrieved
|
||||
|
||||
## PAN-302428
|
||||
|
||||
Fixed an issue on Panorama where daily scheduled report emails for custom reports were delivered with no content and instead incorrectly displayed the message No matching data found. With this fix, the content is displayed correctly.
|
||||
|
||||
## PAN-302085
|
||||
|
||||
Fixed an issue where network values were not displayed in Panorama with the error message There is no value for the selected item. This was due to the device group passing vsysName in Panorama.
|
||||
|
||||
## PAN-301975
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the passive firewall incorrectly triggered PBP alerts even with low packet rates.
|
||||
|
||||
## PAN-301937
|
||||
|
||||
Fixed an issue where Microsoft Defender for Cloud detected cleartext SSH private keys in the /var/appweb and /etc/appweb directories on PA-VM firewalls deployed in Azure.
|
||||
|
||||
## PAN-301912
|
||||
|
||||
Fixed an issue where Panorama stopped responding when deploying dynamic updates to managed devices.
|
||||
|
||||
## PAN-301600
|
||||
|
||||
Fixed an issue on the firewall where, after upgrading Panorama, OSPF adjacencies remained in the exchange start state, which resulted in an incomplete routing table.
|
||||
|
||||
## PAN-301456
|
||||
|
||||
Fixed an issue on Panorama where the debug system reset-ztp CLI command was unavailable.
|
||||
|
||||
## PAN-301409
|
||||
|
||||
Fixed an issue where Panorama failed to perform a selective push to a managed device when device tags were added or modified on the policy rules. The selective push failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
||||
|
||||
## PAN-300837
|
||||
|
||||
Fixed an issue where firewalls experienced multiple reboots due to the pan_task process restarting with a SIGSEGV signal. This occurred because the client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||
|
||||
## PAN-300671
|
||||
|
||||
Fixed an issue where traffic reports that were generated with destination/source and destination/source hostnames were not displayed in IPv4 format.
|
||||
|
||||
## PAN-299751
|
||||
|
||||
Fixed an issue where the firewall was unable to connect to the Subscription License Service (SLS) due to a public and private key pair mismatch with the device certificate.
|
||||
|
||||
## PAN-299622
|
||||
|
||||
Fixed an issue where the MFA timestamp was not redistributed between standalone firewalls behind an Azure load balancer after upgrading, which resulted in users being prompted to reauthenticate multiple times.
|
||||
|
||||
## PAN-297263
|
||||
|
||||
```caveat
|
||||
PA-5220 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the ikemgr process stopped responding intermittently, which caused IPSec tunnels to go down randomly. With this fix, the IKE Security association data structures are accessed in a thread-safe manner, and the ikemgr process does not reference an invalid memory pointer during teardown operations.
|
||||
|
||||
## PAN-299622
|
||||
|
||||
Fixed an issue where the MFA timestamp was not redistributed between standalone firewalls behind an Azure load balancer after upgrading, which resulted in users being prompted to reauthenticate multiple times.
|
||||
|
||||
## PAN-295796
|
||||
|
||||
Fixed an issue where the firewall intermittently failed to forward VXLAN GARP packets, which led to connectivity issues for wireless clients in environments that used VXLAN tunnels for wireless access points.
|
||||
|
||||
## PAN-292447
|
||||
|
||||
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
|
||||
|
||||
## PAN-291945
|
||||
|
||||
Fixed an issue on PA-5220 firewalls where denied traffic logs incorrectly displayed a byte count of 0. This occurred because the bytes_sent value was stored in the most significant bits of u_bytes_sent, resulting in a zero value when a small value was assigned to u_bytes_sent.
|
||||
|
||||
## PAN-285208
|
||||
|
||||
Fixed an issue where the firewall did not automatically recover after a machine check exception (MCE) occurred.
|
||||
|
||||
## PAN-283237
|
||||
|
||||
Fixed an issue where traffic logs incorrectly displayed the action as allow for traffic matching a Security policy rule configured with the action set to deny. This issue occurred due to the child session being used for policy rule lookup when a configuration update triggered a rematch if the FTP-data application was not in the rule.
|
||||
|
||||
## PAN-281588
|
||||
|
||||
Fixed an issue where packet buffer depletion occurred due to the a high number of tcp_pkt_queued packets when Jumbo was enabled.
|
||||
|
||||
## PAN-269535
|
||||
|
||||
Fixed an issue where the mib ID returned an incorrect value via SNMP.
|
||||
|
||||
## PAN-263691
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a memory leak in the all_task process.
|
||||
|
||||
## PAN-262831
|
||||
|
||||
```caveat
|
||||
PA-5400f Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where the all_task process stopped responding, which caused the firewall to restart.
|
||||
|
||||
## PAN-241694
|
||||
|
||||
Fixed an issue where memory leaks related to the devsrvr process occurred when downloading and pushing updates from the App-ID Cloud Engine to the dataplane.
|
||||
|
||||
## PAN-185731
|
||||
|
||||
Fixed an issue where the firewall was unable to parse the URL path and host when the host header was located in a different packet, which resulted in the firewall not logging the URL path in the first packet. The fix is disabled by default. The following CLI commands can be used to enable/disable the feature:set system setting ctd url-crosspkt-host-path-caching enableset system setting ctd url-crosspkt-host-path-caching disableset system setting ctd url-crosspkt-host-path-caching default
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching enable
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching disable
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching default
|
||||
@@ -0,0 +1,197 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.13-h2
|
||||
---
|
||||
|
||||
## PAN-314319
|
||||
|
||||
Fixed an issue where the firewall experienced increased packet drops and slower performance after an upgrade due to high burst traffic.
|
||||
|
||||
## PAN-313572
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the dataplane restarted due to a segmentation fault.
|
||||
|
||||
## PAN-312706
|
||||
|
||||
Fixed an issue where the firewalls restarted due to a function lacking a NULL-pointer sanity check.
|
||||
|
||||
## PAN-311524
|
||||
|
||||
Fixed an issue where config-lock was not displayed on the web interface.
|
||||
|
||||
## PAN-311250
|
||||
|
||||
```caveat
|
||||
Panorama appliances and Log Collectors only
|
||||
```
|
||||
|
||||
Fixed an issue where logs from multiple devices were not visible on Panorama even though the Elasticsearch health status on the dedicated Log Collectors appeared green.
|
||||
|
||||
## PAN-311073
|
||||
|
||||
```caveat
|
||||
Panorama managed firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls incorrectly updated the modified date and MD5 hash of policy rules during an HA sync commit job or a subsequent local commit, even when no changes were made to the policy rules.
|
||||
|
||||
## PAN-308786
|
||||
|
||||
```caveat
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where traffic log queries using the device_name filter returned no results, and, additionally complex log queries that included negation operators produced incorrect outputs.
|
||||
|
||||
## PAN-308654
|
||||
|
||||
Fixed an issue where the Elasticsearch Close Indices process closed more indices than expected and dropped the number of open shards below the minimum of 800 per Elasticsearch instance. This occurred because the process did not correctly account for the number of Elasticsearch instances when calculating the maximum number of allowed open shards.
|
||||
|
||||
## PAN-307702
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where traffic passing through AE layer 2 interfaces was interrupted during HA failovers.
|
||||
|
||||
## PAN-307597
|
||||
|
||||
Fixed an issue where BGP peering sessions between a hub firewall and a satellite firewall over GlobalProtect LSVPN failed to connect.
|
||||
|
||||
## PAN-306555
|
||||
|
||||
Fixed an issue where the firewall stopped responding, which led to service outages.
|
||||
|
||||
## PAN-306451
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on AWS environments only
|
||||
```
|
||||
|
||||
Fixed an issue where, after upgrading the firewall to an affected release, GlobalProtect clients did not connect with IPSec and instead connected using SSL due to traffic flow being disabled when checking for health check packets.
|
||||
|
||||
## PAN-305700
|
||||
|
||||
Fixed an issue where a reboot loop occurred when OSPF interfaces were configued with a link type of point-to-point.
|
||||
|
||||
## PAN-305552
|
||||
|
||||
Fixed an issue where DLP logs displayed an incorrect file type when the firewall did not set the file type field.
|
||||
|
||||
## PAN-304746
|
||||
|
||||
```caveat
|
||||
Panorama appliances and Panorama virtual appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where the configd process restarted when committing and pushing configuration for a new WildFire cluster.
|
||||
|
||||
## PAN-304718
|
||||
|
||||
Fixed an issue where OSPF and BGP outages occurred due to an all_task process restart during clientless VPN content rewrite processing.
|
||||
|
||||
## PAN-304696
|
||||
|
||||
Fixed an issue where the Cloud User-ID connection timed out because the firewall took too long to process the OCSP response.
|
||||
|
||||
## PAN-304576
|
||||
|
||||
Fixed an issue where the firewall entered a non-functional state due to segmentation fault within the all_pktproc process that was caused by a session that involved http2 cleartext traffic
|
||||
|
||||
## PAN-303745
|
||||
|
||||
Fixed an issue where inter-dataplane forwarding did not work for sessions ingressing on Slot 2, which resulted in intermittent ping failures to interfaces on Network Card 2 when traffic was forwarded to Slot 3. Note: With this fix, after a slot restart, the global counter will still show dot1q errors for a short period.
|
||||
|
||||
## PAN-303722
|
||||
|
||||
Fixed an issue on the firewall where configuring spyware and vulnerability profiles in Security policy rules caused a memory leak in the devsrvr process with each configuration commit.
|
||||
|
||||
## PAN-301731
|
||||
|
||||
Fixed an issue where, when the firewall was unable to establish an SCM connection due to the discovery service returning a 404 error when the device was not yet known to the service, the firewall did not retry the attempt as expected.
|
||||
|
||||
## PAN-300664
|
||||
|
||||
Fixed an issue on the Panorama and firewall web interface where Applications pages became unresponsive after activating the SaaS Inline license.
|
||||
|
||||
## PAN-299705
|
||||
|
||||
Fixed an issue where API calls to commit changes on Panorama intermittently failed when using the XML API with refresh=no, which caused changes to not be applied to the partial-commit configuration.
|
||||
|
||||
## PAN-299495
|
||||
|
||||
Fixed an issue where the show system setting ssl-decrypt certificate CLI command did not display certificates when XML output was enabled.
|
||||
|
||||
## PAN-298945
|
||||
|
||||
Fixed an issue where OSCP HTTP POST requests were not formatted correctly, which caused failures with strict responders.
|
||||
|
||||
## PAN-297540
|
||||
|
||||
```caveat
|
||||
Panorama managed firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the HA-Link-Monitor configuration pushed from Panorama was converted to a local configuration on the peer device after an HA sync, which caused subsequent Panorama pushes of link monitor changes to be flagged as overwritten, and a forced template push or manual clearing of the configuration on the firewall was required.
|
||||
|
||||
## PAN-296694
|
||||
|
||||
Fixed an issue where the firewall rebooted due to the useridd process repeatedly restarting during an IP-port data type writes to the redis from multiple sources such as TSA or XML in a scale environment.
|
||||
|
||||
## PAN-295803
|
||||
|
||||
Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code path.
|
||||
|
||||
## PAN-295802
|
||||
|
||||
Fixed an issue where a memory leak related to the configd process occurred.
|
||||
|
||||
## PAN-294379
|
||||
|
||||
Fixed an issue where, when SD-WAN SaaS Application path monitoring failed for all interfaces, the firewall stopped forwarding traffic even if the ISP links and default gateway probing were still active.
|
||||
|
||||
## PAN-292306
|
||||
|
||||
Fixed an issue where the authd process stopped handling RADIUS authentication requests and required a restart.
|
||||
|
||||
## PAN-290938
|
||||
|
||||
Fixed an issue where multiple memory leaks occurred related to the configd process.
|
||||
|
||||
## PAN-288175
|
||||
|
||||
Addressed a stack buffer overflow memory leak under plugin management code path.
|
||||
|
||||
## PAN-287159
|
||||
|
||||
Fixed an issue where file uploads to Dropbox stalled when using a PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic. This occurred because the proxy was unable to decrement packet counts properly when the queue was large, resulting in a receive window size of 0 for the parent session.
|
||||
|
||||
## PAN-279364
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls with multiple NICs only
|
||||
```
|
||||
|
||||
Fixed an issue were the queue count in the task dump displayed an incorrect number of queues for SR-IOV interfaces due to the queue mapping logic incorrectly using a non-multi-NIC function.
|
||||
|
||||
## PAN-278688
|
||||
|
||||
Fixed an issue where DNS Security threat logs were not displayed on the firewall when packet capture was enabled and the domain name length was 62 characters.
|
||||
|
||||
## PAN-274742
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the task-queue dump CLI command returned incorrect information in multi-nic mode.
|
||||
|
||||
## PAN-259785
|
||||
|
||||
Fixed an issue where the devsrvr process restarted and created a core dump because two threads did not terminate correctly.
|
||||
@@ -0,0 +1,441 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.13
|
||||
---
|
||||
|
||||
## PAN-306534
|
||||
|
||||
Fixed an issue were the all_task process repeatedly restarted due to memory pool corruption when processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred due to incorrect buffer length calculations during memory deallocation when the query name field spanned multiple packets.
|
||||
|
||||
## PAN-306502
|
||||
|
||||
Fixed an issue where TLS connection failure occurred when traffic was over TLS1.2 or below, header insertion was enabled on the firewall, send TLS handshake to CTD was enabled, and traffic hit a decryption policy rule configured with the no-decrypt action.
|
||||
|
||||
## PAN-306306
|
||||
|
||||
```caveat
|
||||
Panorama appliances in FIPS-CC mode only
|
||||
```
|
||||
|
||||
Fixed interdevice TLS communication failures that occurred with RSA and RSA-PSS signature algorithms across multiple layer 7 application services.
|
||||
|
||||
## PAN-306226
|
||||
|
||||
Fixed an issue where the TLS handshake did not complete and the session did not go through. This occurred if the HTTP header insertion applied to an HTTP CONNECT request passing through the firewall, the scan-handshake feature was enabled, the session matched a decryption policy rule with the decrypt action, and if the TLS client hello was in a single packet and TLS 1.2 or below.
|
||||
|
||||
## PAN-305480
|
||||
|
||||
Fixed an issue where the pan_task process stopped responding while processing DoH JSON format traffic with DoH Security enabled, which caused missing cross-packet bytes in the decoded DNS query type field, and the dataplane went down.
|
||||
|
||||
## PAN-305412
|
||||
|
||||
Fixed an issue where the Logging Service License Status displays a license failure when the license status transitions from valid to expired and then back to valid even when the connection to the Security Logging Service (SLS) was working.
|
||||
|
||||
## PAN-304496
|
||||
|
||||
Fixed an issue where, after unregistering an IP tag and registering a different IP tag for the same IP address via XML API, the dynamic address group membership was not updated on the dataplane, which resulted in Security policy rules being enforced incorrectly.
|
||||
|
||||
## PAN-304229
|
||||
|
||||
Fixed an issue on the Panorama web interface where you were unable to disable Lifesize (Templates > Network > Network Profiles > IPSec Crypto).
|
||||
|
||||
## PAN-303379
|
||||
|
||||
Fixed an issue where the show system resources CLI command displayed incorrect CPU usage values that did not add up to 100%.
|
||||
|
||||
## PAN-303051
|
||||
|
||||
Fixed an issue on Panorama where a memory leak occurred related to the reportd process due to retaining memory that was temporarily used for report generation instead of releasing the memory for reuse, which resulted in continuous accumulation and memory exhaustion.
|
||||
|
||||
## PAN-302567
|
||||
|
||||
Fixed an issue where firewalls incorrectly returned the message API Error: Success with the error code 403 instead of the correct message API Error: Invalid Credential, when Cisco-ISE server is being used for MSCHAP-PEAP Radius auth.
|
||||
|
||||
## PAN-302317
|
||||
|
||||
Fixed an issue where the all_task process stopped responding after a commit, which cause the dataplane to reboot repeatedly.
|
||||
|
||||
## PAN-302127
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where adding a 26th floating IP address to an aggregate ethernet interface in one vsys caused IPSec tunnels on another vsys to stop working due to rekeying. This occurred due to the routed process not detecting the unchanged virtual address, uninstalling it, and then reinstalling it, which ended the ikemgr connection on the virtual address.
|
||||
|
||||
## PAN-302073
|
||||
|
||||
Fixed an issue on Panorama where the override icon in Agent Config did not change to the revert icon after reverting a configuration change in a template-stack.
|
||||
|
||||
## PAN-301942
|
||||
|
||||
Fixed an issue where WildFire logs intermittently displayed an incorrect block action for file transfers, even when the WildFire verdict was benign, no threats were detected, and the file downloaded successfully.
|
||||
|
||||
## PAN-301848
|
||||
|
||||
Fixed an issue where websites were incorrectly categorized with high severity alerts (Monitoring > URL Filtering) even though they were assessed as low risk. This occurred due to session information being unavailable during logging.
|
||||
|
||||
## PAN-301801
|
||||
|
||||
Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
|
||||
|
||||
## PAN-301430
|
||||
|
||||
Fixed an issue where the web server did not specify the content type in the header for font files, which could allow a browser to misinterpret the content and potentially lead to cross-site scripting (XSS) vulnerabilities.
|
||||
|
||||
## PAN-301386
|
||||
|
||||
Fixed an issue where BFD echo packets were dropped on Vwire interfaces due to being incorrectly detected as a land attack when the source and destination ports of the BFD packets were different.
|
||||
|
||||
## PAN-301305
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the all_task process stopped responding and caused the passive firewall to reboot.
|
||||
|
||||
## PAN-301290
|
||||
|
||||
Fixed an issue on the Panorama web interface where a custom administrator with device group and template permissions was unable to upgrade devices to non-preferred releases due to the options to uncheck base and preferred releases not being displayed.
|
||||
|
||||
## PAN-300637
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall unexpectedly rebooted due to repeated varrcvr process restarts.
|
||||
|
||||
## PAN-300617
|
||||
|
||||
Fixed an issue where the Elasticsearch cluster status displayed as red due to unassigned shards, which prevented logs from updating.
|
||||
|
||||
## PAN-300548
|
||||
|
||||
Fixed an issue where using the IKEv2 multiplier setting for VPN re-authentication resulted in the firewall not re-authenticating at the expected intervals when both sides initiated rekeying. The internal re-authentication counter incremented when the local side triggered the rekey, but not when the peer side triggered it.
|
||||
|
||||
## PAN-300138
|
||||
|
||||
Fixed an issue where DNS queries stalled or repeatedly time out due to multiple DNS responses with different CNAME values causing evasion false positive alerts.
|
||||
|
||||
## PAN-299915
|
||||
|
||||
Fixed an issue where the Elasticsearch cluster health status displayed as red on dedicated log collectors due to an expired Elasticsearch CC certificate, which prevented log visibility from Panorama.
|
||||
|
||||
## PAN-299615
|
||||
|
||||
Fixed an issue where, when the Network Packet Broker feature was enabled, forward TLS (non-decrypted) traffic was not working as expected when there were segmented client hellos and a no-decrypt rule existed. This issue occurred when Zone Protection profiles were configured for trust/untrust zones but not attached to NPB zones.
|
||||
|
||||
## PAN-299450
|
||||
|
||||
Fixed an issue where PAN-OS logrotate did not rotate large log files until the cron.daily process ran, which resulted in the root partition filling up.
|
||||
|
||||
## PAN-299228
|
||||
|
||||
Fixed an issue where a session process consumed excessive CPU resources, even when Data Loss Prevention (DLP) was not enabled. This occurred due to the active threat list being iterated twice when active threats were present in the session.
|
||||
|
||||
## PAN-299193
|
||||
|
||||
Fixed an issue on the firewall where, after upgrading, autocommits repeatedly failed until after a second reboot due to a timing issue between content loading on the management plane card (MPC) and the log receiver startup.
|
||||
|
||||
## PAN-299161
|
||||
|
||||
Fixed an issue where the bytes number overflowed for a specific application, which caused Network Monitor graphs to display an unexpectedly large volume of traffic.
|
||||
|
||||
## PAN-298907
|
||||
|
||||
Fixed an issue on PA-VM in AWS where, in a two-arm deployment integrated with Gateway Load Balancer (GWLB), the firewall did not preserve the GENEVE source port for internet traffic, resulting in increased latency. The fix ensures the firewall preserves the outer UDP source port of GENEVE encapsulation when sending traffic back to GWLB.
|
||||
|
||||
## PAN-298684
|
||||
|
||||
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and Network > Zones > Pre-NAT Identification enabled.
|
||||
|
||||
## PAN-298460
|
||||
|
||||
```caveat
|
||||
Panorama appliances in HA configurations on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue on the web interface where the plugin versions that were displayed when hovering the cursor over the Green Match icon were inconsistent even though the Panorama web interface reported the versions as matching.
|
||||
|
||||
## PAN-298288
|
||||
|
||||
Fixed an issue where traffic loss occurred when two aggregate ethernet interfaces were configured as vwire with only one member link active in the aggregate ethernet interface, which occurred due to an incorrect logic in active port map of AE interfaces.
|
||||
|
||||
## PAN-298279
|
||||
|
||||
Fixed an issue where Panorama administrators defined in a SAML Identity Provider (IdP) were unable to authenticate if their username exceeded 32 characters, and the system logs displayed the failed authentication attempt with a truncated username.
|
||||
|
||||
## PAN-298000
|
||||
|
||||
Fixed an issue where the useridd process stopped responding after an upgrade, which led to high packet buffer congestion and an OOM condition.
|
||||
|
||||
## PAN-297975
|
||||
|
||||
Fixed an issue where Panorama was unable to push the Trusted Root CA configuration to Log Collectors via a Collector Group push due to the Log Collector not supporting the trusted-root-CA configuration.
|
||||
|
||||
## PAN-297963
|
||||
|
||||
Fixed an issue where PA-400 Series firewalls were not properly caching DNS responses for FQDN objects. The firewall was observed to repeatedly send DNS requests for the same FQDN objects every 10-15 seconds, even after receiving valid responses, despite the minimum FQDN refresh interval being set to a much higher value. This resulted in excessive DNS queries originating from the firewall's management interface.
|
||||
|
||||
## PAN-297775
|
||||
|
||||
Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual System field referenced the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. If you're using a multivsys environment, you must upgrade your firewalls to a fixed PAN-OS version. The best practice is to upgrade both the firewalls and Panorama to a fixed PAN-OS version.
|
||||
|
||||
If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message vsys name should end with a number vsys is invalid after you Export or push device config bundle from 11.1.1 Panorama.
|
||||
|
||||
After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an Export or Push device config bundle from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
|
||||
|
||||
## PAN-297774
|
||||
|
||||
Fixed an issue on the web interface where the TLS Version was misspelled as TLS Vesrion (Device > Server Profiles > Email).
|
||||
|
||||
## PAN-297530
|
||||
|
||||
Fixed an issue where, after a failover event, a static default route redistributed into BGP was not advertised to peers until the redistribution profile was removed and re-added.
|
||||
|
||||
## PAN-297321
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where return packets from a phone gateway looped between the HA pair instead of being encapsulated into the GlobalProtect tunnel. This occurred when the inner session and the outer IPSec tunnel terminated on different nodes, which led to excessive retries and packet drops.
|
||||
|
||||
## PAN-297295
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall repeatedly restarted due to high packet rates on the synthetic path in DPDK mode.
|
||||
|
||||
## PAN-297005
|
||||
|
||||
Fixed an issue where exporting custom reports resulted in empty CSV files.
|
||||
|
||||
## PAN-296752
|
||||
|
||||
```caveat
|
||||
PA-1410 Firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall experienced high management CPU usage and repeatedly rebooted when attempting to retrieve SMART data.
|
||||
|
||||
## PAN-296749
|
||||
|
||||
Fixed an issue where email alerts sent from the firewall were marked as spam due to the EHLO header containing only the firewall hostname and not the fully qualified domain name (FQDN).
|
||||
|
||||
## PAN-296635
|
||||
|
||||
Fixed an issue where the reportd process on passive Panorama management servers leaked memory due to scheduled report handling from the Strata Logging Service (SLS). This memory leak occurred daily, consuming available memory until the process was restarted.
|
||||
|
||||
## PAN-296616
|
||||
|
||||
Fixed an issue where, when a PBF policy rule with a monitoring profile was configured, the intermediate firewall dropped the PBF monitoring traffic, which caused the PBF rule to remain disabled on the local firewall.
|
||||
|
||||
## PAN-296598
|
||||
|
||||
Fixed an issue where EAL logs were not forwarded to the IoT Security dashboard when the proxy server password contained special characters.
|
||||
|
||||
## PAN-296397
|
||||
|
||||
Fixed an issue on the Panorama web interface where previewing changes after a commit to shared objects were not accurately displayed in the push scope.
|
||||
|
||||
## PAN-296224
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where adding a 26th floating IP address to an aggregate interface on one vsys caused IPSec tunnels in another vsys to stop working due to rekeying issues.
|
||||
|
||||
## PAN-296208
|
||||
|
||||
Fixed an issue where the firewall did not accept address groups in the filter condition of a Log Forwarding Match list.
|
||||
|
||||
## PAN-296020
|
||||
|
||||
Fixed an issue where commit operations failed during phase 1 when configuring a non-default value for the Graceful Restart Hello Delay due to an FRR parse error if the configured value was between 1 and 9.
|
||||
|
||||
## PAN-295838
|
||||
|
||||
Fixed an issue on IKEv1 tunnels where, if the peer IKE gateway was unreachable, the IKE Phase-1 Security association (SA) was not cleared by DPD until Phase-2 rekeying occurred or until it was manually cleared via the CLI because the DPDs were not sent accurately according to the configured interval due to a miscalculation of the DPD timer. This resulted in the tunnel taking longer than expected to recover.
|
||||
|
||||
## PAN-295578
|
||||
|
||||
Fixed an issue where GlobalProtect HIP data file download and installation failed with the error message An error occurred while processing request. Please try again after some time or contact support or No ETAG from response due to a script exiting prematurely.
|
||||
|
||||
## PAN-295484
|
||||
|
||||
Fixed an issue where SD-WAN did not generate system logs with timestamps and reasons for degradation of Direct Internet Access paths.
|
||||
|
||||
## PAN-295470
|
||||
|
||||
Fixed an issue on the firewall where the useridd process continuously increased its memory consumption, which resulted in an OOM condition that caused the firewall to restart.
|
||||
|
||||
## PAN-294770
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations
|
||||
```
|
||||
|
||||
Fixed an issue on firewalls where, after failover, certain subnets were missing from the Link State Database, which prevented OSPF routes from being immediately learned due to a Type-7 to Type-5 LSA translation conflict in the ABR when the same LSA was advertised by two peers in the NSSA area.
|
||||
|
||||
## PAN-294307
|
||||
|
||||
Fixed an issue on Panorama where a configd SIGSEGV crash occurred when renaming objects within policy rules, objects, or zones.
|
||||
|
||||
## PAN-294161
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to the useridd process restarting and causing an HA failover. This occurred due to the configd process timing out when running the CLI command show user user-id-agent config all.
|
||||
|
||||
## PAN-294123
|
||||
|
||||
Fixed an issue where the firewall removed all Infrastructure and Audit logs, as well as logdb and search engine quotas, when the configured retention period was reached instead of only removing logs older than the configured retention period.
|
||||
|
||||
## PAN-293879
|
||||
|
||||
Fixed an issue on the firewall where the VM monitor source remained in the Getting All status, which prevented dynamic address groups from updating IP addresses for new EC2 instances. This issue occurred due to a race condition where two threads that simultaneously retrieved IP address tag information from AWS VM monitoring sources became stuck while reading the XML file.
|
||||
|
||||
## PAN-293847
|
||||
|
||||
Fixed an issue where EAL logs for traffic matching the intrazone-default security rule were not forwarded to the IoT Security portal.
|
||||
|
||||
## PAN-293574
|
||||
|
||||
Fixed an issue on Panorama where Global Find returned incomplete and inconsistent search results.
|
||||
|
||||
## PAN-293428
|
||||
|
||||
Fixed an issue where the interval of IKEv1 Dead Peer Detection (DPD) R-U-THERE packets did not correspond to the configured value in the IKE Gateway profile due to using the value configured for retry instead.
|
||||
|
||||
## PAN-293297
|
||||
|
||||
Fixed an issue on Panorama where a full push to device groups was initiated instead of a selective push when using Commit and Push Changes Made By in the commit and push.
|
||||
|
||||
## PAN-292471
|
||||
|
||||
Fixed an issue where the default route (0.0.0.0/0) advertised via the Originate Default Route in BGP AFI profiles did not appear in the output of the show advanced-routing bgp peer advertised-routes CLI command, even though it was being sent to the BGP peer.
|
||||
|
||||
## PAN-292261
|
||||
|
||||
Fixed an issue where the firewall repeatedly reported an unreachable syslog server as back online when the server remained unavailable. This resulted in misleading alternating connection status messages in the system logs.
|
||||
|
||||
## PAN-291915
|
||||
|
||||
Fixed an issue on the firewall where the PDT process experienced a memory leak due to frequent dumping of fabric traffic statistics, which resulted in high CPU utilization and instability.
|
||||
|
||||
## PAN-291804
|
||||
|
||||
Fixed an issue on Panorama where deleting objects resulted in errors indicating references in Security policy rules.
|
||||
|
||||
## PAN-291661
|
||||
|
||||
Fixed an issue on Panorama appliances and Log Collectors where, after an upgrade, Elasticsearch intermittently entered into a Red state before automatically recovering.
|
||||
|
||||
## PAN-291660
|
||||
|
||||
Fixed an issue where the firewall incorrectly reported the speed of 25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID.
|
||||
|
||||
## PAN-291653
|
||||
|
||||
Fixed an issue where the GlobalProtect host ID field was intermittently blank in traffic logs on Prisma Access, even when the user was connected and had the correct host ID information. This occurred when the IP address to host ID entry expired and the entry was re-insterted without the dataplane flag being set.
|
||||
|
||||
## PAN-291273
|
||||
|
||||
Fixed an issue where a PA-VM-Flex firewall in an air-gapped environment failed to install the license when bootstrapping after a factory reset when the ISO image contained a PAN-OS image.
|
||||
|
||||
## PAN-291009
|
||||
|
||||
Fixed an issue where, after a web server returned a 401 or 403 error, the firewall was unable to decrypt HTTP/2 traffic, and the firewall rejected all subsequent streams from the client.
|
||||
|
||||
## PAN-290681
|
||||
|
||||
Fixed an issue on Panorama and Panorama managed firewalls where template settings reverted during a device group push when Include Device and Network Templates was checked, even if no changes were made to the template. This caused the SAML IDP server profile certificate to revert to an older, invalid certificate, and resulted in GlobalProtect users being unable to authenticate via SAML.
|
||||
|
||||
## PAN-290665
|
||||
|
||||
Fixed an issue with firewalls enabled with Security profiles where certain traffic conditions caused high dataplane CPU utilization and packet buffer exhaustion, which caused LACP flapping conditions.
|
||||
|
||||
## PAN-290640
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure environments in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message Unknown error during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
|
||||
|
||||
## PAN-289578
|
||||
|
||||
Fixed an issue on Panorama managed firewalls where the source user, source device vendor, source MAC address, and OS version information were not visible in traffic logs and SCM when the user and device access control lists were empty.
|
||||
|
||||
## PAN-289067
|
||||
|
||||
Fixed an issue where, after upgrading Panorama in a High Availability (HA) pair, the configuration logs stopped synchronizing from the primary Panorama to the secondary Panorama. This issue occurred because the log forwarding flag was permanently disabled due to the connection state not being active when the log-fwd-ctrl message was received.
|
||||
|
||||
## PAN-288938
|
||||
|
||||
Fixed an issue on the Panorama web interface where the search bar suddenly was not displayed, or the filter/clear filter icon moved to the left of the search bar.
|
||||
|
||||
## PAN-287713
|
||||
|
||||
Fixed an issue on Panorama where, after uninstalling a plugin, commit validation failed with the error message interface '-' is not a valid reference due to cloud service plugin configuration errors.
|
||||
|
||||
## PAN-287581
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not process and transmit HA path monitoring probes received from another HA cluster when the firewall acted as a gateway for internal monitoring IP addresses used in the HA path monitoring group, which caused HA flapping due to path monitoring failures.
|
||||
|
||||
## PAN-286555
|
||||
|
||||
Fixed an issue where PA-VM-Flex firewalls bootstrapped in an air-gapped environment did not display premium partner and threat prevention licenses.
|
||||
|
||||
## PAN-286297
|
||||
|
||||
Fixed an issue where the firewall did not respond to ARP requests when a subinterface was configured with source address translation using the Translated Address option.
|
||||
|
||||
## PAN-282961
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly after a commit due to a memory leak related to the rasmgr process and displayed the error message Management server failed to send phase 1 to client l2ctrld before rebooting.
|
||||
|
||||
## PAN-282687
|
||||
|
||||
Fixed an issue on Panorama where performing a selective revert of configuration changes resulted in all configuration changes being reverted.
|
||||
|
||||
## PAN-278611
|
||||
|
||||
Fixed an issue on Panorama where software images were not purged from the /opt/pancfg/mgmt/sw-images folder.
|
||||
|
||||
## PAN-276525
|
||||
|
||||
Resolved multiple issues affecting IPSec tunnels using NAT Traversal (NAT-T) when a Dynamic NAT policy was configured (including Dynamic NAT or DIPP). During rekey events, tunnels could go down or flap due to incorrect session handling. This issue impacted both cluster and standalone deployments.
|
||||
|
||||
## PAN-272432
|
||||
|
||||
Fixed an issue where Panorama and Cortex Data Lake (CDL) logs displayed incorrect interface names without node IDs for cluster firewalls.
|
||||
|
||||
## PAN-267965
|
||||
|
||||
```caveat
|
||||
Firewalls on Amazon Web Services (AWS) environments only
|
||||
```
|
||||
|
||||
Fixed an issue where newly bootstrapped firewalls sent an incorrect, non-DHCP-assigned hostname to the SNMP server. This occurred because the SNMP process referred to a configuration file that was not updated due to a missing configuration commit.
|
||||
|
||||
## PAN-262353
|
||||
|
||||
Fixed an issue where, when Panorama was upgraded to PAN-OS 10.2.10, and log collectors were on PAN-OS 10.2.9-h1, logs from a log collector group were not viewable on a Panorama.
|
||||
|
||||
## PAN-254946
|
||||
|
||||
Fixed an issue where the firewall HA2 keep-alive went down multiple times without a specific reason.
|
||||
|
||||
## PAN-229976
|
||||
|
||||
Fixed an issue where, when FRR was enabled, routes that were advertised to eBGP peers incorrectly had the Community attribute set to graceful-shutdown.
|
||||
@@ -0,0 +1,237 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h10
|
||||
---
|
||||
|
||||
## PAN-286897
|
||||
|
||||
Fixed an issue where the pan_task process stopped responding when the firewall attempted to forward files to the WildFire public cloud, which caused the dataplane to experience heartbeat failures.
|
||||
|
||||
## PAN-285590
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1.
|
||||
|
||||
## PAN-284066
|
||||
|
||||
Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command.
|
||||
|
||||
## PAN-283789
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
|
||||
|
||||
## PAN-283467
|
||||
|
||||
```caveat
|
||||
PA-3400 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall unexpectedly rebooted and entered maintenance mode due to a ctd-agent out-of-memory (OOM) condition. This occurred during advanced services load testing and a high volume of IoT EAL log forwarding.
|
||||
|
||||
## PAN-282640
|
||||
|
||||
Fixed an issue where custom reports showed incomplete data when exported in CSV format from Panorama.
|
||||
|
||||
## PAN-280477
|
||||
|
||||
Fixed an issue on the web interface were you were unable to scroll up or down to view source zones in a NAT policy rule.
|
||||
|
||||
## PAN-280335
|
||||
|
||||
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that prevented to SNMP server from logging.
|
||||
|
||||
## PAN-273614
|
||||
|
||||
Fixed an issue where packets were dropped initially when a SYN cookie with activation threshold 0 was enabled.
|
||||
|
||||
## PAN-272605
|
||||
|
||||
Fixed an issue where the firewall did not display VPC endpoints when there was a large amount of VPC endpoints to interface mappings.
|
||||
|
||||
## PAN-271560
|
||||
|
||||
Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable.
|
||||
|
||||
## PAN-271152
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall failed over into a non-functional state, and the LFC LED was blinking on the passive firewall.
|
||||
|
||||
## PAN-270849
|
||||
|
||||
Fixed a memory leak issue related to the configd process that occurred when running consecutive commits for multiple days.
|
||||
|
||||
## PAN-269193
|
||||
|
||||
Fixed an issue where the firewall redirected the user to the first application instead of the portal page with a list of applications when multiple applications were configured for GlobalProtect clientless VPN along with any user match.
|
||||
|
||||
## PAN-269139
|
||||
|
||||
```caveat
|
||||
Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.
|
||||
|
||||
## PAN-264982
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on KVM only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall entered maintenance mode after an auto-commit when sending an ARP packet through the loopback interface using an IPv6 address.
|
||||
|
||||
## PAN-264477
|
||||
|
||||
Fixed an issue where the firewall did not start Elasticsearch after a commit if Elasticsearch was not previously enabled and started.
|
||||
|
||||
## PAN-261429
|
||||
|
||||
Fixed an issue where the show auth radius-require-msg-authentic command CLI displayed no output.
|
||||
|
||||
## PAN-254524
|
||||
|
||||
Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed.
|
||||
|
||||
## PAN-284116
|
||||
|
||||
Fixed an issue where mTLS decryption bypass did not work when the decryption profile was configured with the maximum TLS version as TLS 1.3.
|
||||
|
||||
## PAN-281882
|
||||
|
||||
Fixed an issue where OSPF redistributed connected routes beyond the intended loopback IP address.
|
||||
|
||||
## PAN-280698
|
||||
|
||||
Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.
|
||||
|
||||
## PAN-280532
|
||||
|
||||
Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped.
|
||||
|
||||
## PAN-279621
|
||||
|
||||
Fixed an issue where processes stopped responding when HTTPS Forward traffic was run.
|
||||
|
||||
## PAN-278981
|
||||
|
||||
Fixed an issue where DNS domain resolutions experienced intermittent delays due to the firewall not connecting to the DNS Security cloud.
|
||||
|
||||
## PAN-262373
|
||||
|
||||
Fixed an issue where the error message Failed to reload config files displayed in the system logs even when device telemetry was not enabled.
|
||||
|
||||
## PAN-277417
|
||||
|
||||
Fixed an memory leak issue related to TLS inbound decryption.
|
||||
|
||||
## PAN-274806
|
||||
|
||||
```caveat
|
||||
PA-5250 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where IPv6 pings experienced a high number of dropped packets when forwarded to another dataplane, which resulted in ping failures. This occurred when initiating a ping to the link local address of the firewall and the packet drop percentage depended on the number of dataplanes.
|
||||
|
||||
## PAN-274569
|
||||
|
||||
Fixed an issue where the QSPF transceiver interface displayed an incorrect range figure on the temperature alarm.
|
||||
|
||||
## PAN-274496
|
||||
|
||||
Fixed an issue where the root partition reached 100% which caused the system to become non-functional and failover even when aggressive cleaning was enabled.
|
||||
|
||||
## PAN-273422
|
||||
|
||||
Fixed an issue where traffic failed when Inline cloud analysis (Advanced Threat Prevention) was enabled in the Anti-Spyware profile with the action set to anything other than allow or alert and the maximum latency condition was reached.
|
||||
|
||||
## PAN-272812
|
||||
|
||||
Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets.
|
||||
|
||||
## PAN-271700
|
||||
|
||||
Fixed an issue where User-ID connections were lost after an HA failover.
|
||||
|
||||
## PAN-271184
|
||||
|
||||
Fixed an issue where Device Telemetry failed due to an issue with the encoding of characters in the log file path.
|
||||
|
||||
## PAN-271151
|
||||
|
||||
Fixed an issue where the GlobalProtect client did not automatically initiate a Kerberos SSO connection after logging in to Windows.
|
||||
|
||||
## PAN-270379
|
||||
|
||||
Fixed an issue where socket files created in the /tmp directory were not cleared.
|
||||
|
||||
## PAN-270192
|
||||
|
||||
Fixed an issue where Panorama did not display the management IP address of devices onboarded via ZTP.
|
||||
|
||||
## PAN-268705
|
||||
|
||||
Fixed an intermittent issue where the firewall failed to process FTP traffic after upgrading to PAN-OS 10.1.14.
|
||||
|
||||
## PAN-267707
|
||||
|
||||
Fixed an issue where BFD sessions did not come up even when BGP peering was established.
|
||||
|
||||
## PAN-267001
|
||||
|
||||
Fixed an issue where multicast streams were unstable with ECMP and dropped every 30 seconds.
|
||||
|
||||
## PAN-266704
|
||||
|
||||
Fixed an issue where filtering BGP routes by peer name in Advanced Routing Engine (ARE) did not display the correct routes.
|
||||
|
||||
## PAN-266574
|
||||
|
||||
Fixed an issue where users were unable connect to the portal due to Certificate Revocation List (CRL) checks due to the downloaded CRL file being expired, which caused the CRL cache to be bypassed.
|
||||
|
||||
## PAN-266312
|
||||
|
||||
Fixed an issue where BFD sessions took longer than expected to establish after an HA failover due to BGP.
|
||||
|
||||
## PAN-261999
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where enabling flow basic on firewalls caused ARP entries to be removed on both firewalls.
|
||||
|
||||
## PAN-261570
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where packet loss occurred when dataport was used for HA3 for asymmetrically routed traffic during commits and a virtual wire was configured.
|
||||
|
||||
## PAN-260229
|
||||
|
||||
Fixed an issue where HA path monitoring using VWire did not work as expected after a reboot.
|
||||
|
||||
## PAN-257442
|
||||
|
||||
A fix was made to address CVE-2025-0123.
|
||||
|
||||
## PAN-245064
|
||||
|
||||
```caveat
|
||||
Multi-vsys firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
|
||||
@@ -0,0 +1,309 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h14
|
||||
---
|
||||
|
||||
## PAN-290996
|
||||
|
||||
Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections Per Second) per vsys on firewalls after upgrading to PAN-OS 11.1.6-h3, even when active connections were present.
|
||||
|
||||
## PAN-290803
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where firewall failed to bootstrap with a custom image, and VM-Series plugin information was not displayed in the system information.
|
||||
|
||||
## PAN-290239
|
||||
|
||||
```caveat
|
||||
PA-455 firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, the TCP session for syslog forwarding did not resume after the syslog server service was disabled and then re-enabled, which caused logs to be dropped. This occurred when the syslog server was down for more than 16 minutes.
|
||||
|
||||
## PAN-290088
|
||||
|
||||
Fixed an issue where a memory leak occurred related to the configd process when pushing configurations from Panorama to a firewall. This occurred when the configurations contained shared policy rules.
|
||||
|
||||
## PAN-289102
|
||||
|
||||
```caveat
|
||||
PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and CN-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed a race condition issue related to predict processing, which resulted in a dataplane restart and traffic loss.
|
||||
|
||||
## PAN-288893
|
||||
|
||||
```caveat
|
||||
Firewalls in multi-vsys configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where HTTP/2 traffic failed due when one virtual system (vsys) had a decryption policy rule enabled and another vsys had a no-decrypt policy rule for the same session.
|
||||
|
||||
## PAN-287818
|
||||
|
||||
Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_restore_timeout not initiating when the accumulation session_init failed.
|
||||
|
||||
## PAN-287734
|
||||
|
||||
Fixed an issue where Scan ERR: Internal Err 1002 messages were unexpectedly generated when WIF shared memory use was high.
|
||||
|
||||
## PAN-287621
|
||||
|
||||
Added debug logs for an issue where a slow IP address pool NAT leak occurred when persistent NAT was enabled, which led to NAT IP pool exhaustion.
|
||||
|
||||
## PAN-287056
|
||||
|
||||
Fixed an issue where BGP export policy rules with next-hop matching failed to block the advertisement of static routes, and the firewall incorrectly matched the egress interface IP address instead of the original next-hop IP address of the static route, which caused the deny rule to fail.
|
||||
|
||||
## PAN-287023
|
||||
|
||||
Fixed an issue where a large number of logs caused the logrcvr process to stop responding.
|
||||
|
||||
## PAN-287002
|
||||
|
||||
A fix was made to address CVE-2025-0133.
|
||||
|
||||
## PAN-286857
|
||||
|
||||
Fixed an issue where only failed Kerberos authentication events were logged in auth.log, and successful authentication events were not logged.
|
||||
|
||||
## PAN-286848
|
||||
|
||||
Fixed an issue where ECMP incorrectly balanced sessions across links based on the configured metric, which led to an imbalance in traffic distribution and resulted in traffic assignment shifting disproportionately to routes with lower metrics.
|
||||
|
||||
## PAN-286443
|
||||
|
||||
Fixed an issue where, after an upgrade, the firewall was unable to be managed via HTTPS or SSH.
|
||||
|
||||
## PAN-286306
|
||||
|
||||
Fixed an issue where, when getting transceiver information from ESCC for SFP 25G modules, the transceiver code was incorrectly updated with Unknown instead of 25GBase-SR.
|
||||
|
||||
## PAN-285894
|
||||
|
||||
Fixed an issue where the all_task process stopped responding, which caused the firewall to reboot unexpectedly, and traffic failures occurred.
|
||||
|
||||
## PAN-285818
|
||||
|
||||
Fixed an issue where a tool was needed to display leaked NAT port numbers without requiring a forced synchronization.
|
||||
|
||||
## PAN-284908
|
||||
|
||||
Fixed an issue where retrieving filenames from OneDrive resulted in a cache miss.
|
||||
|
||||
## PAN-284073
|
||||
|
||||
Fixed an issue on the firewall that caused commits to fail and the web interface to become inaccessible.
|
||||
|
||||
## PAN-284067
|
||||
|
||||
Fixed an issue where the devsrvr process experienced out of memory (OOM) conditions due to the show running application statistics CLI command, which caused the firewall to reboot.
|
||||
|
||||
## PAN-284003
|
||||
|
||||
Fixed an issue where clients did not receive a valid response when when searching a website due to a compression error.
|
||||
|
||||
## PAN-283979
|
||||
|
||||
Fixed an issue where the firewall became non-functional due to high root partition use.
|
||||
|
||||
## PAN-283936
|
||||
|
||||
```caveat
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where the configd process intermittently restarted, which caused Panorama to be temporarily unavailable.
|
||||
|
||||
## PAN-283331
|
||||
|
||||
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
|
||||
|
||||
## PAN-282359
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected.
|
||||
|
||||
## PAN-282277
|
||||
|
||||
Fixed an issue where an OOM condition on the logrcvr process caused interface flapping, and the interface unexpectedly went down and then recovered without intervention.
|
||||
|
||||
## PAN-281509
|
||||
|
||||
```caveat
|
||||
Panorama appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where log exports were slower than expected or failed when filtering logs after an upgrade, which resulted in timeouts or delays in displaying logs on the web interface.
|
||||
|
||||
## PAN-280532
|
||||
|
||||
Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped.
|
||||
|
||||
## PAN-280101
|
||||
|
||||
Fixed an issue where set and edit commands took longer than expected when adding address objects with a large number of dynamic groups due to the completion cache being enabled. With this fix, the completion cache is disabled by default.
|
||||
|
||||
## PAN-279500
|
||||
|
||||
Fixed an issue where TLS connections failed to establish in asymmetric routing environments if the firewall did not see server-to-client (s2c) packets of the TLS handshake.
|
||||
|
||||
To use this fix, run the following CLI command: debug dataplane set ssl-decrypt accumulate-client-hello asym-disable yes.
|
||||
|
||||
## PAN-278836
|
||||
|
||||
Fixed an issue where, after an upgrade, GlobalProtect attempted to use the embedded browser instead of the default browser for gateway authentication even when it was configured to use the default browser.
|
||||
|
||||
## PAN-278812
|
||||
|
||||
Fixed an issue where authentication to GlobalProtect failed with the error message User not in allowed list.
|
||||
|
||||
## PAN-278190
|
||||
|
||||
Fixed an issue on Panorama where a scheduled report with SLS data had an invalid translated-query.
|
||||
|
||||
## PAN-278150
|
||||
|
||||
Fixed an issue where the firewall removed the Authentication Key Identifier (AKID) from the certificate during SSL decryption, which caused Python 3.13 to fail with a certificate verification error.
|
||||
|
||||
## PAN-277751
|
||||
|
||||
Fixed an issue where a policy-based forwarding (PBF) rule with an action of no-pbf and a service of TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a result, traffic was matched by a lower rule with a service of any and an action of forward.
|
||||
|
||||
## PAN-276920
|
||||
|
||||
Fixed an issue where web-advertisement traffic was not immediately blocked which resulted in pages loading indefinitely.
|
||||
|
||||
## PAN-276862
|
||||
|
||||
Fixed an issue on Panorama where the logd process stopped responding unexpectedly.
|
||||
|
||||
## PAN-276616
|
||||
|
||||
Fixed an issue on the firewall where half-duplex settings on Ethernet was not visible.
|
||||
|
||||
## PAN-276276
|
||||
|
||||
```caveat
|
||||
PA-450 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, data that was excluded using the query builder in a custom report was still visible in the report, and the logs displayed errors related to invalid threat names being queried.
|
||||
|
||||
## PAN-275133
|
||||
|
||||
Fixed an issue where HTTP 503 server errors occurred while browsing websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
|
||||
|
||||
## PAN-275047
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, the firewall was unable to send logs to the Strata Logging Service (SLS) when using a specific proxy server, and the SSL connection status displayed as failed when attempting to forward logs through the web proxy.
|
||||
|
||||
## PAN-273964
|
||||
|
||||
Fixed an issue where SNMP scans to a firewall timed out after upgrading to a PAN-OS 10.2 release.
|
||||
|
||||
## PAN-273727
|
||||
|
||||
Fixed an issue where the firewall skipped the DNS policy rule of a domain external dynamic list (EDL) during an EDL refresh.
|
||||
|
||||
To use this fix, run the following CLI command and commit: set deviceconfig setting ctd custom-edl-domains-continuous-reload yes/no
|
||||
|
||||
## PAN-271810
|
||||
|
||||
Fixed an issue where auto-negotiation advertised and negotiated 10/100 half and full duplex.
|
||||
|
||||
## PAN-271490
|
||||
|
||||
Fixed an issue on the firewall that caused the following error message to be displayed: frr_ns0: failed to stop child frr_ns0_ospf6d.
|
||||
|
||||
## PAN-271432
|
||||
|
||||
Fixed an issue where the firewall was unable to decrypt SSL traffic when using forward proxy and HSM with an ECDSA signing certificate.
|
||||
|
||||
## PAN-271215
|
||||
|
||||
A fix was made to address CVE-2025-4230.
|
||||
|
||||
## PAN-269700
|
||||
|
||||
Fixed an issue where commits to service connection firewalls from Panorama failed.
|
||||
|
||||
## PAN-269057
|
||||
|
||||
Fixed an issue where the routed process stopped responding due to accessing freed memory from a hash table when the route vectors were resized. This occurred when a large number of static routes were configured.
|
||||
|
||||
## PAN-268922
|
||||
|
||||
```caveat
|
||||
PA-3220 firewalls in high availability (HA) configurations only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where the firewalls went out of sync after a configuration push from Panorama.
|
||||
|
||||
## PAN-268787
|
||||
|
||||
Fixed an issue where users were unable to log in to Panorama and the following error message was displayed: Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of devices.
|
||||
|
||||
## PAN-268708
|
||||
|
||||
Fixed an issue where PDF summary and email reports displayed IPv6 addresses instead of IPv4 addresses.
|
||||
|
||||
## PAN-268680
|
||||
|
||||
Fixed an issue where the configd process stopped responding when a configuration merge operation changed.
|
||||
|
||||
## PAN-267759
|
||||
|
||||
Fixed an issue where Prisma Access gateway downloads were slower than expected.
|
||||
|
||||
## PAN-267614
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected due to high CPU utilization on the mongodb process.
|
||||
|
||||
## PAN-267328
|
||||
|
||||
Fixed an issue where the all_task process stopped responding, which caused the firewall to stop processing traffic.
|
||||
|
||||
## PAN-267045
|
||||
|
||||
Fixed an issue on the firewall where ICMP ping loss occurred after installing a Network Processing Card (NPC) in slot 7.
|
||||
|
||||
## PAN-265549
|
||||
|
||||
A fix was made to address CVE-2025-0137.
|
||||
|
||||
## PAN-265014
|
||||
|
||||
Fixed an issue where changes made to device groups with the same prefix name were not visible in the commit scope.
|
||||
|
||||
## PAN-264845
|
||||
|
||||
Fixed an issue where the Log Forwarding for Security Services feature did not correctly filter policy rules with log forwarding profiles.
|
||||
|
||||
## PAN-263749
|
||||
|
||||
Fixed an issue where disk space that was used by file descriptors was not freed, which caused the root partition to become full and Panorama to be inaccessible.
|
||||
|
||||
## PAN-260564
|
||||
|
||||
Fixed an issue on firewalls in HA configurations where a network loop was detected by switches after suspending HA on the active firewall.
|
||||
|
||||
## PAN-260279
|
||||
|
||||
Fixed an issue where selective push operations failed with the error message: Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
||||
|
||||
## PAN-255020
|
||||
|
||||
Fixed an issue where the Panorama web interface did not display the push scope data for custom admin users when performing a partial commit and push.
|
||||
|
||||
## PAN-226184
|
||||
|
||||
Fixed an issue where push operations from Panorama were slow due to the rasmgr process taking longer than expected.
|
||||
@@ -0,0 +1,393 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h17
|
||||
---
|
||||
|
||||
## PAN-298241
|
||||
|
||||
Fixed an issue where the NAT IP address pool was exhausted, which led to intermittent connectivity issues with call applications and outbound call failures. This occurred due to the firewall not properly releasing NAT dynamic ports back to the address pool.
|
||||
|
||||
## PAN-296519
|
||||
|
||||
Fixed an issue where a stream receiving a reconnect signal with an associated error in Wifclient caused the entire pool to close, which resulted in a complete disconnection.
|
||||
|
||||
## PAN-295644
|
||||
|
||||
Fixed an issue where Cloud Data Lake (CDL) log forwarding streams intermittently displayed as inactive.
|
||||
|
||||
## PAN-295385
|
||||
|
||||
Fixed an issue where syslog forwarding dropped due to FQDN resolution failures.
|
||||
|
||||
## PAN-295342
|
||||
|
||||
Fixed an issue where the pan_comm process stopped responding due to insufficient time allocated to read file descriptors when processing long messages.
|
||||
|
||||
## PAN-295049
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding due to memory allocation errors during Redis communication.
|
||||
|
||||
## PAN-294488
|
||||
|
||||
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the Subject Common Name, Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
|
||||
|
||||
## PAN-294436
|
||||
|
||||
Fixed an issue where polling failed for ethernet interfaces due to the physical port counters read from the MAC being 0.
|
||||
|
||||
## PAN-294179
|
||||
|
||||
Fixed an issue on Panorama where commit versions did not display correct data in the config audit page even after a refresh.
|
||||
|
||||
## PAN-293985
|
||||
|
||||
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
|
||||
|
||||
## PAN-293877
|
||||
|
||||
```caveat
|
||||
Firewalls with Hub vsys (virtual system) configurations enabled only
|
||||
```
|
||||
|
||||
Fixed an issue where, when using the Hub vsys feature to redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP policy enforcement failed intermittently on the active secondary firewall. This occurred when traffic destined for specific non-Hub vsys was routed to the active secondary, and the HIP query was not triggered due to an incorrect check for the HIP mask in the Hub vsys.
|
||||
|
||||
## PAN-293842
|
||||
|
||||
Fixed an issue where the hybrid-SWG service proxy stopped working after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to establish the listening interface.
|
||||
|
||||
## PAN-293673
|
||||
|
||||
Fixed an issue where the firewall stopped all tasks due to an OOM condition caused by a scheduled log export using FTP to an external FTP server.
|
||||
|
||||
## PAN-293511
|
||||
|
||||
Fixed an issue where renaming a BGP filtering profile in Panorama does not update the corresponding BGP peer group in the virtual router, leading to commit failures.
|
||||
|
||||
## PAN-292242
|
||||
|
||||
Fixed an issue on M-200 and logging appliances where traffic logs were intermittently truncated when forwarded using a TCP syslog configuration. This issue occurred during the log forwarding stage due to intermittent syslog drops caused by exceeding the forwarding queue capacity.
|
||||
|
||||
## PAN-292228
|
||||
|
||||
Fixed an issue where, after configuring dual stack GlobalProtect with both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with the error message flow-basic error; packet dropped, tunnel resolution failure.
|
||||
|
||||
## PAN-292202
|
||||
|
||||
Fixed an issue where the system logs repeatedly displayed the alert Clearing snmpd.log due to log overflow due to the SNMP counters rolling over.
|
||||
|
||||
## PAN-291940
|
||||
|
||||
Fixed an issue where the firewall established multiple TCP connections to a syslog server, which caused logs to be dropped. This occurred because the firewall established a new TCP session for each transfer and the sessions were not closed, which resulted in a continuous increase in connections over time.
|
||||
|
||||
## PAN-291792
|
||||
|
||||
```caveat
|
||||
PA-7050 firewalls on vwire instances only
|
||||
```
|
||||
|
||||
Fixed an issue where Bidirectional Forwarding Detection (BFD) echo packets were dropped due to the firewall dropping packets with the same source and destination IP addresses.
|
||||
|
||||
## PAN-291785
|
||||
|
||||
Fixed an issue where the all_task process stopped responding.
|
||||
|
||||
## PAN-291631
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall frequently rebooted.
|
||||
|
||||
## PAN-291456
|
||||
|
||||
Fixed an issue where the custom completer for device groups and templates received the device group name and template name from the running configuration instead of the candidate configuration.
|
||||
|
||||
## PAN-291283
|
||||
|
||||
Fixed an issue on Panorama where a memory leak associated with the configd process occurred during commits, which caused the configd process to restart and the commit to fail.
|
||||
|
||||
## PAN-290919
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where file download speeds and performance was slower than expected for Prisma Access mobile users when SSL decryption was enabled.
|
||||
|
||||
To use this fix, run the CLI command debug dataplane set ssl-decrypt fptcp-rto min <100-500>.
|
||||
|
||||
## PAN-290691
|
||||
|
||||
Added the CLI command set system setting ctd h323_rtp_predict timeout to increase the maximum timeout limit from 3600 seconds to 65535 seconds.
|
||||
|
||||
## PAN-290449
|
||||
|
||||
Fixed an issue where, when multiple scheduled vulnerability reports were sent in the same email, only the first attached report was displayed.
|
||||
|
||||
## PAN-289803
|
||||
|
||||
Fixed an issue on the firewall where AIPOs and ADEM licenses failed when SD-WAN or GlobalProtect licenses were not present.
|
||||
|
||||
## PAN-289406
|
||||
|
||||
Fixed an issue where, when redistributing User-ID information between firewalls, the receiving firewall incorrectly received and stored duplicate Host Information Profile (HIP) profiles. This occurred when a GlobalProtect gateway redistributed User-ID and HIP information through an intermediate firewall.
|
||||
|
||||
## PAN-289383
|
||||
|
||||
Fixed an issue where the MPLS interface eth1/6 went down and remained down, even after replacing the SFP with a supported one and adjusting duplex and speed settings.
|
||||
|
||||
## PAN-289109
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected during configuration operations and a configuration lock time out occurred during a commit.
|
||||
|
||||
## PAN-288988
|
||||
|
||||
Fixed an issue on Panorama where, after logging in to the web interface as the ZTP installer administrator, the web interface was blank.
|
||||
|
||||
## PAN-288432
|
||||
|
||||
Fixed an issue where, when Advanced Routing Engine was enabled firewalls configured with multiple logical routers, static routes were preferred over eBGP routes even though the static routes had a higher administrative distance.
|
||||
|
||||
## PAN-288426
|
||||
|
||||
```caveat
|
||||
M-600 Panorama appliances in Log Collector mode in a Log Collector group only
|
||||
```
|
||||
|
||||
Fixed an issue where the reportd and logd processes stopped responding, which resulted in the Panorama server not receiving logs from firewalls configured under the Log Collector group.
|
||||
|
||||
## PAN-288363
|
||||
|
||||
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
|
||||
|
||||
## PAN-287842
|
||||
|
||||
Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
|
||||
|
||||
## PAN-287688
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
|
||||
|
||||
## PAN-287601
|
||||
|
||||
Fixed an issue on Panorama where commits took longer than expected.
|
||||
|
||||
## PAN-287387
|
||||
|
||||
Fixed an issue on Panorama where API jobs failed with the error message Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a large number of address objects in a single set call.
|
||||
|
||||
## PAN-286931
|
||||
|
||||
Fixed an issue where syslog forwarding in PAN-OS 11.1 and later releases did not support service routes when performing certificate validation over TLS.
|
||||
|
||||
## PAN-286899
|
||||
|
||||
Fixed an issue where the device-group-tags CLI command used an unnecessary configuration read lock.
|
||||
|
||||
## PAN-286615
|
||||
|
||||
Fixed an issue where the firewall double-freed shared memory when the shared memory usage reached 100% when sending large payloads. This occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced WildFire (AWF), or Advanced URL Filtering were enabled.
|
||||
|
||||
## PAN-286475
|
||||
|
||||
Fixed an issue where the option to sort sequence numbers was missing from Filters prefix list in the advanced routing filters.
|
||||
|
||||
## PAN-286299
|
||||
|
||||
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tab became read-only.
|
||||
|
||||
## PAN-286231
|
||||
|
||||
Fixed an issue where a simultaneous selective push from Panorama to multiple firewalls with different base configurations resulted in configuration corruption, which caused the firewall to go down.
|
||||
|
||||
## PAN-285436
|
||||
|
||||
Fixed an issue where a selective push from Panorama caused the firewall Security policy rules to be removed on firewalls associated with the device group. This occurred when the base configuration version chosen for the selective push preceded the device configuration import operation, which caused the imported configuration to not be included in the pushed configuration.
|
||||
|
||||
## PAN-285285
|
||||
|
||||
Fixed an issue where commits remained at 98% completion when static route configuration cleanup was in progress.
|
||||
|
||||
## PAN-284117
|
||||
|
||||
```caveat
|
||||
Panorama appliances in Log Collector mode only
|
||||
```
|
||||
|
||||
Fixed an issue where the vm_agent process restarted after an upgrade.
|
||||
|
||||
## PAN-283813
|
||||
|
||||
Fixed an issue on Panorama where the web interface performance was slower than usual when retrieving read-only configurations from Panorama.
|
||||
|
||||
## PAN-283522
|
||||
|
||||
Fixed an issue where the SAML single log out (SLO) URL was not correctly displayed in the web interface after it was changed in the SAML profile.
|
||||
|
||||
## PAN-283165
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected after a period of inactivity due to the Panorama management server unnecessarily reading the running-config.xml file.
|
||||
|
||||
## PAN-281776
|
||||
|
||||
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
|
||||
|
||||
## PAN-281721
|
||||
|
||||
Fixed an issue where the firewall generated high-severity system alerts indicating that the configuration size exceeded the maximum recommended size, even when the configuration size was within the expected limits.
|
||||
|
||||
## PAN-281488
|
||||
|
||||
Fixed an issue where searching configuration logs for an audit_uuid did not return a result if the rule was created with a clone operation.
|
||||
|
||||
## PAN-281096
|
||||
|
||||
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to all, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
|
||||
|
||||
## PAN-279901
|
||||
|
||||
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
|
||||
|
||||
To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes
|
||||
|
||||
## PAN-279829
|
||||
|
||||
Fixed an issue where NAT pool leaks occurred during a test when RTSP traffic hit NAT rules.
|
||||
|
||||
## PAN-279706
|
||||
|
||||
```caveat
|
||||
M-600 appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama did not update all `panreplay` database entries after performing a commit and full push to all devices.
|
||||
|
||||
## PAN-279690
|
||||
|
||||
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to unexpectedly restart.
|
||||
|
||||
## PAN-279415
|
||||
|
||||
Fixed an issue where service routes configured to use a data plane interface incorrectly used the management plane interface for traffic transmission. This issue affected syslog and CRL status traffic when a custom service route was not configured.
|
||||
|
||||
## PAN-279400
|
||||
|
||||
Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
|
||||
|
||||
## PAN-279366
|
||||
|
||||
Fixed an issue where the firewall used an unnecessary configuration lock when running operational commands.
|
||||
|
||||
## PAN-277234
|
||||
|
||||
Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none.
|
||||
|
||||
## PAN-277178
|
||||
|
||||
Fixed an issue on Panorama where you were unable to delete a shared object due to the rulebase incorrectly referencing the shared object instead of the device group-specific object when the name was used.
|
||||
|
||||
To use this fix, delete the original shared object after cloning it to a device group with the same name.
|
||||
|
||||
## PAN-276795
|
||||
|
||||
Fixed an issue where the GlobalProtect client displayed an error message when you clicked Check Now and Preferred Releases and Base Releases were unchecked (Device > Software).
|
||||
|
||||
## PAN-275272
|
||||
|
||||
Fixed an issue where a dataplane restart was not triggered as expected when internal packet path monitoring failure occurred.
|
||||
|
||||
## PAN-274064
|
||||
|
||||
Fixed an issue on Panorama where the request batch license info CLI command displayed entries for devices that were no longer attached to Panorama.
|
||||
|
||||
## PAN-273153
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected due to excessive polling of the MonitorDirect.getTasks API by the Task Manager.
|
||||
|
||||
## PAN-271438
|
||||
|
||||
Fixed an issue where the firewall calculated available memory incorrectly on CENTOS devices, which caused the firewall to display high memory usage alerts even when sufficient memory was available.
|
||||
|
||||
## PAN-271425
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue with SSL inbound decryption on firewalls on a vwire setup with asymmetric routing.
|
||||
|
||||
To use this fix, enter the CLI command set system setting ssl-decrypt ha-vwire-mac-learn global yes on both firewalls in an HA pair.
|
||||
|
||||
## PAN-269659
|
||||
|
||||
Fixed an issue on the firewall where you were unable to configure more than 500 DHCP relay servers even though the supported limit was 4096.
|
||||
|
||||
## PAN-269155
|
||||
|
||||
Fixed an issue where an OOM condition occurred, which caused processes to stop responding.
|
||||
|
||||
## PAN-268522
|
||||
|
||||
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
|
||||
|
||||
## PAN-268002
|
||||
|
||||
Fixed an issue where URL filtering response pages were not displayed for sites that were blocked as a result of SSL/TLS handshake inspection.
|
||||
|
||||
## PAN-267330
|
||||
|
||||
Fixed an issue where the firewall dropped inbount RTP traffic after using Webex Screen Sharing due to the firewall removing the NAT cache when the predict timed out, which caused a new NAT to be established that conflicted with existing sessions. To use this fix, run the CLI command set system setting ctd h323_rtp_predict timeout <120-3600> to increase the timeout limit.
|
||||
|
||||
## PAN-265782
|
||||
|
||||
Fixed an issue on Panorama where, after you enabled multihop in a BFD profile, you were unable to disable it via the web interface.
|
||||
|
||||
## PAN-265111
|
||||
|
||||
Fixed an issue where fragmented SSL hello packets were reordered when going out of the SC/ZTT towards the datacenter.
|
||||
|
||||
## PAN-263465
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding due to a memory leak and buffer overrun.
|
||||
|
||||
## PAN-262599
|
||||
|
||||
Fixed an issue where the firewall displayed incorrect policy cache usage and configuration memory usage during a commit, which caused the configuration commit to fail with a CONFIG_UPDATE_START error. This occurred when a large number of External Dynamic Lists (EDLs), shared addresses, and policy rules were configured.
|
||||
|
||||
## PAN-261677
|
||||
|
||||
Fixed an issue where multiple smartctl processes entered a d state due to failure to read from the kernel partition, which resulted in high CPU and management impact.
|
||||
|
||||
## PAN-260827
|
||||
|
||||
Fixed an issue where the firewall consumed excessive CPU while processing traffic for a workload running on a GKE cluster, which caused reduced throughput.
|
||||
|
||||
## PAN-260661
|
||||
|
||||
Fixed an issue where daily email reports generated from the custom report did not display the report details in PDF or CSV files.
|
||||
|
||||
## PAN-256670
|
||||
|
||||
Fixed an issue where scheduled email reports were sent without PDF attachments if the firewall was in FIPS-CC mode.
|
||||
|
||||
## PAN-255860
|
||||
|
||||
```caveat
|
||||
PA-5200 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the all_pktproc process stopped responding when the firewall was under a heavy traffic load.
|
||||
|
||||
## PAN-251442
|
||||
|
||||
Fixed an issue where the firewall rebooted into maintenance mode if the authentication process restarted repeatedly.
|
||||
|
||||
## PAN-251035
|
||||
|
||||
Fixed an issue where selective push operations did not push certificate changes to the firewall.
|
||||
|
||||
## PAN-241230
|
||||
|
||||
Fixed an issue where the SNMP get request status value for Panorama connections was incorrect.
|
||||
@@ -0,0 +1,121 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h19
|
||||
---
|
||||
|
||||
## PAN-300906
|
||||
|
||||
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to missing XML-related functions for inline-cloud-proxy and session-distribution commands in dagger files handling.
|
||||
|
||||
## PAN-300096
|
||||
|
||||
Fixed an issue where a local commit on a firewall breaks template stack overrides, preventing the enabling of LACP (Link Aggregation Control Protocol). After a local commit, the LACP enable check was unexpectedly unchecked, causing an outage. Attempting to re-enable LACP through the web interface was unsuccessful, requiring manual removal of the LACP configuration from the Panorama CLI.
|
||||
|
||||
## PAN-297972
|
||||
|
||||
Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis pre-filtering signatures, even when Inline Cloud Analysis features were not enabled.
|
||||
|
||||
## PAN-297240
|
||||
|
||||
Fixed an issue where attempting to generate reports in a WildFire FIPS Private Cloud or WF-500 deployment returned 401 errors.
|
||||
|
||||
## PAN-296490
|
||||
|
||||
```caveat
|
||||
FIPS CC mode enabled only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama on GCP reboots every hour after upgrading to 11.1.6-h10. Panorama will run for up to an hour and then crash.
|
||||
|
||||
## PAN-296453
|
||||
|
||||
Fixed an issue where decryption exclusion lists were not working for untrusted certificates, and SSL sessions were still being decrypted even after adding them to the exclusion list. This occurred because the firewall was not adding sessions to the exclude cache until after receiving a non-RFC alert (BadCertificate) from the server. The fix ensures that the first session is added to the exclude cache, allowing subsequent sessions to skip decryption. This issue affects firewalls configured as clients in server-client communication.
|
||||
|
||||
## PAN-295944
|
||||
|
||||
Fixed an issue where static routes remained active in the FIB and RIB even when the associated physical port interface was down, which resulted in traffic being incorrectly routed through a non-operational interface.
|
||||
|
||||
## PAN-295560
|
||||
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors, tunnel logs were not visible in Panorama or Splunk even though traffic and threat logs were received.
|
||||
|
||||
## PAN-294893
|
||||
|
||||
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
|
||||
|
||||
## PAN-294524
|
||||
|
||||
Fixed an issue where firewalls and Panorama management servers were unable to view or download WildFire reports from a WF-500 appliance, resulting in a 401 error in the report tab.
|
||||
|
||||
## PAN-292393
|
||||
|
||||
Fixed an issue where TFTP file transfers intermittently timed out in active-active HA pairs when the TFTP control channel was processed by one firewall and the data channel was processed by the other. This occurred because the firewall receiving the data channel failed to match the predicted session due to asynchronous processing of HA messages.
|
||||
|
||||
## PAN-292229
|
||||
|
||||
Fixed an issue where Panorama was unable to retrieve userid logs from the firewall for subscribed user-ip-mappings after Panorama was rebooted.
|
||||
|
||||
## PAN-291288
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a pan_task process restart related to page allocation failures.
|
||||
|
||||
## PAN-289249
|
||||
|
||||
Fixed an issue where a memory leak occurred on the reportd process when a WildFire update was initiated while device telemetry data collection was in progress. This resulted in an OOM condition.
|
||||
|
||||
## PAN-287803
|
||||
|
||||
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.
|
||||
|
||||
## PAN-287782
|
||||
|
||||
Fixed an issue where firewalls configured in vwire mode modified DSCP values from AF11 to CS0 on traffic passing through the firewall, even when QoS policy rules and DSCP rewrite settings were not configured.
|
||||
|
||||
## PAN-287622
|
||||
|
||||
Fixed an issue where IPv6 traffic was affected after upgrading the firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.
|
||||
|
||||
## PAN-287423
|
||||
|
||||
Fixed an issue where content loading issues occurred on IPv6 websites due to the firewall incorrectly setting the IPv6 header flow label to 0.
|
||||
|
||||
## PAN-285648
|
||||
|
||||
Fixed an issue where the logrcvr process crashed on PA-7050 firewalls due to system log processing threads becoming blocked when the queue was full. This resulted in a heartbeat failure.
|
||||
|
||||
## PAN-283053
|
||||
|
||||
Fixed an issue where the firewall experienced high disk space utilization, which caused the firewall to become non-functional.
|
||||
|
||||
## PAN-282854
|
||||
|
||||
Fixed an issue where the Elasticsearch cluster did not start after deploying dedicated log collectors in a multi-collector environment.
|
||||
|
||||
## PAN-277306
|
||||
|
||||
Fixed an issue where the XML API and REST API failed to run commands and displayed an error.
|
||||
|
||||
## PAN-277135
|
||||
|
||||
Fixed an issue where the firewall stopped responding when a DNS client closed or reset a TCP connection while the firewall was sending a response.
|
||||
|
||||
## PAN-277034
|
||||
|
||||
Fixed an issue where WildFire reports were not fully displayed and were not downloadable due to static resources not being found.
|
||||
|
||||
## PAN-267450
|
||||
|
||||
Fixed an issue where the reportd process stopped responding with a SIGSEGV at schedule_report_es_response.
|
||||
|
||||
## PAN-260185
|
||||
|
||||
Fixed an issue where a dataplane crash occurred in Inline Cloud Analysis action lookup because there were no vulnerability or anti-spyware profiles in the security policy rule.
|
||||
|
||||
## PAN-253963
|
||||
|
||||
```caveat
|
||||
Panorama appliances in Panorama mode and Log Collector mode only
|
||||
```
|
||||
|
||||
Fixed an issue where autocommits took longer than expected to complete.
|
||||
@@ -0,0 +1,277 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h1
|
||||
---
|
||||
|
||||
## PAN-278088
|
||||
|
||||
Fixed an issue where the show system resources follow CLI command was not available.
|
||||
|
||||
## PAN-276546
|
||||
|
||||
Fixed an issue where a session lost the PBF rule mapping after a configuration change or commit.
|
||||
|
||||
## PAN-273994
|
||||
|
||||
A fix was made to address CVE-2025-0111.
|
||||
|
||||
## PAN-273971
|
||||
|
||||
A fix was made to address CVE-2025-0108.
|
||||
|
||||
## PAN-273300
|
||||
|
||||
Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed with a validation error.
|
||||
|
||||
## PAN-273278
|
||||
|
||||
A fix was made to address CVE-2025-0109.
|
||||
|
||||
## PAN-273245
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where upgrading an HA firewall pair from PAN-OS 10.2.11-h1 to PAN-OS 11.1.5 caused the firewalls to enter a nonfunctional loop due to repeated HA path monitoring failures.
|
||||
|
||||
## PAN-273129
|
||||
|
||||
Fixed an issue on the web interface where the negate option was visible when you clicked on the rule name, but not when you viewed the target options from the rulebase attribute.
|
||||
|
||||
## PAN-273085
|
||||
|
||||
Fixed an issue on the web interface where you were unable to edit or create policy rules.
|
||||
|
||||
## PAN-273026
|
||||
|
||||
Fixed an issue where traffic logs did not display correctly when filters were applied.
|
||||
|
||||
## PAN-273021
|
||||
|
||||
Fixed an issue where 25G port links did not come up due to a change in the handling of 25G DAC modules.
|
||||
|
||||
## PAN-272959
|
||||
|
||||
Fixed an issue where the firewall generated BGP update packets larger than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames were enabled globally.
|
||||
|
||||
## PAN-272849
|
||||
|
||||
Fixed an issue where log forwarding to a UDP syslog server stopped when an unreachable TCP syslog server was configured and applied.
|
||||
|
||||
## PAN-272538
|
||||
|
||||
Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and share-unused-objects-with-devices was set to off.
|
||||
|
||||
## PAN-272006
|
||||
|
||||
Fixed an issue where the firewall did not trigger a kernel core dump as a large core when the CPLD (Complex Programmable Logic Device) sent a Non-Maskable Interrupt (NMI) to the CPU.
|
||||
|
||||
## PAN-271926
|
||||
|
||||
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC error when the firewall was configured to decrypt and inspect TLS traffic.
|
||||
|
||||
## PAN-271912
|
||||
|
||||
Fixed an issue on Panorama where the configd process stopped responding when filtering in the configuration audit window after upgrading to PAN-OS 11.1.3.
|
||||
|
||||
## PAN-271613
|
||||
|
||||
Fixed an issue where configuration pushes from Panorama to the firewall failed due to an OOXML commit error.
|
||||
|
||||
## PAN-271314
|
||||
|
||||
Fixed an issue where pushing changes to a prefix list used for BGP from Panorama affected OSPF routes.
|
||||
|
||||
## PAN-270607
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where OSPF failed to establish after a failover from the active firewall to the passive firewall.
|
||||
|
||||
## PAN-270549
|
||||
|
||||
Fixed an issue where some TLS connections were not handled correctly, which led to instability in the dataplane.
|
||||
|
||||
## PAN-270471
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not detect configuration changes when only the interface of an IKE gateway was changed, which caused IPSec tunnels to not come up after migrating the IKE gateway IP address from a subinterface to a physical interface.
|
||||
|
||||
## PAN-269956
|
||||
|
||||
Fixed an issue where the all_pktproc process stopped responding, which caused internal path monitor failures.
|
||||
|
||||
## PAN-269899
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected when querying for device tags.
|
||||
|
||||
## PAN-269737
|
||||
|
||||
Fixed an issue where the followig critical error displayed repeatedly: /mnt/cdrom is mounted as Read-Only.
|
||||
|
||||
## PAN-269731
|
||||
|
||||
Fixed an issue where Panorama did not display logs from firewalls after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) getting restarted continuously.
|
||||
|
||||
## PAN-269499
|
||||
|
||||
Fixed an issue where the firewall stopped responding when receiving a high number of logs.
|
||||
|
||||
## PAN-269106
|
||||
|
||||
Fixed an issue where the wifclient might crash during server cert verification for MICA gRPC connections and cause the dataplane to restart when using a cloud-based ML detection engine (MICA). On certain platforms, this caused the firewall to reboot periodically.
|
||||
|
||||
## PAN-268972
|
||||
|
||||
Fixed an issue where Panorama was slower than expected when using a high number of device group tags in a non-shared context.
|
||||
|
||||
## PAN-268815
|
||||
|
||||
Fixed an issue that caused the firewall to reboot due to the wifclient exiting multiple times when using IoT Security.
|
||||
|
||||
## PAN-268465
|
||||
|
||||
Fixed an issue with firewalls in active/passive HA configurations where the the total user count in the registered users was different between the active and passive firewall.
|
||||
|
||||
## PAN-267781
|
||||
|
||||
Fixed an issue where Panorama did not display the Source Dynamic Address Group.
|
||||
|
||||
## PAN-267762
|
||||
|
||||
```caveat
|
||||
Panorama virtual appliances in Management-Only mode
|
||||
```
|
||||
|
||||
Fixed a issue where the maximum configuration size was lower than expected.
|
||||
|
||||
## PAN-267671
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to the all_task process restarting with an OOM condition due to a memory leak on the reportd process.
|
||||
|
||||
## PAN-267662
|
||||
|
||||
Fixed an issue where the firewall experienced a memory out-of-bounds access when the firewall was configured with SD-WAN and the SD-WAN plugin was loading, which caused the firewall to stop responding and drop VPN tunnels.
|
||||
|
||||
## PAN-267097
|
||||
|
||||
Fixed an issue where the replay database size increased significantly due to local and special configurations not being purged after commits.
|
||||
|
||||
## PAN-266354
|
||||
|
||||
Fixed an issue where Hybrid-SWG explicit proxy connections failed when the number of destination domains exceeded 1024.
|
||||
|
||||
## PAN-265745
|
||||
|
||||
Fixed an issue where the firewall displayed incorrect MAC receive error counters for VMWare devices hosted in ESXi.
|
||||
|
||||
## PAN-265219
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where GRE traffic did not work properly.
|
||||
|
||||
## PAN-265179
|
||||
|
||||
Fixed an issue where a kernel race condition caused the firewall to reboot with a kernel panic.
|
||||
|
||||
## PAN-264423
|
||||
|
||||
Fixed an issue where the firewall sent a 503 response when a client connected to a web server when the firewall was configured as a web proxy and authentication bypass for Kerberos was enabled.
|
||||
|
||||
## PAN-262946
|
||||
|
||||
Fixed an issue on the firewall where logging in via the CLI or web interface did not work due to increased memory usage.
|
||||
|
||||
## PAN-262383
|
||||
|
||||
Fixed an issue where the firewall was unable to decompress the HTTP2 header, which caused the session to be classified as unknown-tcp instead of web-browsing.
|
||||
|
||||
## PAN-260461
|
||||
|
||||
Fixed an issue where traffic logs showed a non-zero destination port number on ICMP echo sessions through the firewall.
|
||||
|
||||
## PAN-260290
|
||||
|
||||
Fixed an issue for fixed model licenses to support new content size requirements by reducing the total sessions supported to be equivalent to their flex memory counterpart.
|
||||
|
||||
## PAN-260235
|
||||
|
||||
Fixed an issue where the firewall sent Threat logs and URL logs to an external syslog server without Security profile settings when Enhanced Application Logging was enabled.
|
||||
|
||||
## PAN-260149
|
||||
|
||||
Fixed an issue where the management plane DNS cache size was lower than expected.
|
||||
|
||||
## PAN-259078
|
||||
|
||||
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
|
||||
|
||||
## PAN-258149
|
||||
|
||||
Fixed an issue where the firewall dropped the SYN-ACK when using the TCP Fast Open option.
|
||||
|
||||
## PAN-255323
|
||||
|
||||
```caveat
|
||||
PA-7050 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the Network Processing Card (NPC), Data Processing Card (DPC), and Log forwarding Card (LFC) remained in a starting state after an unexpected power cycle.
|
||||
|
||||
## PAN-254904
|
||||
|
||||
Fixed an issue on Panorama where a core file was generated by /usr/local/bin/logd during a restart.
|
||||
|
||||
## PAN-254293
|
||||
|
||||
Fixed an issue where an explicit proxy caused intermittent SSL handshake failures to SAP applications accessing public URLs.
|
||||
|
||||
## PAN-252381
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected when opening interfaces, virtual routers, and zones in a template or template stack.
|
||||
|
||||
## PAN-251484
|
||||
|
||||
Fixed an issue where the firewall web interface displayed incorrect PPPoE configuration options under the subinterface of an Aggregate Ethernet interface.
|
||||
|
||||
## PAN-250585
|
||||
|
||||
Fixed an issue where the firewall CPU use increased after upgrading from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system resource reporting by the REST API.
|
||||
|
||||
## PAN-248508
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not perform MSS clamping when GWLB endpoints were mapped to static subinterfaces.
|
||||
|
||||
## PAN-246699
|
||||
|
||||
Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy rules stopped incrementing.
|
||||
|
||||
## PAN-233647
|
||||
|
||||
Fixed an issue where Panorama management servers generated duplicate configuration logs.
|
||||
|
||||
## PAN-233581
|
||||
|
||||
Fixed an issue on firewalls in active/active HA configurations where SYN+ACK packets of asymmetric TCP sessions were dropped because of a session synchronization issue.
|
||||
|
||||
## PAN-224152
|
||||
|
||||
Fixed an issue where device tags for devices in a child device group were not available in the parent shared device group.
|
||||
|
||||
## PAN-216054
|
||||
|
||||
Fixed an issue that caused the firewall's fan speed to increase while it was idle.
|
||||
@@ -0,0 +1,73 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h20
|
||||
---
|
||||
|
||||
## PAN-303737
|
||||
|
||||
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to session-distribution commands in dagger files handling.
|
||||
|
||||
## PAN-299772
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in active/passive configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an HA failover event, the newly active firewall DHCP client interfaces failed to obtain IP addresses automatically. This occurred because the DHCP client processes did not initiate the necessary DHCP discover or renew requests
|
||||
|
||||
## PAN-298654
|
||||
|
||||
Fixed an issue where the firewall generate false positive threat logs during updates to a large domain list (EDL) when a DNS lookup for a domain being added or removed occurred during the update process. This resulted in a threat log being generated for a different, unrelated domain that remained on the list.
|
||||
|
||||
## PAN-298505
|
||||
|
||||
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, the vsys ID changed in sequence, causing autocommit failures with validation errors. This occurred when the multi-vsys firewall had virtual systems created and pushed from Panorama, and the vsys ID was not in a correct sequence because the unused vsys was deleted from Panorama and pushed to devices.
|
||||
|
||||
## PAN-297797
|
||||
|
||||
Fixed an issue where, during a refresh of a large External Dynamic List (EDL), traffic that matched a domain on the list was incorrectly identified as a different domain, which resulted in false positive threat logs.
|
||||
|
||||
## PAN-295221
|
||||
|
||||
Fixed an issue where, after upgrading Panorama and Log Collectors from PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not forwarded to a Splunk server over UDP.
|
||||
|
||||
## PAN-293848
|
||||
|
||||
Fixed an issue where Panorama failed to push the default value of None for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as None in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
|
||||
|
||||
## PAN-291716
|
||||
|
||||
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM) conditions, leading to device crashes and reboots.
|
||||
|
||||
## PAN-289859
|
||||
|
||||
```caveat
|
||||
Panorama virtual appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where Panorama failed to mount logging disks larger than 2TB due to a partitioning error.
|
||||
|
||||
## PAN-288388
|
||||
|
||||
Fixed an issue where, after an EDL certificate update or repository migration, authentication failures caused the firewall to not fall back to the last successfully cached EDL entries, which led to policy rules that referenced the EDL to not be enforced.
|
||||
|
||||
## PAN-287693
|
||||
|
||||
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when Use Proxy Settings for Private Cloud was enabled.
|
||||
|
||||
## PAN-284872
|
||||
|
||||
Fixed an issue where ENA (Elastic Network Adapter) extended statistics (conntrack allowance metric) were unavailable in DPDK 22.11.x. This metric is now available through AWS Cloudwatch.
|
||||
|
||||
## PAN-277682
|
||||
|
||||
Fixed an issue where moving an address object from a device group to shared and renaming it did not reflect in the address group, which caused commits to fail.
|
||||
|
||||
## PAN-262444
|
||||
|
||||
Fixed an issue where the firewall did not refresh the external dynamic list due to the first entry in the list being removed from the global external list and breaking out of the loop.
|
||||
|
||||
## PAN-257515
|
||||
|
||||
Fixed an issue where Possible Domain Fronting Detection for HTTP/2 generated false positives. With this change, domain fronting is limited to HTTP/1.
|
||||
@@ -0,0 +1,117 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h21
|
||||
---
|
||||
|
||||
## PAN-299815
|
||||
|
||||
Fixed an issue on multi-vsys firewalls where a host was not removed from the quarantine list after receiving a redistribution message from Panorama. This occurred when Panorama was configured to redistribute quarantine messages to a firewall cluster, and the GlobalProtect configuration and redistribution were built out in a vsys other than vsys1.
|
||||
|
||||
## PAN-299615
|
||||
|
||||
Fixed an issue where, when the Network Packet Broker feature was enabled, forward TLS (non-decrypted) traffic was not working as expected when there were segmented client hellos and a no-decrypt rule existed. This issue occurred when Zone Protection profiles were configured for trust/untrust zones but not attached to NPB zones.
|
||||
|
||||
## PAN-297782
|
||||
|
||||
Fixed an issue on Panorama where reassociating a vsys from one device group to another in a multi-vsys environment resulted in another vsys from the same firewall being removed from the original device group. This resulted in the device being moved into the no device groups attached group, a superuser was required to manually reattach the device.
|
||||
|
||||
## PAN-297775
|
||||
|
||||
Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual Systems field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs.
|
||||
|
||||
## PAN-296752
|
||||
|
||||
Fixed an issue where the firewall experienced high management CPU usage and repeatedly rebooted when attempting to retrieve SMART data.
|
||||
|
||||
## PAN-295470
|
||||
|
||||
Fixed an issue on the firewall where the useridd process continuously increased its memory consumption, which resulted in an OOM condition that caused the firewall to restart.
|
||||
|
||||
## PAN-293847
|
||||
|
||||
Fixed an issue where EAL logs for traffic matching the intrazone-default Security policy rule were not forwarded to the IoT Security portal.
|
||||
|
||||
## PAN-292261
|
||||
|
||||
Fixed an issue where the firewall repeatedly reported an unreachable syslog server as back online when the server remained unavailable. This resulted in misleading alternating connection status messages in the system logs.
|
||||
|
||||
## PAN-291661
|
||||
|
||||
Fixed an issue on Panorama appliances and Log Collectors where, after an upgrade, Elasticsearch intermittently entered into a Red state before automatically recovering.
|
||||
|
||||
## PAN-291653
|
||||
|
||||
Fixed an issue where the GlobalProtect host ID field was intermittently blank in traffic logs on Prisma Access, even when the user was connected and had the correct host ID information. This occurred when the IP address to host ID entry expired and the entry was re-insterted without the dataplane flag being set.
|
||||
|
||||
## PAN-289405
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Added the CLI command no-refresh-discard-session to address an issue where the discarded session time to live (TTL) did not refresh at the default value.
|
||||
|
||||
## PAN-289067
|
||||
|
||||
Fixed an issue where, after upgrading Panorama in a High Availability (HA) pair, the configuration logs stopped synchronizing from the primary Panorama to the secondary Panorama. This issue occurred because the log forwarding flag was permanently disabled due to the connection state not being active when the log-fwd-ctrl message was received.
|
||||
|
||||
## PAN-288930
|
||||
|
||||
Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.
|
||||
|
||||
## PAN-288761
|
||||
|
||||
Fixed an issue on the firewall where the logrcvr process stopped responding.
|
||||
|
||||
## PAN-288097
|
||||
|
||||
Fixed an issue where on the firewall where the routed process stopped responding after changing the MTU or any link state parameters when OSPF and PIM were enabled on the same interface.
|
||||
|
||||
## PAN-287314
|
||||
|
||||
Fixed an issue with firewalls in active/passive HA configurations where an OOM condition occurred and caused a failover due to a memory leak associated with the logrcvr process.
|
||||
|
||||
## PAN-285169
|
||||
|
||||
Fixed an issue on Panorama where Kerberos superusers were unable to edit policy rules because the target device tab was grayed out.
|
||||
|
||||
## PAN-283954
|
||||
|
||||
Fixed an issue where the configd process stopped responding due to a circular reference between address groups.
|
||||
|
||||
## PAN-282093
|
||||
|
||||
Enhanced the CLI command request legacy reset to delete the legacy certificate files that were being used to connect with the secondary Panorama appliance.
|
||||
|
||||
## PAN-274797
|
||||
|
||||
Fixed an issue where a DPC on slot 3 failed intermittently due to the pktlog_forwarding process restarting, which resulted in an unexpected HA failover.
|
||||
|
||||
## PAN-272539
|
||||
|
||||
```caveat
|
||||
Panorama appliances on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where user to IP address mapping was missing for some users connected to specific Prisma Access gateways, which caused the collection layer Azure firewall to not form the mapping.
|
||||
|
||||
## PAN-272175
|
||||
|
||||
Fixed an issue where session rematch caused ACE cloud application traffic to match the wrong policy rule.
|
||||
|
||||
## PAN-271507
|
||||
|
||||
```caveat
|
||||
PA-5450 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the DPC on slot 3 intermittently stopped responding due an all_pktproc restart.
|
||||
|
||||
## PAN-258039
|
||||
|
||||
Fixed an issue where the firewall displayed the incorrect rule name when a threat log was generated for Inline Cloud Analyzed CMD Injection Traffic Detection.
|
||||
|
||||
## PAN-251715
|
||||
|
||||
Fixed an issue where the firewall closed the SSL connection to the user ID agent.
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h22
|
||||
---
|
||||
|
||||
## PAN-306226
|
||||
|
||||
Fixed an issue where the TLS handshake did not complete and the session did not go through. This occurred if the HTTP header insertion applied to an HTTP CONNECT request passing through the firewall, the scan-handshake feature was enabled, the session matched a decryption policy rule with the decrypt action, and if the TLS client hello was in a single packet and TLS 1.2 or below.
|
||||
@@ -0,0 +1,117 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h23
|
||||
---
|
||||
|
||||
## PAN-306502
|
||||
|
||||
Fixed an issue where TLS connection failure occurred when traffic was over TLS1.2 or below, header insertion was enabled on the firewall, send TLS handshake to CTD was enabled, and traffic hit a decryption policy rule configured with the no-decrypt action.
|
||||
|
||||
## PAN-304636
|
||||
|
||||
Fixed an issue where BGP aggregate routes were not created and discard routes were not installed in the routing table.
|
||||
|
||||
## PAN-306226
|
||||
|
||||
Fixed an issue where the TLS handshake did not complete and the session did not go through. This occurred if the HTTP header insertion applied to an HTTP CONNECT request passing through the firewall, the scan-handshake feature was enabled, the session matched a decryption policy rule with the decrypt action, and if the TLS client hello was in a single packet and TLS 1.2 or below.
|
||||
|
||||
## PAN-304496
|
||||
|
||||
Fixed an issue where, after unregistering an IP tag and registering a different IP tag for the same IP address via XML API, the dynamic address group membership was not updated on the dataplane, which resulted in Security policy rules being enforced incorrectly.
|
||||
|
||||
## PAN-303954
|
||||
|
||||
Fixed an issue where, when configuring Safenet HSMs in HA and authentication HSM manually, the second HSM server failed to authenticate due to the firewall overwriting the first HSM server's certificate with the second HSM server's certificate.
|
||||
|
||||
## PAN-303051
|
||||
|
||||
Fixed an issue on Panorama where a memory leak occurred related to the reportd process due to retaining memory that was temporarily used for report generation instead of releasing the memory for reuse, which resulted in continuous accumulation and memory exhaustion.
|
||||
|
||||
## PAN-301801
|
||||
|
||||
Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
|
||||
|
||||
## PAN-300637
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall unexpectedly rebooted due to repeated varrcvr process restarts.
|
||||
|
||||
## PAN-300548
|
||||
|
||||
Fixed an issue where using the IKEv2 multiplier setting for VPN re-authentication resulted in the firewall not re-authenticating at the expected intervals when both sides initiated rekeying. The internal re-authentication counter incremented when the local side triggered the rekey, but not when the peer side triggered it.
|
||||
|
||||
## PAN-297975
|
||||
|
||||
Fixed an issue where Panorama was unable to push the Trusted Root CA configuration to Log Collectors via a Collector Group push due to the Log Collector not supporting the trusted-root-CA configuration.
|
||||
|
||||
## PAN-297708
|
||||
|
||||
Fixed an issue where a long-lived session with many Machine Learning (ML) model triggers caused a memory leak of feature states associated with the ML model runs. This resulted in Spyware_State failure increases, allocation max outs, and impaired policy matching.
|
||||
|
||||
## PAN-297610
|
||||
|
||||
Fixed an issue where the firewall became unresponsive after an upgrade due to the fsck command scanning drive partitions in parallel with the root partition, which caused the process to take an extended amount of time.
|
||||
|
||||
## PAN-297295
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall repeatedly restarted due to high packet rates on the synthetic path in DPDK mode.
|
||||
|
||||
## PAN-288158
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall became inaccessible via the web interface and SSH and remained in an initializing state.
|
||||
|
||||
## PAN-287611
|
||||
|
||||
Fixed an issue where, after upgrading, the firewall incorrectly calculated the UDP checksum for RTP traffic after NAT and Security policy application, which led to dropped packets and silent calls in applications.
|
||||
|
||||
## PAN-284866
|
||||
|
||||
Fixed an issue where the LFC failed to validate Certificate Revocation Lists (CRL) for SSL syslog connections, which caused a failure to forward logs to external syslog servers.
|
||||
|
||||
## PAN-278126
|
||||
|
||||
Fixed an issue where the number of registered IP Tags on Panorama did not match the number of registered IP Tags on the managed firewalls due to a change in file format between PAN-OS releases.
|
||||
|
||||
## PAN-274697
|
||||
|
||||
Fixed an issue where push operations from Panorama failed on passive firewalls when an application was removed from a Security policy rule and the policy rule was referenced in a device group.
|
||||
|
||||
## PAN-270554
|
||||
|
||||
Fixed an issue where the GlobalProtect client (UWP) or metered hotspot connections triggered TLS resumption for GlobalProtect portal authentication, which caused the portal authentication to fail with a valid cert required error.
|
||||
|
||||
## PAN-260090
|
||||
|
||||
Fixed an issue where commit all operations failed when the application openair-psa was used as a keyword on a remote network instance that was upgraded to an affected release.
|
||||
|
||||
## PAN-257616
|
||||
|
||||
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
||||
|
||||
## PAN-257362
|
||||
|
||||
Fixed an issue where GlobalProtect traffic destined for the internet did not follow the path-based forwarding (PBF) rule and was sent out the wrong interface.
|
||||
|
||||
## PAN-255253
|
||||
|
||||
Fixed an issue where the firewall did not establish a syslog connection to the probe VM syslog server in ADEM Regressions.
|
||||
|
||||
## PAN-242602
|
||||
|
||||
Fixed an issue where GlobalProtect clients experienced slow SMB-V3 download throughput when passing through a Prisma IPSec tunnel and the firewall and the SMB-V3 session owner dataplane was the same as the IPSec-ESP tunnel on the multi-dataplane firewall.
|
||||
|
||||
## PAN-241694
|
||||
|
||||
Fixed an issue where memory leaks related to the devsrvr process occurred when downloading and pushing updates from the App-ID Cloud Engine to the dataplane.
|
||||
@@ -0,0 +1,139 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h25
|
||||
---
|
||||
|
||||
## PAN-308060
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the BFD session went down and did not recover even though the BGP remained in an established state, which caused the firewall to cease route learning and advertisement with the peer, even though BGP keep-alives were exchanged correctly.
|
||||
|
||||
## PAN-307795
|
||||
|
||||
Fixed an issue where Panorama incorrectly generated system logs indicating a lost connection to its peer after an upgrade even when High Availability was not configured.
|
||||
|
||||
## PAN-305412
|
||||
|
||||
Fixed an issue where the Logging Service License Status displays a license failure when the license status transitions from valid to expired and then back to valid even when the connection to the Security Logging Service (SLS) was working.
|
||||
|
||||
## PAN-305301
|
||||
|
||||
Fixed an issue where the timing of GlobalProtect lifetime expiry or inactivity logout notifications used for GlobalProtect SSL tunnels could cause the pan_task process to stop responding and the dataplane to restart.
|
||||
|
||||
## PAN-303959
|
||||
|
||||
Fixed an issue where traffic is incorrectly identified as unknown-tcp/unknown-udp due to App-ID resource leak and eventually dropped.
|
||||
|
||||
## PAN-302551
|
||||
|
||||
Fixed an issue where the firewall displayed as disconnected in the SLS due to the serial number not being retrieved
|
||||
|
||||
## PAN-301975
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the passive firewall incorrectly triggered PBP alerts even with low packet rates.
|
||||
|
||||
## PAN-301912
|
||||
|
||||
Fixed an issue where Panorama stopped responding when deploying dynamic updates to managed devices.
|
||||
|
||||
## PAN-301600
|
||||
|
||||
Fixed an issue on the firewall where, after upgrading Panorama, OSPF adjacencies remained in the exchange start state, which resulted in an incomplete routing table.
|
||||
|
||||
## PAN-301456
|
||||
|
||||
Fixed an issue on Panorama where the debug system reset-ztp CLI command was unavailable.
|
||||
|
||||
## PAN-301409
|
||||
|
||||
Fixed an issue where Panorama failed to perform a selective push to a managed device when device tags were added or modified on the policy rules. The selective push failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
||||
|
||||
## PAN-300837
|
||||
|
||||
Fixed an issue where firewalls experienced multiple reboots due to the pan_task process restarting with a SIGSEGV signal. This occurred because the client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
||||
|
||||
## PAN-299751
|
||||
|
||||
Fixed an issue where the firewall was unable to connect to the Subscription License Service (SLS) due to a public and private key pair mismatch with the device certificate.
|
||||
|
||||
## PAN-298907
|
||||
|
||||
Fixed an issue on PA-VM in AWS where, in a two-arm deployment integrated with Gateway Load Balancer (GWLB), the firewall did not preserve the GENEVE source port for internet traffic, resulting in increased latency. The fix ensures the firewall preserves the outer UDP source port of GENEVE encapsulation when sending traffic back to GWLB.
|
||||
|
||||
## PAN-298872
|
||||
|
||||
```caveat
|
||||
PA-400 Series firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where ports went down after an HA failover.
|
||||
|
||||
## PAN-297263
|
||||
|
||||
```caveat
|
||||
PA-5220 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the ikemgr process crashed intermittently, causing IPSec tunnels to go down randomly. The fix ensures that the IKE security association data structures are accessed in a thread-safe manner. This prevents the ikemgr process from referencing an invalid memory pointer during teardown operations and provides stability.
|
||||
|
||||
## PAN-296208
|
||||
|
||||
Fixed an issue where the firewall did not accept address groups in the filter condition of a Log Forwarding Match list.
|
||||
|
||||
## PAN-290241
|
||||
|
||||
Fixed an issue where the useridd process became unresponsive, which caused User-ID CLI commands to time out.
|
||||
|
||||
## PAN-289652
|
||||
|
||||
Fixed an issue related to external URL lists where pushing configuration changes from Panorama failed.
|
||||
|
||||
## PAN-288427
|
||||
|
||||
Fixed an issue on Panorama where commit jobs were not queued and the system reported that the useridd was not connected.
|
||||
|
||||
## PAN-287921
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the maximum registered IP address for was incorrectly set to 100,000 instead of the expected 500,000.
|
||||
|
||||
## PAN-285208
|
||||
|
||||
Fixed an issue where the firewall did not automatically recover after a machine check exception (MCE) occurred.
|
||||
|
||||
## PAN-281588
|
||||
|
||||
Fixed an issue where packet buffer depletion occurred due to the a high number of tcp_pkt_queued packets when Jumbo was enabled.
|
||||
|
||||
## PAN-272731
|
||||
|
||||
Fixed an issue on Panorama where commits took longer than expected due to the show object dynamic-address-group all CLI command holding the devicetable lock for an extended period.
|
||||
|
||||
## PAN-263691
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to a memory leak in the all_task process.
|
||||
|
||||
## PAN-253921
|
||||
|
||||
Fixed an issue where the firewall displayed the following error message: critical userid registe 0 fail to integrate the update of registered ip addresses since 2 seconds ago; critical system log alerts observed.
|
||||
|
||||
## PAN-185731
|
||||
|
||||
Fixed an issue where the firewall was unable to parse the URL path and host when the host header was located in a different packet, which resulted in the firewall not logging the URL path in the first packet. The fix is disabled by default. The following CLI commands can be used to enable/disable the feature: set system setting ctd url-crosspkt-host-path-caching enableset system setting ctd url-crosspkt-host-path-caching disableset system setting ctd url-crosspkt-host-path-caching default
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching enable
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching disable
|
||||
|
||||
set system setting ctd url-crosspkt-host-path-caching default
|
||||
@@ -0,0 +1,97 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h3
|
||||
---
|
||||
|
||||
## PAN-279604
|
||||
|
||||
Fixed an issue where scheduled SaaS application usage reports were generated incorrectly, and the login page was displayed instead of the report content.
|
||||
|
||||
## PAN-274791
|
||||
|
||||
Fixed an issue where the firewall might reboot when traffic matches with certain Advanced features (such as Advanced Threat Prevention and Advanced URL Filtering with properly configured URL Filtering/Anti-Spyware/Vulnerability security profiles) and Shared Pool Type 32 becomes depleted.
|
||||
|
||||
## PAN-274592
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not fail over when the active firewall experienced data plane issues.
|
||||
|
||||
## PAN-273949
|
||||
|
||||
Fixed an issue where the firewall generated the following error message in the snmpd logs: pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key X2F1dGhfa2V5 import from cryptod failed.
|
||||
|
||||
## PAN-273019
|
||||
|
||||
Fixed an intermittent issue where SSL decryption failed.
|
||||
|
||||
## PAN-271723
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the all_task process stopped responding, which caused the passive firewall to repeatedly reboot.
|
||||
|
||||
## PAN-270248
|
||||
|
||||
Fixed an issue where the firewall failed to forward logs to a SNMP trap server if the SNMP manager IP address was unable to be resolved.
|
||||
|
||||
## PAN-269091
|
||||
|
||||
Fixed an issue where the varrcvr process stopped responding.
|
||||
|
||||
## PAN-268909
|
||||
|
||||
Fixed an issue where IP address tags were removed from firewalls after a management server or useridd process restart. This occurred when a Panorama serial-number based configuration was used for User-ID redistribution.
|
||||
|
||||
## PAN-268800
|
||||
|
||||
Fixed an issue where a large number of logs caused the logrcvr process to stop responding.
|
||||
|
||||
## PAN-267995
|
||||
|
||||
Fixed an issue where after migrating to a new platform, DLP verdicts were not displayed in the Cloud Manager or logs.
|
||||
|
||||
## PAN-267204
|
||||
|
||||
Fixed an issue where Panorama port 9300 did not adhere to restricted TLS versions and ciphers.
|
||||
|
||||
## PAN-266559
|
||||
|
||||
Fixed an issue where partial commits failed when objects that were referenced in a high number of Security policy rules were renamed.
|
||||
|
||||
## PAN-266116
|
||||
|
||||
Fixed an issue where URLs did not work due to certificate revocation list (CRL) requests failing.
|
||||
|
||||
## PAN-263291
|
||||
|
||||
Fixed an issue where Microsoft Outlook did not work as expected when the GlobalProtect clientless VPN was configured.
|
||||
|
||||
## PAN-261998
|
||||
|
||||
Fixed an issue where the firewall configuration process restarted during an External Dynamic List refresh or a commit and push operation.
|
||||
|
||||
## PAN-260300
|
||||
|
||||
```caveat
|
||||
PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue related to the all_pktproc process where DPC slot 3 stopped responding.
|
||||
|
||||
## PAN-259076
|
||||
|
||||
Fixed an issue where the firewall displayed an OCSP/CRL check failure when accessing websites.
|
||||
|
||||
## PAN-258570
|
||||
|
||||
Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr process progressively using more memory when WildFire file forwarding is handling PE files.
|
||||
|
||||
## PAN-255619
|
||||
|
||||
Fixed an intermittent issue where file downloads from websites failed when decrypting HTTP/2 traffic.
|
||||
@@ -0,0 +1,77 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h4
|
||||
---
|
||||
|
||||
## PAN-282236
|
||||
|
||||
Fixed an issue where large IPv6 packets were reassembled on the firewall when the packets arrived fragmented over an IPv4 tunnel.
|
||||
|
||||
## PAN-280471
|
||||
|
||||
Fixed an issue where navigating PanoramaMonitorLogs was slower than expected.
|
||||
|
||||
## PAN-279746
|
||||
|
||||
Fixed an issue where SMTP packets were not sent out when the Client Hello arrived at the firewall in multiple out-of-order segments and the traffic was not subject to SSL decryption.
|
||||
|
||||
## PAN-279191
|
||||
|
||||
Fixed an issue where a GlobalProtect gateway stopped responding when handling HTTP/1.1 traffic with web inspection enabled.
|
||||
|
||||
## PAN-278684
|
||||
|
||||
```caveat
|
||||
PA-445 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not properly power cycle during a reboot.
|
||||
|
||||
## PAN-277147
|
||||
|
||||
Fixed an issue where daily scheduled reports were not generated and emailed.
|
||||
|
||||
## PAN-276062
|
||||
|
||||
Fixed an issue where importing a firewall with a large number of address objects into Panorama did not work and remained at 99% completion.
|
||||
|
||||
## PAN-275905
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected and Elasticsearch CPU usage was high.
|
||||
|
||||
## PAN-275754
|
||||
|
||||
Added support for bootstrapping Panorama virtual appliances on ESXi.
|
||||
|
||||
## PAN-275032
|
||||
|
||||
```caveat
|
||||
M-600 appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where the Elasticsearch cluster certificate (CC) status displayed with a past expiration date, which caused all shards to be unassigned.
|
||||
|
||||
## PAN-273141
|
||||
|
||||
Fixed an issue where GlobalProtect clients experienced slow file transfer download throughput when passing through an IPSec tunnel.
|
||||
|
||||
## PAN-272085
|
||||
|
||||
Fixed an issue where the firewall might crash and reboot when DoH is enabled for DNS Security and multiple DoH transactions are sent in a single HTTP/1 connection.
|
||||
|
||||
## PAN-270744
|
||||
|
||||
Fixed an issue where API calls to Panorama failed with the error Server error : Timed out while getting config lock. Please try again.
|
||||
|
||||
## PAN-269291
|
||||
|
||||
Fixed an issue where the scheduled report generation script did not return debug information.
|
||||
|
||||
## PAN-268279
|
||||
|
||||
Fixed an issue where autocommits failed if the management IPv6 gateway was the same as the dataplane interface IP address.
|
||||
|
||||
## PAN-267650
|
||||
|
||||
Fixed an issue where the firewall did not detect the eth1/1 and eth1/2 interfaces when you created a firewall on an ESXi 8 server.
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h5
|
||||
---
|
||||
|
||||
## PAN-282022
|
||||
|
||||
Fixed the support limitation for the Panorama M-600 and M-700 appliances.
|
||||
@@ -0,0 +1,201 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h6
|
||||
---
|
||||
|
||||
## PAN-282022
|
||||
|
||||
Fixed the support limitation for the Panorama M-600 and M-700 appliances.
|
||||
|
||||
## PAN-281885
|
||||
|
||||
Fixed an issue where, when exporting and importing CSV files, the hash values of pre-shared key variables set at template and template stack levels changed inconsistently, which resulted in both variables displaying the same hash value.
|
||||
|
||||
## PAN-281269
|
||||
|
||||
```caveat
|
||||
PA-5220, PA-5250, and PA-5420 firewalls
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall management server memory usage continuously increased.
|
||||
|
||||
## PAN-281264
|
||||
|
||||
Fixed an issue where the routed process memory usage continuously increased when Advanced Routing was enabled.
|
||||
|
||||
## PAN-280505
|
||||
|
||||
Fixed an issue where the web interface did not display a message to commit prior changes before attempting a partial configuration load.
|
||||
|
||||
## PAN-280243
|
||||
|
||||
Fixed an issue where the firewall lost the pre-shared key configuration assigned from a PSK variable when an unrelated device group configuration was loaded.
|
||||
|
||||
## PAN-279336
|
||||
|
||||
Fixed an issue where the CLI did not display a message to commit prior changes before loading a partial configuration.
|
||||
|
||||
## PAN-279176
|
||||
|
||||
Fixed an issue where the configuration audit displayed inaccurate information after partially loading the configuration via the CLI, which caused the audit to flag the configuration as deleted or changed.
|
||||
|
||||
## PAN-279065
|
||||
|
||||
Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.
|
||||
|
||||
## PAN-278296
|
||||
|
||||
Fixed an issue where the system MAC address of the aggregate interface was the same on the active firewall and the passive firewall after an upgrade.
|
||||
|
||||
## PAN-277762
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
|
||||
|
||||
## PAN-277631
|
||||
|
||||
Fixed an issue where the logrcvr process discarded logs due to a full queue.
|
||||
|
||||
## PAN-275718
|
||||
|
||||
Fixed an issue where Panorama stopped forwarding logs to a Syslog server after upgrading to PAN-OS 11.1.5-h1.
|
||||
|
||||
## PAN-275713
|
||||
|
||||
Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the Active Directory returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
|
||||
|
||||
## PAN-275077
|
||||
|
||||
Fixed an issue where DNS Security intermittently logs malicious domain URLs as Alert instead of taking a Sinkhole action, even when configured to Sinkhole malicious DNS domains.
|
||||
|
||||
## PAN-274750
|
||||
|
||||
Fixed an issue where the detailed log view in Panorama did not display all packet details for traffic logs received from the cloud.
|
||||
|
||||
## PAN-273694
|
||||
|
||||
Fixed an issue where the firewall rebooted due to an out-of-bounds memory access that occurred as a result of the SIP content length value being split across packets.
|
||||
|
||||
## PAN-273453
|
||||
|
||||
Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.
|
||||
|
||||
## PAN-272746
|
||||
|
||||
```caveat
|
||||
PA-440 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall entered an unstable state after committing changes or onboarding to Panorama.
|
||||
|
||||
## PAN-272171
|
||||
|
||||
Fixed an issue where the firewall dropped the AAAA DNS server response and caused delays in traffic from Ubuntu or Linux clients when DNS Security was enabled.
|
||||
|
||||
## PAN-271498
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls in FIPS mode only
|
||||
```
|
||||
|
||||
Fixed an issue where decrypted traffic repeatedly failed and frequent reboots were required.
|
||||
|
||||
## PAN-271351
|
||||
|
||||
A fix was made to address CVE-2025-0116.
|
||||
|
||||
## PAN-270193
|
||||
|
||||
Fixed an issue where the Panorama management server changed its certificate authority (CA) unexpectedly, which caused managed firewalls to disconnect.
|
||||
|
||||
## PAN-269052
|
||||
|
||||
Fixed an issue where traffic was blocked by a URL filtering profile even though the Security policy rule did not have a URL filtering profile configured.
|
||||
|
||||
## PAN-268629
|
||||
|
||||
Fixed an issue where traffic did not match the correct security policy when using an application-filter that references a cloud application. This occurred when a high number of cloud applications were attached with a custom tag.
|
||||
|
||||
## PAN-267518
|
||||
|
||||
Fixed an issue where WildFire submission logs incorrectly reported allowed malicious samples even when they were blocked by threat prevention profiles.
|
||||
|
||||
## PAN-266695
|
||||
|
||||
Fixed an issue on Panorama where a cyclic nested address group configuration caused the configd process to stop responding after a commit.
|
||||
|
||||
## PAN-262063
|
||||
|
||||
Fixed an issue where the firewall did not display the converted configurations before a commit and reboot, and the commit failed when attempting to migrate from MS to FRR mode.
|
||||
|
||||
## PAN-261825
|
||||
|
||||
Fixed an issue where traffic was dropped when Data Loss Prevention or Advanced URL Filtering were enabled. This occurred when the payload size was greater than 3.5 KB.
|
||||
|
||||
## PAN-261739
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall displayed 0 for the physical port counters read from MAC.
|
||||
|
||||
## PAN-261597
|
||||
|
||||
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to become unavailable.
|
||||
|
||||
## PAN-261312
|
||||
|
||||
Fixed an issue where a commit for a policy and configuration dump overlapped, which resulted in a null pointer exception.
|
||||
|
||||
## PAN-260059
|
||||
|
||||
Fixed an issue where Device Telemetry Regions did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off.
|
||||
|
||||
## PAN-259767
|
||||
|
||||
Fixed an issue where GlobalProtect users were unable to connect when the option Block sessions if the certificate was not issued to the authenticating device was enabled in the certificate profile.
|
||||
|
||||
## PAN-258743
|
||||
|
||||
Fixed an issue where, when you attempted to select a redistribution profile when creating a BGP Redistribute policy rule, the firewall displayed an empty dropdown.
|
||||
|
||||
## PAN-258680
|
||||
|
||||
Fixed an issue on Panorama where, when you removed Security profile groups from a Security policy rule via the CLI and committed the change, the Security policy rule was deleted.
|
||||
|
||||
## PAN-257183
|
||||
|
||||
Fixed an issue where the firewall dropped DNS traffic when using DNS Security.
|
||||
|
||||
## PAN-256904
|
||||
|
||||
Fixed an issue where the firewall inconsistently blocked URLs due to intermittent URL category misidentification.
|
||||
|
||||
## PAN-253127
|
||||
|
||||
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the hardware pool DFLT became highly utilized, and the packet buffer gradually increased.
|
||||
|
||||
## PAN-251724
|
||||
|
||||
Fixed an issue where users matched incorrect Security policy rules with a HIP profile.
|
||||
|
||||
## PAN-235733
|
||||
|
||||
Fixed an issue where the displayed NTP information was incorrect if the DNS servers timed out.
|
||||
|
||||
## PAN-234993
|
||||
|
||||
Fixed an issue where CPU base gateway auto-scaling failed, which caused performance issues.
|
||||
|
||||
## PAN-233868
|
||||
|
||||
Fixed an issue where the firewall took an incorrect action for overlapping custom and edl-url-categories in a policy rule.
|
||||
|
||||
## PAN-212889
|
||||
|
||||
Fixed an issue on Panorama where different threat names were used when querying a threat under Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in Threat Monitor and filtering it in the global filters.
|
||||
@@ -0,0 +1,105 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6-h7
|
||||
---
|
||||
|
||||
## PAN-286255
|
||||
|
||||
Fixed an issue where, when the firewall received an unexpected termination request for SSL sessions, the dataplane experienced a slow buffer resource leak.
|
||||
|
||||
## PAN-285941
|
||||
|
||||
Fixed an issue where high memory consumption occurred on the logrcvr process.
|
||||
|
||||
## PAN-285651
|
||||
|
||||
```caveat
|
||||
Panorama appliances in active/passive HA configurations on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue on Panorama that caused firewalls to disconnect unexpectedly.
|
||||
|
||||
## PAN-285597
|
||||
|
||||
Fixed an issue where a routed process memory leak occurred when advanced routing was enabled.
|
||||
|
||||
## PAN-282391
|
||||
|
||||
Fixed an issue on Panorama where a memory leak occurred after cloning a template, resulting in an increase in memory use, which caused OOM errors.
|
||||
|
||||
## PAN-282206
|
||||
|
||||
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
|
||||
|
||||
## PAN-282069
|
||||
|
||||
Fixed an issue on Panorama where Security policy rules were removed from device groups when you cloned or edited Security policy rules that used more than 63 characters.
|
||||
|
||||
## PAN-281649
|
||||
|
||||
Fixed an issue where the index size limit was incorrectly calculated and indices rolled over earlier than expected, which resulted in high memory and OOM errors.
|
||||
|
||||
## PAN-280942
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding.
|
||||
|
||||
## PAN-279691
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall didn't synchronize IPSec SAs (security associations) to the passive firewall if the tunnel was not initially established by the active firewall.
|
||||
|
||||
## PAN-274671
|
||||
|
||||
Fixed an issue where empty traffic logdb folders were generated for each day even when trafcfic logs were not received by the logrcvr process.
|
||||
|
||||
## PAN-274570
|
||||
|
||||
Fixed an issue where the devsrvr process restarted after a failed commit due to an invalid memory access.
|
||||
|
||||
## PAN-271701
|
||||
|
||||
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and Enhanced Application Log stopped working due to incorrect memory usage accounting, which caused memory usage to remain at 99% after an extended period of time.
|
||||
|
||||
## PAN-271273
|
||||
|
||||
Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
|
||||
|
||||
## PAN-271175
|
||||
|
||||
Fixed an issue where the all_task process stopped responding with a SIGABRT.
|
||||
|
||||
## PAN-269027
|
||||
|
||||
Fixed an issue related to external dynamic lists that caused commit times on the firewall to be higher than expected.
|
||||
|
||||
## PAN-268614
|
||||
|
||||
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.
|
||||
|
||||
## PAN-268118
|
||||
|
||||
Fixed an issue on firewalls in active/passive HA configurations where, after a failover, irrelevant routing FIB entries were seen in the routing table on the newly active firewall.
|
||||
|
||||
## PAN-267444
|
||||
|
||||
Fixed an issue where large file downloads or uploads failed or remained in an incomplete state when using DLP HTTP2 mirror mode.
|
||||
|
||||
## PAN-260015
|
||||
|
||||
Fixed an issue on the firewall where the dataplane restarted due to insufficient allocation of memory buffers.
|
||||
|
||||
## PAN-256867
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding while processing session logs for forwarding to the LFC.
|
||||
|
||||
## PAN-255914
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) environments only
|
||||
```
|
||||
|
||||
Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.
|
||||
@@ -0,0 +1,229 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.6
|
||||
---
|
||||
|
||||
## PAN-273215
|
||||
|
||||
Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading.
|
||||
|
||||
## PAN-271913
|
||||
|
||||
Fixed an issue on firewalls in high availability (HA) configurations where, when using the Cloud Identity Engine (CIE), the firewall experienced consistent memory leaks on the active firewall, which caused unexpected failovers.
|
||||
|
||||
## PAN-270224
|
||||
|
||||
Fixed an issue where indices were not opened after a query.
|
||||
|
||||
## PAN-269539
|
||||
|
||||
Fixed an issue where whitespace was added before the timestamp in syslog logs forwarded from Panorama.
|
||||
|
||||
## PAN-269000
|
||||
|
||||
Fixed an issue where the firewall stopped responding due to a NULL pointer dereference when path monitoring failed.
|
||||
|
||||
## PAN-268951
|
||||
|
||||
Fixed a CPS counter query issue that caused SNMP polling timeouts on the firewall.
|
||||
|
||||
## PAN-268727
|
||||
|
||||
Fixed an issue where traffic was dropped when the accumulation proxy was enabled and header insertion modified packets.
|
||||
|
||||
## PAN-268474
|
||||
|
||||
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop.
|
||||
|
||||
## PAN-268419
|
||||
|
||||
Fixed an issue where Managed Devices > Summary displayed incorrect subcolumns.
|
||||
|
||||
## PAN-268319
|
||||
|
||||
Fixed an issue where Receive Time and Time Generated were not visible as attributes in the Filter Builder for system logs and URL filtering logs.
|
||||
|
||||
## PAN-268229
|
||||
|
||||
Fixed an issue where the firewall stopped responding during session setup for ECMP hit-count updates.
|
||||
|
||||
## PAN-268228
|
||||
|
||||
Fixed an issue where Panorama administrators were unable to select Edit Selection when pushing changes to devices if they logged in using TACACS authentication.
|
||||
|
||||
## PAN-267934
|
||||
|
||||
Fixed an issue where commits remained at 98%, which resulted in the BGP connection flapping.
|
||||
|
||||
## PAN-267590
|
||||
|
||||
Fixed a lock usage error that caused the ikemgr process to stop responding.
|
||||
|
||||
## PAN-267348
|
||||
|
||||
Fixed an issue on the Panorama web interface where WildFire Activity by File Type in the ACC did not display the file type name.
|
||||
|
||||
## PAN-267321
|
||||
|
||||
Fixed an issue where packets were dropped when BFD inter-dataplane packet forwarding failed.
|
||||
|
||||
## PAN-267285
|
||||
|
||||
Fixed an issue where a port was able to be connected from outside the network. With this fix, the port is restricted to the local interface.
|
||||
|
||||
## PAN-267091
|
||||
|
||||
Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
|
||||
|
||||
## PAN-266900
|
||||
|
||||
Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall.
|
||||
|
||||
## PAN-266639
|
||||
|
||||
Fixed an issue where administrators were unable to edit or add virtual router configurations when a filter was applied to the viewer.
|
||||
|
||||
## PAN-266581
|
||||
|
||||
Fixed an issue where a failed SSL connection to a syslog server resulted in a /tmp/srvr.crt.xxxxxx file not being removed, which caused index node (inode) exhaustion.
|
||||
|
||||
## PAN-266167
|
||||
|
||||
Fixed an issue where the restart option for IPSec tunnels was greyed out (Network > IPSec Tunnels > IKE Info).
|
||||
|
||||
## PAN-266003
|
||||
|
||||
Fixed an issue on the firewall where a configuration policy push caused both active and passive firewalls to go down when a high number of spyware profiles and vulnerability profiles were pushed to the dataplane.
|
||||
|
||||
## PAN-265621
|
||||
|
||||
Fixed an issue where the restart option for IPSec tunnels was greyed out when you attempted to restart the tunnel from Network > IPSec Tunnels > IKE Info.
|
||||
|
||||
## PAN-265399
|
||||
|
||||
Fixed an issue where DNS queries for uppercase internal domain (SRV record) timed out when DNS Security was enabled.
|
||||
|
||||
## PAN-265366
|
||||
|
||||
Fixed an issue where firewall experienced frequent reboots when ipv6 trafic is routed to explicit proxy, causing explicit proxy to crash.
|
||||
|
||||
## PAN-265160
|
||||
|
||||
Fixed an issue where the firewall created multiple connections to a syslog server and remained in the FINWAIT1 state, which caused logs to drop while being forwarded to the syslog server.
|
||||
|
||||
## PAN-264981
|
||||
|
||||
Fixed an issue on the Panorama web interface where it took longer than expected to edit Security policy rules.
|
||||
|
||||
## PAN-264883
|
||||
|
||||
```caveat
|
||||
PA-7080 appliances with LPCs only
|
||||
```
|
||||
|
||||
Fixed an issue where syslog forwarding over TCP stopped after upgrading.
|
||||
|
||||
## PAN-264678
|
||||
|
||||
Fixed an issue where Preview Changes did not display configuration changes in Commit and push > Push Scope.
|
||||
|
||||
## PAN-264662
|
||||
|
||||
Fixed an issue where HTTP POST requests were blocked for URLs that had the block-continue category configured.
|
||||
|
||||
## PAN-263843
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall received no-license packet buffers instead of memory based packet buffer numbers.
|
||||
|
||||
## PAN-263208
|
||||
|
||||
```caveat
|
||||
PA-5440 and PA-5445 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where interrupts were generated at a certain packet rate, and dataplane processes missed heartbeats, which caused the dataplane to go down.
|
||||
|
||||
## PAN-263012
|
||||
|
||||
Fixed an issue where commits failed from a Panorama appliance with a default master key to a firewall with a master key configured and a VM Information source configured.
|
||||
|
||||
## PAN-262973
|
||||
|
||||
Fixed an issue where changes made by a custom role Panorama administrator did not display in the push scope for other custom role administrators when a full commit was performed.
|
||||
|
||||
## PAN-262540
|
||||
|
||||
Fixed an issue where application traffic transactions that reused TCP ports did not work with decryption.
|
||||
|
||||
## PAN-262511
|
||||
|
||||
Fixed an issue on firewalls in HA configurations where OSPF neighbors were not established after an HA failover.
|
||||
|
||||
## PAN-260796
|
||||
|
||||
Fixed an issue where servers were not accessible through an active SSL GlobalProtect VPN tunnel until a new connection was established or the session was cleared on the firewall.
|
||||
|
||||
## PAN-260604
|
||||
|
||||
Fixed an issue where the firewall displayed inaccurate throughput utilization stats in NetFlow analyzer tools.
|
||||
|
||||
## PAN-260417
|
||||
|
||||
Fixed an issue on Panorama where UpdateLicDB was triggered every few minutes when firewalls with PAYG licenses were onboarded.
|
||||
|
||||
## PAN-257736
|
||||
|
||||
```caveat
|
||||
PA-5450 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where traffic to benign applications was impacted by holding TCP sequential segments for MLC inspection and not releasing the full chain after a benign verdict was received.
|
||||
|
||||
## PAN-256552
|
||||
|
||||
Fixed an issue where the logrcvr stopped responding, which caused the firewall to restart.
|
||||
|
||||
## PAN-255747
|
||||
|
||||
Fixed an issue on the firewall where CLI commands returned Server error: op command for client dagger timed out as client is not available.
|
||||
|
||||
## PAN-255653
|
||||
|
||||
Fixed an HA failover issue where, when Management Processing Card (MPC) or Base Card (BC) failures occurred, the HA link went down, which caused fpp-down events on one firewall.
|
||||
|
||||
## PAN-253485
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where dataplane packet capture filter configuration failed on the active firewall with the error op command for client dagger timed out as client is not available.
|
||||
|
||||
## PAN-252669
|
||||
|
||||
Fixed an issue where the ikemgr process stopped responding with a SIGSEGV error.
|
||||
|
||||
## PAN-251973
|
||||
|
||||
Fixed an issue where the firewall did not detect evasions due to TCP checksum offloading not being enabled.
|
||||
|
||||
## PAN-249581
|
||||
|
||||
Fixed an issue where stale BGP routes were advertised to peers even when they were not present in the local RIB table.
|
||||
|
||||
## PAN-249384
|
||||
|
||||
Fixed an issue on Panorama where configuration locks were observed during a partial rulebase commit.
|
||||
|
||||
## PAN-243920
|
||||
|
||||
Fixed an issue where the firewall name was truncated in the logs when the name used more than 31 characters.
|
||||
|
||||
## PAN-233197
|
||||
|
||||
Fixed an issue where the CLI command to set the FEC parameter for the front panel ports was not supported on platforms supporting 25G and 100G.
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.7-h1
|
||||
---
|
||||
|
||||
## PAN-279604
|
||||
|
||||
Fixed an issue where scheduled SaaS application usage reports were generated incorrectly, and the login page was displayed instead of the report content.
|
||||
@@ -0,0 +1,661 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.7-h2
|
||||
---
|
||||
|
||||
## PAN-290996
|
||||
|
||||
Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections Per Second) per vsys on firewalls after upgrading to PAN-OS 11.1.6-h3, even when active connections were present.
|
||||
|
||||
## PAN-289304
|
||||
|
||||
```caveat
|
||||
PA-7500 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where SNMP polling failed due to the snmpd process becoming unresponsive to incoming requests, which resulted in high CPU usage.
|
||||
|
||||
## PAN-289102
|
||||
|
||||
```caveat
|
||||
PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and CN-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed a race condition issue related to predict processing, which resulted in a dataplane restart and traffic loss.
|
||||
|
||||
## PAN-286897
|
||||
|
||||
Fixed an issue where the pan_task process stopped responding when the firewall attempted to forward files to the WildFire public cloud, which caused the dataplane to experience heartbeat failures.
|
||||
|
||||
## PAN-286306
|
||||
|
||||
Fixed an issue where, when getting transceiver information from ESCC for SFP 25G modules, the transceiver code was incorrectly updated with Unknown instead of 25GBase-SR.
|
||||
|
||||
## PAN-286255
|
||||
|
||||
Fixed an issue where, when the firewall received an unexpected termination request for SSL sessions, the dataplane experienced a slow buffer resource leak.
|
||||
|
||||
## PAN-285941
|
||||
|
||||
Fixed an issue where high memory consumption occurred on the logrcvr process.
|
||||
|
||||
## PAN-285651
|
||||
|
||||
```caveat
|
||||
Panorama appliances in active/passive HA configurations on Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue on Panorama that caused firewalls to disconnect unexpectedly.
|
||||
|
||||
## PAN-285597
|
||||
|
||||
Fixed an issue where a routed process memory leak occurred when advanced routing was enabled.
|
||||
|
||||
## PAN-285590
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1.
|
||||
|
||||
## PAN-284116
|
||||
|
||||
Fixed an issue where mTLS decryption bypass did not work when the decryption profile was configured with the maximum TLS version as TLS 1.3.
|
||||
|
||||
## PAN-284066
|
||||
|
||||
Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command.
|
||||
|
||||
## PAN-283789
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
|
||||
|
||||
## PAN-283467
|
||||
|
||||
```caveat
|
||||
PA-3400 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall unexpectedly rebooted and entered maintenance mode due to a ctd-agent out-of-memory (OOM) condition. This occurred during advanced services load testing and a high volume of IoT EAL log forwarding.
|
||||
|
||||
## PAN-282391
|
||||
|
||||
```caveat
|
||||
Panorama appliances and Log Collectors only
|
||||
```
|
||||
|
||||
Fixed an issue where a VLD memory leak caused increased memory use, which resulted in OOM errors.
|
||||
|
||||
## PAN-282236
|
||||
|
||||
Fixed an issue where large IPv6 packets were reassembled incorrectly on the firewall when the packets arrived fragmented over an IPv4 tunnel.
|
||||
|
||||
## PAN-282206
|
||||
|
||||
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
|
||||
|
||||
## PAN-282069
|
||||
|
||||
Fixed an issue on Panorama where Security policy rules were removed from device groups when you cloned or edited Security policy rules that used more than 63 characters.
|
||||
|
||||
## PAN-282022
|
||||
|
||||
Fixed the support limitation for the Panorama M-600 and M-700 appliances.
|
||||
|
||||
## PAN-281885
|
||||
|
||||
Fixed an issue where, when exporting and importing CSV files, the hash values of pre-shared key variables set at template and template stack levels changed inconsistently, which resulted in both variables displaying the same hash value.
|
||||
|
||||
## PAN-281649
|
||||
|
||||
Fixed an issue where the index size limit was incorrectly calculated and indices rolled over earlier than expected, which resulted in high memory and OOM errors.
|
||||
|
||||
## PAN-281269
|
||||
|
||||
```caveat
|
||||
$$PA-5420 firewalls$$
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall management server memory usage continuously increased.
|
||||
|
||||
## PAN-281264
|
||||
|
||||
Fixed an issue where the routed process memory usage continuously increased when Advanced Routing was enabled.
|
||||
|
||||
## PAN-280942
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding.
|
||||
|
||||
## PAN-280698
|
||||
|
||||
Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.
|
||||
|
||||
## PAN-280505
|
||||
|
||||
Fixed an issue where the web interface did not display a message to commit prior changes before attempting a partial configuration load.
|
||||
|
||||
## PAN-280477
|
||||
|
||||
Fixed an issue on the web interface were you were unable to scroll up or down to view source zones in a NAT policy rule.
|
||||
|
||||
## PAN-280471
|
||||
|
||||
Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected.
|
||||
|
||||
## PAN-280243
|
||||
|
||||
Fixed an issue where the firewall lost the pre-shared key configuration assigned from a PSK variable when an unrelated device group configuration was loaded.
|
||||
|
||||
## PAN-279983
|
||||
|
||||
```caveat
|
||||
PA-1400 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue on the web interface where Enable Bonjour Reflector was not displayed (Network > Interfaces > Ethernet Interface).
|
||||
|
||||
## PAN-279746
|
||||
|
||||
Fixed an issue where SMTP packets were not sent out when the Client Hello arrived at the firewall in multiple out-of-order segments and the traffic was not subject to SSL decryption.
|
||||
|
||||
## PAN-279691
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall didn't synchronize IPSec SAs (security associations) to the passive firewall if the tunnel was not initially established by the active firewall.
|
||||
|
||||
## PAN-279621
|
||||
|
||||
Fixed an issue where processes stopped responding when HTTPS Forward traffic was run.
|
||||
|
||||
## PAN-279336
|
||||
|
||||
Fixed an issue where the CLI did not display a message to commit prior changes before loading a partial configuration.
|
||||
|
||||
## PAN-279191
|
||||
|
||||
Fixed an issue where a GlobalProtect gateway stopped responding when handling HTTP/1.1 traffic with web inspection enabled.
|
||||
|
||||
## PAN-279176
|
||||
|
||||
Fixed an issue where the configuration audit displayed inaccurate information after partially loading the configuration via the CLI, which caused the audit to flag the configuration as deleted or changed.
|
||||
|
||||
## PAN-279065
|
||||
|
||||
Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.
|
||||
|
||||
## PAN-278296
|
||||
|
||||
Fixed an issue where the system MAC address of the aggregate interface was the same on the active firewall and the passive firewall after an upgrade.
|
||||
|
||||
## PAN-278088
|
||||
|
||||
Fixed an issue where the show system resources follow CLI command was not available.
|
||||
|
||||
## PAN-277762
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
|
||||
|
||||
## PAN-277631
|
||||
|
||||
Fixed an issue where the logrcvr process discarded logs due to a full queue.
|
||||
|
||||
## PAN-277417
|
||||
|
||||
Fixed an memory leak issue related to TLS inbound decryption.
|
||||
|
||||
## PAN-276062
|
||||
|
||||
Fixed an issue where importing a firewall with a large number of address objects into Panorama did not work and remained at 99% completion.
|
||||
|
||||
## PAN-275905
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected and Elasticsearch CPU usage was high.
|
||||
|
||||
## PAN-275718
|
||||
|
||||
Fixed an issue where Panorama stopped forwarding logs to a Syslog server after upgrading to PAN-OS 11.1.5-h1.
|
||||
|
||||
## PAN-275713
|
||||
|
||||
Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the Active Directory returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
|
||||
|
||||
## PAN-275077
|
||||
|
||||
Fixed an issue where DNS Security intermittently logs malicious domain URLs as Alert instead of taking a Sinkhole action, even when configured to Sinkhole malicious DNS domains.
|
||||
|
||||
## PAN-275032
|
||||
|
||||
```caveat
|
||||
M-600 appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where the Elasticsearch cluster certificate (CC) status displayed with a past expiration date, which caused all shards to be unassigned.
|
||||
|
||||
## PAN-274791
|
||||
|
||||
Fixed an issue where the firewall might reboot when traffic matches with certain Advanced features (such as Advanced Threat Prevention and Advanced URL Filtering with properly configured URL Filtering/Anti-Spyware/Vulnerability security profiles) and Shared Pool Type 32 becomes depleted.
|
||||
|
||||
## PAN-274750
|
||||
|
||||
Fixed an issue where the detailed log view in Panorama did not display all packet details for traffic logs received from the cloud.
|
||||
|
||||
## PAN-274671
|
||||
|
||||
Fixed an issue where empty traffic logdb folders were generated for each day even when traffic logs were not received by the logrcvr process.
|
||||
|
||||
## PAN-274592
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not fail over when the active firewall experienced data plane issues.
|
||||
|
||||
## PAN-274570
|
||||
|
||||
Fixed an issue where the devsrvr process restarted after a failed commit due to an invalid memory access.
|
||||
|
||||
## PAN-274314
|
||||
|
||||
```caveat
|
||||
PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where, when the pan_task process restarted, control plane packets were dropped, which could impact LACP and pings to host interfaces.
|
||||
|
||||
## PAN-273949
|
||||
|
||||
Fixed an issue where the firewall generated the following error message in the snmpd logs: pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key X2F1dGhfa2V5 import from cryptod failed.
|
||||
|
||||
## PAN-273694
|
||||
|
||||
Fixed an issue where the firewall rebooted due to an out-of-bounds memory access that occurred as a result of the SIP content length value being split across packets.
|
||||
|
||||
## PAN-273453
|
||||
|
||||
Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.
|
||||
|
||||
## PAN-273422
|
||||
|
||||
Fixed an issue where traffic failed when Inline cloud analysis (Advanced Threat Prevention) was enabled in the Anti-Spyware profile with the action set to anything other than allow or alert and the maximum latency condition was reached.
|
||||
|
||||
## PAN-273308
|
||||
|
||||
A fix was made to address CVE-2025-0130.
|
||||
|
||||
## PAN-273141
|
||||
|
||||
Fixed an issue where GlobalProtect clients experienced slow file transfer download throughput when passing through an IPSec tunnel.
|
||||
|
||||
## PAN-273129
|
||||
|
||||
Fixed an issue on the web interface where the negate option was visible when you clicked on the rule name, but not when you viewed the target options from the rulebase attribute.
|
||||
|
||||
## PAN-273026
|
||||
|
||||
Fixed an issue where traffic logs did not display correctly when filters were applied.
|
||||
|
||||
## PAN-273021
|
||||
|
||||
Fixed an issue where 25G port links did not come up due to a change in the handling of 25G DAC modules.
|
||||
|
||||
## PAN-273019
|
||||
|
||||
Fixed an intermittent issue where SSL decryption failed.
|
||||
|
||||
## PAN-272812
|
||||
|
||||
Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets.
|
||||
|
||||
## PAN-272746
|
||||
|
||||
```caveat
|
||||
PA-440 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall entered an unstable state after committing changes or onboarding to Panorama.
|
||||
|
||||
## PAN-272605
|
||||
|
||||
Fixed an issue where the firewall did not display VPC endpoints when there was a large amount of VPC endpoints to interface mappings.
|
||||
|
||||
## PAN-272171
|
||||
|
||||
Fixed an issue where the firewall dropped the AAAA DNS server response and caused delays in traffic from Ubuntu or Linux clients when DNS Security was enabled.
|
||||
|
||||
## PAN-272085
|
||||
|
||||
Fixed an issue where the firewall unexpectedly stopped responding and rebooted when DoH was enabled for DNS Security and multiple DoH transactions were sent in a single HTTP/1 connection.
|
||||
|
||||
## PAN-271915
|
||||
|
||||
Fixed an issue where the push scope did not populate when attempting to push a policy to a device group.
|
||||
|
||||
## PAN-271723
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the all_task process stopped responding, which caused the passive firewall to repeatedly reboot.
|
||||
|
||||
## PAN-271701
|
||||
|
||||
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and Enhanced Application Log stopped working due to incorrect memory usage accounting, which caused memory usage to remain at 99% after an extended period of time.
|
||||
|
||||
## PAN-271700
|
||||
|
||||
Fixed an issue where User-ID connections were lost after an HA failover.
|
||||
|
||||
## PAN-271560
|
||||
|
||||
Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable.
|
||||
|
||||
## PAN-271498
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls in FIPS mode only
|
||||
```
|
||||
|
||||
Fixed an issue where decrypted traffic repeatedly failed and frequent reboots were required.
|
||||
|
||||
## PAN-271351
|
||||
|
||||
A fix was made to address CVE-2025-0116.
|
||||
|
||||
## PAN-271273
|
||||
|
||||
Fixed an issue where the all_task process stopped responding with a SIGABRT.
|
||||
|
||||
## PAN-271151
|
||||
|
||||
Fixed an issue where the GlobalProtect client did not automatically initiate a Kerberos SSO connection after logging in to Windows.
|
||||
|
||||
## PAN-270849
|
||||
|
||||
Fixed a memory leak issue related to the configd process that occurred when running consecutive commits for multiple days.
|
||||
|
||||
## PAN-270744
|
||||
|
||||
Fixed an issue where API calls to Panorama failed with the error Server error : Timed out while getting config lock. Please try again.
|
||||
|
||||
## PAN-270379
|
||||
|
||||
Fixed an issue where socket files created in the /tmp directory were not cleared.
|
||||
|
||||
## PAN-270248
|
||||
|
||||
Fixed an issue where the firewall failed to forward logs to a SNMP trap server if the SNMP manager IP address was unable to be resolved.
|
||||
|
||||
## PAN-270193
|
||||
|
||||
Fixed an issue where the Panorama management server changed its certificate authority (CA) unexpectedly, which caused managed firewalls to disconnect.
|
||||
|
||||
## PAN-269737
|
||||
|
||||
Fixed an issue where the following critical error displayed repeatedly: /mnt/cdrom is mounted as Read-Only.
|
||||
|
||||
## PAN-269291
|
||||
|
||||
Fixed an issue where the scheduled report generation script did not return debug information.
|
||||
|
||||
## PAN-269193
|
||||
|
||||
Fixed an issue where the firewall redirected the user to the first application instead of the portal page with a list of applications when multiple applications were configured for GlobalProtect clientless VPN along with any user match.
|
||||
|
||||
## PAN-269139
|
||||
|
||||
```caveat
|
||||
Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only
|
||||
```
|
||||
|
||||
Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.
|
||||
|
||||
## PAN-269091
|
||||
|
||||
Fixed an issue where the varrcvr process stopped responding.
|
||||
|
||||
## PAN-269052
|
||||
|
||||
Fixed an issue where traffic was blocked by a URL filtering profile even though the Security policy rule did not have a URL filtering profile configured.
|
||||
|
||||
## PAN-269027
|
||||
|
||||
Fixed an issue related to external dynamic lists that caused commit times on the firewall to be higher than expected.
|
||||
|
||||
## PAN-268909
|
||||
|
||||
Fixed an issue where IP address tags were removed from firewalls after a management server or useridd process restart. This occurred when a Panorama serial-number based configuration was used for User-ID redistribution.
|
||||
|
||||
## PAN-268800
|
||||
|
||||
Fixed an issue where a large number of logs caused the logrcvr process to stop responding.
|
||||
|
||||
## PAN-268705
|
||||
|
||||
Fixed an intermittent issue where the firewall failed to process FTP traffic after upgrading to PAN-OS 10.1.14.
|
||||
|
||||
## PAN-268629
|
||||
|
||||
Fixed an issue where traffic did not match the correct security policy when using an application-filter that referenced a cloud application. This occurred when a high number of cloud applications were attached with a custom tag.
|
||||
|
||||
## PAN-268614
|
||||
|
||||
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.
|
||||
|
||||
## PAN-268279
|
||||
|
||||
Fixed an issue where autocommits failed if the management IPv6 gateway was the same as the dataplane interface IP address.
|
||||
|
||||
## PAN-268127
|
||||
|
||||
Fixed an issue where tagging devices in Panorama did not work as expected.
|
||||
|
||||
## PAN-268118
|
||||
|
||||
Fixed an issue on firewalls in active/passive HA configurations where, after a failover, irrelevant routing FIB entries were seen in the routing table on the newly active firewall.
|
||||
|
||||
## PAN-267995
|
||||
|
||||
Fixed an issue where after migrating to a new platform, DLP verdicts were not displayed in the Cloud Manager or logs.
|
||||
|
||||
## PAN-267671
|
||||
|
||||
Fixed an issue where the firewall rebooted unexpectedly due to the all_task process restarting with an OOM condition due to a memory leak on the reportd process.
|
||||
|
||||
## PAN-267518
|
||||
|
||||
Fixed an issue where WildFire submission logs incorrectly reported allowed malicious samples even when they were blocked by threat prevention profiles.
|
||||
|
||||
## PAN-267444
|
||||
|
||||
Fixed an issue where large file downloads or uploads failed or remained in an incomplete state when using DLP HTTP2 mirror mode.
|
||||
|
||||
## PAN-267204
|
||||
|
||||
Fixed an issue where Panorama port 9300 did not adhere to restricted TLS versions and ciphers.
|
||||
|
||||
## PAN-266695
|
||||
|
||||
Fixed an issue on Panorama where a cyclic nested address group configuration caused the configd process to stop responding after a commit.
|
||||
|
||||
## PAN-266559
|
||||
|
||||
Fixed an issue where partial commits failed when objects that were referenced in a high number of Security policy rules were renamed.
|
||||
|
||||
## PAN-266354
|
||||
|
||||
Fixed an issue where Hybrid-SWG explicit proxy connections failed when the number of destination domains exceeded 1024.
|
||||
|
||||
## PAN-266116
|
||||
|
||||
Fixed an issue where URLs did not work due to certificate revocation list (CRL) requests failing.
|
||||
|
||||
## PAN-265745
|
||||
|
||||
Fixed an issue where the firewall displayed incorrect MAC receive error counters for VMWare devices hosted in ESXi.
|
||||
|
||||
## PAN-264477
|
||||
|
||||
Fixed an issue where the firewall did not start Elasticsearch after a commit if Elasticsearch was not previously enabled and started.
|
||||
|
||||
## PAN-264423
|
||||
|
||||
Fixed an issue where the firewall sent a 503 response when a client connected to a web server when the firewall was configured as a web proxy and authentication bypass for Kerberos was enabled.
|
||||
|
||||
## PAN-263291
|
||||
|
||||
Fixed an issue where Microsoft Outlook did not work as expected when the GlobalProtect clientless VPN was configured.
|
||||
|
||||
## PAN-262063
|
||||
|
||||
Fixed an issue where the firewall did not display the converted configurations before a commit and reboot, and the commit failed when attempting to migrate from MS to FRR mode.
|
||||
|
||||
## PAN-261998
|
||||
|
||||
Fixed an issue where the firewall configuration process restarted during an External Dynamic List refresh or a commit and push operation.
|
||||
|
||||
## PAN-261825
|
||||
|
||||
Fixed an issue where traffic was dropped when Data Loss Prevention or Advanced URL Filtering were enabled. This occurred when the payload size was greater than 3.5 KB.
|
||||
|
||||
## PAN-261739
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environments only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall displayed 0 for the physical port counters read from MAC.
|
||||
|
||||
## PAN-261597
|
||||
|
||||
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to become unavailable.
|
||||
|
||||
## PAN-261429
|
||||
|
||||
Fixed an issue where the show auth radius-require-msg-authentic command CLI displayed no output.
|
||||
|
||||
## PAN-261312
|
||||
|
||||
Fixed an issue where a commit for a policy and configuration dump overlapped, which resulted in a null pointer exception.
|
||||
|
||||
## PAN-260300
|
||||
|
||||
```caveat
|
||||
PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue related to the all_pktproc process where DPC slot 3 stopped responding.
|
||||
|
||||
## PAN-260149
|
||||
|
||||
Fixed an issue where the management plane DNS cache size was lower than expected.
|
||||
|
||||
## PAN-260059
|
||||
|
||||
Fixed an issue where Device Telemetry Regions did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off.
|
||||
|
||||
## PAN-260015
|
||||
|
||||
Fixed an issue on the firewall where the dataplane restarted due to insufficient allocation of memory buffers.
|
||||
|
||||
## PAN-259767
|
||||
|
||||
Fixed an issue where GlobalProtect users were unable to connect when the option Block sessions if the certificate was not issued to the authenticating device was enabled in the certificate profile.
|
||||
|
||||
## PAN-259076
|
||||
|
||||
Fixed an issue where the firewall displayed an OCSP/CRL check failure when accessing websites.
|
||||
|
||||
## PAN-258743
|
||||
|
||||
Fixed an issue where, when you attempted to select a redistribution profile when creating a BGP Redistribute policy rule, the firewall displayed an empty dropdown.
|
||||
|
||||
## PAN-258680
|
||||
|
||||
Fixed an issue on Panorama where, when you removed Security profile groups from a Security policy rule via the CLI and committed the change, the Security policy rule was deleted.
|
||||
|
||||
## PAN-258570
|
||||
|
||||
Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr process progressively using more memory when WildFire file forwarding is handling PE files.
|
||||
|
||||
## PAN-257183
|
||||
|
||||
Fixed an issue where the firewall dropped DNS traffic when using DNS Security.
|
||||
|
||||
## PAN-256904
|
||||
|
||||
Fixed an issue where the firewall inconsistently blocked URLs due to intermittent URL category misidentification.
|
||||
|
||||
## PAN-256867
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding while processing session logs for forwarding to the LFC.
|
||||
|
||||
## PAN-255914
|
||||
|
||||
(VM-Series firewalls on Amazon Web Services (AWS) environments only) Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.
|
||||
|
||||
## PAN-255619
|
||||
|
||||
Fixed an intermittent issue where file downloads from websites failed when decrypting HTTP/2 traffic.
|
||||
|
||||
## PAN-254293
|
||||
|
||||
Fixed an issue where an explicit proxy caused intermittent SSL handshake failures to SAP applications accessing public URLs.
|
||||
|
||||
## PAN-253778
|
||||
|
||||
```caveat
|
||||
PA-7500 Series firewalls in a cluster configuration only
|
||||
```
|
||||
|
||||
Fixed an issue where users were able to enable or disable certain configurations.
|
||||
|
||||
## PAN-253127
|
||||
|
||||
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the hardware pool DFLT became highly utilized, and the packet buffer gradually increased.
|
||||
|
||||
## PAN-251724
|
||||
|
||||
Fixed an issue where users matched incorrect Security policy rules with a HIP profile.
|
||||
|
||||
## PAN-248157
|
||||
|
||||
Fixed an issue where the firewall showed three different sets of name validation rules when generating, importing, or editing a certificate.
|
||||
|
||||
## PAN-245064
|
||||
|
||||
```caveat
|
||||
Multi-vsys firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
|
||||
|
||||
## PAN-235733
|
||||
|
||||
Fixed an issue where the displayed NTP information was incorrect if the DNS servers timed out.
|
||||
|
||||
## PAN-234993
|
||||
|
||||
Fixed an issue where CPU base gateway auto-scaling failed, which caused performance issues.
|
||||
|
||||
## PAN-233868
|
||||
|
||||
Fixed an issue where the firewall took an incorrect action for overlapping custom and edl-url-categories in a policy rule.
|
||||
|
||||
## PAN-216054
|
||||
|
||||
Fixed an issue that caused the firewall fan speed to increase while it was idle.
|
||||
@@ -0,0 +1,33 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.7-h4
|
||||
---
|
||||
|
||||
## PAN-300227
|
||||
|
||||
Fixed an issue where the firewall dropped packets due to the incoming flow being hashed to a flow bucket that was full.
|
||||
|
||||
## PAN-290453
|
||||
|
||||
Fixed an issue where PA-7500 firewalls experienced silent traffic drops. During migration from PA-7050 to PA-7500 firewalls connected in series, intermittent connection losses occurred for some applications. Traffic leaving the PA-7050 was not received or processed by the PA-7500, even with direct connections and replaced cables/SFPs. Global counters did not indicate any drops on the PA-7500.
|
||||
|
||||
## PAN-289304
|
||||
|
||||
```caveat
|
||||
PA-7500 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where SNMP polling failed due to the snmpd process becoming unresponsive to incoming requests, which resulted in high CPU usage.
|
||||
|
||||
## PAN-279604
|
||||
|
||||
Fixed an issue where scheduled SaaS application usage reports were generated incorrectly, and the login page was displayed instead of the report content.
|
||||
|
||||
## PAN-253778
|
||||
|
||||
```caveat
|
||||
PA-7500 Series firewalls in a cluster configuration only
|
||||
```
|
||||
|
||||
Fixed an issue where users were able to enable or disable certain configurations.
|
||||
@@ -0,0 +1,125 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.7
|
||||
---
|
||||
|
||||
## PAN-273245
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where upgrading an HA firewall pair from PAN-OS 10.2.11-h1 to PAN-OS 11.1.5 caused the firewalls to enter a nonfunctional loop due to repeated HA path monitoring failures.
|
||||
|
||||
## PAN-272849
|
||||
|
||||
Fixed an issue where log forwarding to a UDP syslog server stopped when an unreachable TCP syslog server was configured and applied.
|
||||
|
||||
## PAN-272538
|
||||
|
||||
Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and share-unused-objects-with-devices was set to off.
|
||||
|
||||
## PAN-272006
|
||||
|
||||
Fixed an issue where the firewall did not trigger a kernel core dump as a large core when the CPLD (Complex Programmable Logic Device) sent a Non-Maskable Interrupt (NMI) to the CPU.
|
||||
|
||||
## PAN-271926
|
||||
|
||||
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC error when the firewall was configured to decrypt and inspect TLS traffic.
|
||||
|
||||
## PAN-271912
|
||||
|
||||
Fixed an issue on Panorama where the configd process stopped responding when filtering in the configuration audit window after upgrading to PAN-OS 11.1.3.
|
||||
|
||||
## PAN-271828
|
||||
|
||||
Fixed an issue where, after an accumulation proxy changed to no-decrypt or no proxy, only the Client Hello was sent to Content Threat Detection.
|
||||
|
||||
## PAN-271314
|
||||
|
||||
Fixed an issue where pushing changes to a prefix list used for BGP from Panorama affected OSPF routes.
|
||||
|
||||
## PAN-270607
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where OSPF failed to establish after a failover from the active firewall to the passive firewall.
|
||||
|
||||
## PAN-270471
|
||||
|
||||
```caveat
|
||||
Firewalls in active/active configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not detect configuration changes when only the interface of an IKE gateway was changed, which caused IPSec tunnels to not come up after migrating the IKE gateway IP address from a subinterface to a physical interface.
|
||||
|
||||
## PAN-269956
|
||||
|
||||
Fixed an issue where the all_pktproc process stopped responding, which caused internal path monitor failures.
|
||||
|
||||
## PAN-269731
|
||||
|
||||
Fixed an issue where Panorama did not display logs from firewalls after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) getting restarted continuously.
|
||||
|
||||
## PAN-269337
|
||||
|
||||
Fixed an issue where the cluster compatibility timer was limited to 300 to 3600 seconds.
|
||||
|
||||
## PAN-268465
|
||||
|
||||
Fixed an issue with firewalls in active/passive HA configurations where the total user count in the registered users was different between the active and passive firewall.
|
||||
|
||||
## PAN-267781
|
||||
|
||||
Fixed an issue where Panorama did not display the Source Dynamic Address Group.
|
||||
|
||||
## PAN-267097
|
||||
|
||||
Fixed an issue where the replay database size increased significantly due to local and special configurations not being purged after commits.
|
||||
|
||||
## PAN-265219
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where GRE traffic did not work properly.
|
||||
|
||||
## PAN-265179
|
||||
|
||||
Fixed an issue where a kernel race condition caused the firewall to reboot with a kernel panic.
|
||||
|
||||
## PAN-262946
|
||||
|
||||
Fixed an issue on the firewall where logging in via the CLI or web interface did not work due to increased memory usage.
|
||||
|
||||
## PAN-262043
|
||||
|
||||
Fixed an issue where Voice over WiFi (VoWiFi) stopped working after switching from a PA-5200 Series firewall to a PA-7500 Series firewall in NGFW clustering mode with NATT IPSec Passthrough and NAT policy enabled. To use this fix, enter the CLI command show tunnel-acceleration, disable tunnel acceleration, and reboot the PA-7500 Series firewall.
|
||||
|
||||
## PAN-260235
|
||||
|
||||
Fixed an issue where the firewall sent Threat logs and URL logs to an external syslog server without Security profile settings when Enhanced Application Logging was enabled.
|
||||
|
||||
## PAN-259078
|
||||
|
||||
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
|
||||
|
||||
## PAN-258149
|
||||
|
||||
Fixed an issue where the firewall dropped the SYN-ACK when using the TCP Fast Open option.
|
||||
|
||||
## PAN-246699
|
||||
|
||||
Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy rules stopped incrementing.
|
||||
|
||||
## PAN-240529
|
||||
|
||||
Fixed an issue where cloud application information was not displayed in the traffic log in NGFW cluster nodes.
|
||||
|
||||
## PAN-212889
|
||||
|
||||
Fixed an issue on Panorama where different threat names were used when querying a threat under Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in Threat Monitor and filtering it in the global filters.
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,285 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 11.1.9
|
||||
---
|
||||
|
||||
## PAN-290996
|
||||
|
||||
When performing an SNMP walk, the Connections Per Second (CPS) counters incorrectly return a value of 0 for each virtual system (VSYS), despite the firewall actively processing connections.
|
||||
|
||||
## PAN-286255
|
||||
|
||||
Fixed an issue where, when the firewall received an unexpected termination request for SSL sessions, the dataplane experienced a slow buffer resource leak.
|
||||
|
||||
## PAN-285941
|
||||
|
||||
Fixed an issue where high memory consumption occurred on the logrcvr process.
|
||||
|
||||
## PAN-284073
|
||||
|
||||
Fixed an issue on the firewall that caused commits to fail and the web interface to become inaccessible.
|
||||
|
||||
## PAN-283954
|
||||
|
||||
Fixed an issue where the configd process stopped responding due to a circular reference between address groups.
|
||||
|
||||
## PAN-283168
|
||||
|
||||
Fixed an issue related to syslog forwarding that caused the logrcvr process stopped responding.
|
||||
|
||||
## PAN-282697
|
||||
|
||||
Fixed an issue where traffic was delayed significantly when it used No Authentication Explicit Proxy and matched a decryption policy rule.
|
||||
|
||||
## PAN-282454
|
||||
|
||||
Fixed an issue where, when you added the Virtual System Name column under Unified Logs, the column did not remain visible in the table if you closed and re-opened the tab.
|
||||
|
||||
## PAN-282391
|
||||
|
||||
Fixed an issue on Panorama where a memory leak occurred after cloning a template, resulting in an increase in memory use, which caused OOM errors.
|
||||
|
||||
## PAN-282359
|
||||
|
||||
Fixed an issue where the Panorama web interface was slower than expected.
|
||||
|
||||
## PAN-282206
|
||||
|
||||
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
|
||||
|
||||
## PAN-282069
|
||||
|
||||
Fixed an issue on Panorama where Security policy rules were removed from device groups when you cloned or edited Security policy rules that used more than 63 characters.
|
||||
|
||||
## PAN-281885
|
||||
|
||||
Fixed an issue where, when exporting and importing CSV files, the hash values of pre-shared key variables set at template and template stack levels changed inconsistently, which resulted in both variables displaying the same hash value.
|
||||
|
||||
## PAN-281882
|
||||
|
||||
Fixed an issue where OSPF was redistributing connected routes beyond the intended loopback IP.
|
||||
|
||||
## PAN-281649
|
||||
|
||||
Fixed an issue where the index size limit was incorrectly calculated and indices rolled over earlier than expected, which resulted in high memory and OOM errors.
|
||||
|
||||
## PAN-281269
|
||||
|
||||
```caveat
|
||||
PA-5220, PA-5250, and PA-5420 firewalls
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall management server memory usage continuously increased.
|
||||
|
||||
## PAN-280942
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding.
|
||||
|
||||
## PAN-280700
|
||||
|
||||
Fixed an Issue where commits failed with the error invalid IPv6 x:x - must be global/link-local unicast when the management IPv6 address had a specific value.
|
||||
|
||||
## PAN-280477
|
||||
|
||||
Fixed an issue on the web interface were you were unable to scroll up or down to view source zones in a NAT policy rule.
|
||||
|
||||
## PAN-279691
|
||||
|
||||
```caveat
|
||||
Firewalls in active/passive HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall didn't synchronize IPSec SAs (security associations) to the passive firewall if the tunnel was not initially established by the active firewall.
|
||||
|
||||
## PAN-279647
|
||||
|
||||
Fixed an issue where threat names were displayed differently on the web interface and the exported CSV file.
|
||||
|
||||
## PAN-279621
|
||||
|
||||
Fixed an issue where processes stopped responding when HTTPS Forward traffic was run.
|
||||
|
||||
## PAN-279400
|
||||
|
||||
Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
|
||||
|
||||
## PAN-279209
|
||||
|
||||
Fixed an issue where changes made to the management interface permitted IP address list in a global template were not pushed to the template stack or firewalls.
|
||||
|
||||
## PAN-279195
|
||||
|
||||
Fixed an issue on Panorama where Device Health displayed the device memory as 0%.
|
||||
|
||||
## PAN-279065
|
||||
|
||||
Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.
|
||||
|
||||
## PAN-278190
|
||||
|
||||
Fixed an issue on Panorama where a scheduled report with SLS data had an invalid translated-query.
|
||||
|
||||
## PAN-277755
|
||||
|
||||
Fixed an issue that caused the request system private-data-reset CLI command to fail.
|
||||
|
||||
## PAN-277417
|
||||
|
||||
Fixed an memory leak issue related to TLS inbound decryption.
|
||||
|
||||
## PAN-277018
|
||||
|
||||
Fixed an issue where FTP data connections did not work for EPRT with Source IP + Port translation enabled on the firewall.
|
||||
|
||||
## PAN-276862
|
||||
|
||||
Fixed an issue on Panorama where the logd process stopped responding unexpectedly.
|
||||
|
||||
## PAN-276616
|
||||
|
||||
Fixed an issue on the firewall where half-duplex settings on Ethernet was not visible.
|
||||
|
||||
## PAN-276412
|
||||
|
||||
Fixed an issue where you were unable to download XML files from Panorama > Summary > Backups.
|
||||
|
||||
## PAN-274907
|
||||
|
||||
Fixed an issue on Panorama where Config Audit Commit Date displayed the timestamp of the configuration edit instead of the commit time.
|
||||
|
||||
## PAN-274750
|
||||
|
||||
Fixed an issue where the detailed log view in Panorama did not display all packet details for traffic logs received from the cloud.
|
||||
|
||||
## PAN-274726
|
||||
|
||||
Fixed an issue where Wildfire signature generation was enabled on all nodes in a cluster instead of only the active node.
|
||||
|
||||
## PAN-274569
|
||||
|
||||
Fixed an issue where the QSPF transceiver interface displayed an incorrect range figure on the temperature alarm.
|
||||
|
||||
## PAN-274314
|
||||
|
||||
```caveat
|
||||
PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where, when the pan_task process restarted, control plane packets were dropped, which could impact LACP and pings to host interfaces.
|
||||
|
||||
## PAN-273870
|
||||
|
||||
Fixed an issue on the firewall where you were unable to local changes that were made via the web interface.
|
||||
|
||||
## PAN-273422
|
||||
|
||||
Fixed an issue where traffic failed when Inline cloud analysis (Advanced Threat Prevention) was enabled in the Anti-Spyware profile with the action set to anything other than allow or alert and the maximum latency condition was reached.
|
||||
|
||||
## PAN-273141
|
||||
|
||||
Fixed an issue where GlobalProtect clients experienced slow file transfer download throughput when passing through an IPSec tunnel.
|
||||
|
||||
## PAN-271701
|
||||
|
||||
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and Enhanced Application Log stopped working due to incorrect memory usage accounting, which caused memory usage to remain at 99% after an extended period of time.
|
||||
|
||||
## PAN-271498
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls in FIPS mode only
|
||||
```
|
||||
|
||||
Fixed an issue where decrypted traffic repeatedly failed and frequent reboots were required.
|
||||
|
||||
## PAN-271273
|
||||
|
||||
Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
|
||||
|
||||
## PAN-271175
|
||||
|
||||
Fixed an issue where the all_task process stopped responding with a SIGABRT.
|
||||
|
||||
## PAN-271151
|
||||
|
||||
Fixed an issue where the GlobalProtect client did not automatically initiate a Kerberos SSO connection after logging in to Windows.
|
||||
|
||||
## PAN-270192
|
||||
|
||||
Fixed an issue where Panorama did not display the management IP address of devices onboard via ZTP.
|
||||
|
||||
## PAN-269404
|
||||
|
||||
Fixed an issue where the firewall did not reset the maximum latency timer for hold mode.
|
||||
|
||||
## PAN-268705
|
||||
|
||||
Fixed an intermittent issue where the firewall failed to process FTP traffic after upgrading to PAN-OS 10.1.14.
|
||||
|
||||
## PAN-268614
|
||||
|
||||
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.
|
||||
|
||||
## PAN-267936
|
||||
|
||||
Fixed an issue where commits failed with a validation error when you changed the encryption level and re-encryption option on a Panorama managed firewall.
|
||||
|
||||
## PAN-267444
|
||||
|
||||
Fixed an issue where large file downloads or uploads failed or remained in an incomplete state when using DLP HTTP2 mirror mode.
|
||||
|
||||
## PAN-266589
|
||||
|
||||
Fixed an issue where the firewall was unable to generate a tech support file when management server debug was disabled.
|
||||
|
||||
## PAN-263465
|
||||
|
||||
Fixed an issue where the logrcvr process stopped responding due to a memory leak and buffer overrun.
|
||||
|
||||
## PAN-263270
|
||||
|
||||
Fixed an issue where, after a commit was performed from Strata Cloud Manager, the SD-WAN configuration containing BGP routes did not display on the hub firewall.
|
||||
|
||||
## PAN-263052
|
||||
|
||||
Fixed an issue where the request logdb migrate-to-panorama start end-time <start-time> <type> CLI command did not work as expected, and you were unable to resend logs from a firewall to Panorama or a log collector.
|
||||
|
||||
## PAN-260015
|
||||
|
||||
Fixed an issue on the firewall where the dataplane restarted due to insufficient allocation of memory buffers.
|
||||
|
||||
## PAN-259610
|
||||
|
||||
Fixed an issue where Wildfire content installation failed for WF-500B clusters when deployed from Panorama using the deployment schedule.
|
||||
|
||||
## PAN-255914
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Amazon Web Services (AWS) environments only
|
||||
```
|
||||
|
||||
Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.
|
||||
|
||||
## PAN-254524
|
||||
|
||||
Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed.
|
||||
|
||||
## PAN-253127
|
||||
|
||||
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the hardware pool DFLT became highly utilized, and the packet buffer gradually increased.
|
||||
|
||||
## PAN-249574
|
||||
|
||||
Fixed an issue where selective pushes failed due to a missing log collector reference.
|
||||
|
||||
## PAN-245064
|
||||
|
||||
```caveat
|
||||
Multi-vsys firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
|
||||
|
||||
## PAN-238208
|
||||
|
||||
Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error Session is invalid if the session is not available for the cookie.
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,50 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>Palo Alto Issues Tracker</title>
|
||||
<link rel="stylesheet" href="styles.css">
|
||||
</head>
|
||||
<body>
|
||||
<header>
|
||||
<h1>Palo Alto Issues Tracker</h1>
|
||||
</header>
|
||||
<main class="container">
|
||||
<aside class="sidebar">
|
||||
<h2>Search</h2>
|
||||
<input
|
||||
type="text"
|
||||
id="issue-search"
|
||||
class="issue-search"
|
||||
placeholder="Filter displayed issues..."
|
||||
autocomplete="off"
|
||||
>
|
||||
<h2>Type</h2>
|
||||
<div id="issue-type-filters" class="issue-filters">
|
||||
<label>
|
||||
<input type="checkbox" id="filter-addressed" checked>
|
||||
Addressed
|
||||
</label>
|
||||
<label>
|
||||
<input type="checkbox" id="filter-known" checked>
|
||||
Known
|
||||
</label>
|
||||
</div>
|
||||
<h2>Products</h2>
|
||||
<div id="product-tree"></div>
|
||||
</aside>
|
||||
<section id="issues" class="content">
|
||||
<section id="addressed-section">
|
||||
<h2>Addressed Issues <span id="addressed-count" class="issue-count">(0)</span></h2>
|
||||
<div id="addressed-issues"></div>
|
||||
</section>
|
||||
<section id="known-section">
|
||||
<h2>Known Issues <span id="known-count" class="issue-count">(0)</span></h2>
|
||||
<div id="known-issues"></div>
|
||||
</section>
|
||||
</section>
|
||||
</main>
|
||||
<script type="module" src="script.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,649 @@
|
||||
export function clearIssues() {
|
||||
document.getElementById('addressed-issues').innerHTML = '';
|
||||
document.getElementById('known-issues').innerHTML = '';
|
||||
}
|
||||
|
||||
let socialRefsByIssueId = new Map();
|
||||
const socialRefsReady = loadSocialRefs();
|
||||
const issueFileDataCache = new Map();
|
||||
const issueFilePromiseCache = new Map();
|
||||
|
||||
function loadSocialRefs() {
|
||||
return fetch('social_refs.json')
|
||||
.then(response => {
|
||||
if (!response.ok) {
|
||||
throw new Error(`Failed to load social_refs.json (${response.status})`);
|
||||
}
|
||||
return response.json();
|
||||
})
|
||||
.then(data => {
|
||||
socialRefsByIssueId = normalizeSocialRefs(data);
|
||||
})
|
||||
.catch(error => {
|
||||
console.warn('Social refs unavailable:', error);
|
||||
socialRefsByIssueId = new Map();
|
||||
});
|
||||
}
|
||||
|
||||
export function loadIssuesForCheckedPaths({
|
||||
issueTypeFilters,
|
||||
checkedFileRefs,
|
||||
applyIssueSearchFilter
|
||||
}) {
|
||||
const addressedFiles = checkedFileRefs && typeof checkedFileRefs === 'object' && Array.isArray(checkedFileRefs.addressedFiles)
|
||||
? checkedFileRefs.addressedFiles
|
||||
: [];
|
||||
const knownFiles = checkedFileRefs && typeof checkedFileRefs === 'object' && Array.isArray(checkedFileRefs.knownFiles)
|
||||
? checkedFileRefs.knownFiles
|
||||
: [];
|
||||
|
||||
if (addressedFiles.length === 0 && knownFiles.length === 0) {
|
||||
clearIssues();
|
||||
applyIssueSearchFilter();
|
||||
return;
|
||||
}
|
||||
|
||||
if (issueTypeFilters.addressed) {
|
||||
loadIssuesFromFiles(addressedFiles, 'addressed', 'addressed-issues', applyIssueSearchFilter);
|
||||
} else {
|
||||
document.getElementById('addressed-issues').innerHTML = '';
|
||||
}
|
||||
|
||||
if (issueTypeFilters.known) {
|
||||
loadIssuesFromFiles(knownFiles, 'known', 'known-issues', applyIssueSearchFilter);
|
||||
} else {
|
||||
document.getElementById('known-issues').innerHTML = '';
|
||||
}
|
||||
}
|
||||
|
||||
function loadIssuesFromFiles(fileRefs, issueType, elementId, applyIssueSearchFilter) {
|
||||
const issuesContainer = document.getElementById(elementId);
|
||||
issuesContainer.innerHTML = '';
|
||||
|
||||
if (!fileRefs || fileRefs.length === 0) {
|
||||
renderNone(issuesContainer);
|
||||
applyIssueSearchFilter();
|
||||
return;
|
||||
}
|
||||
|
||||
const allIssues = [];
|
||||
let loadedCount = 0;
|
||||
|
||||
fileRefs.forEach(fileRef => {
|
||||
fetchIssueFile(fileRef.productKey, fileRef.fileName, issueType)
|
||||
.then(data => {
|
||||
const sourceVersion = getSourceVersionFromFileName(fileRef.fileName);
|
||||
normalizeIssuesFromPayload(data).forEach(issue => {
|
||||
allIssues.push({
|
||||
id: issue.id || '',
|
||||
summary: issue.summary || '',
|
||||
sourceVersion
|
||||
});
|
||||
});
|
||||
})
|
||||
.catch(error => {
|
||||
console.error(`Error loading ${fileRef.fileName}:`, error);
|
||||
})
|
||||
.finally(() => {
|
||||
loadedCount++;
|
||||
if (loadedCount === fileRefs.length) {
|
||||
socialRefsReady.finally(() => {
|
||||
displayIssues(allIssues, issueType, elementId);
|
||||
applyIssueSearchFilter();
|
||||
});
|
||||
}
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
function fetchIssueFile(productKey, fileName, issueType) {
|
||||
const filePath = `data/issues/${productKey}/${issueType}/${fileName}`;
|
||||
|
||||
if (issueFileDataCache.has(filePath)) {
|
||||
return Promise.resolve(issueFileDataCache.get(filePath));
|
||||
}
|
||||
|
||||
if (issueFilePromiseCache.has(filePath)) {
|
||||
return issueFilePromiseCache.get(filePath);
|
||||
}
|
||||
|
||||
const request = fetch(filePath)
|
||||
.then(response => {
|
||||
if (!response.ok) {
|
||||
throw new Error(`Failed to load ${fileName}`);
|
||||
}
|
||||
|
||||
if (/\.md$/i.test(fileName)) {
|
||||
return response.text().then(text => parseMarkdownIssues(text));
|
||||
}
|
||||
|
||||
return response.json();
|
||||
})
|
||||
.then(data => {
|
||||
issueFileDataCache.set(filePath, data);
|
||||
issueFilePromiseCache.delete(filePath);
|
||||
return data;
|
||||
})
|
||||
.catch(error => {
|
||||
issueFilePromiseCache.delete(filePath);
|
||||
throw error;
|
||||
});
|
||||
|
||||
issueFilePromiseCache.set(filePath, request);
|
||||
return request;
|
||||
}
|
||||
|
||||
function parseMarkdownIssues(markdownText) {
|
||||
const lines = String(markdownText || '').split(/\r?\n/);
|
||||
const issues = [];
|
||||
let currentIssue = null;
|
||||
let inCaveatBlock = false;
|
||||
let caveatLines = [];
|
||||
|
||||
lines.forEach(line => {
|
||||
const issueHeaderMatch = line.match(/^##\s+(.+)$/);
|
||||
if (issueHeaderMatch) {
|
||||
finalizeMarkdownIssue(currentIssue, issues);
|
||||
currentIssue = {
|
||||
id: issueHeaderMatch[1].trim(),
|
||||
descriptionLines: [],
|
||||
caveat: ''
|
||||
};
|
||||
inCaveatBlock = false;
|
||||
caveatLines = [];
|
||||
return;
|
||||
}
|
||||
|
||||
if (!currentIssue) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (/^```caveat\s*$/i.test(line.trim())) {
|
||||
inCaveatBlock = true;
|
||||
caveatLines = [];
|
||||
return;
|
||||
}
|
||||
|
||||
if (inCaveatBlock) {
|
||||
if (/^```\s*$/.test(line.trim())) {
|
||||
currentIssue.caveat = caveatLines.join(' ').replace(/\s+/g, ' ').trim();
|
||||
inCaveatBlock = false;
|
||||
caveatLines = [];
|
||||
return;
|
||||
}
|
||||
|
||||
const caveatLine = line.trim();
|
||||
if (caveatLine) {
|
||||
caveatLines.push(caveatLine);
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
const trimmed = line.trim();
|
||||
if (!trimmed || /^---\s*$/.test(trimmed)) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (/^(type|product|version|date):\s*/i.test(trimmed)) {
|
||||
return;
|
||||
}
|
||||
|
||||
currentIssue.descriptionLines.push(trimmed);
|
||||
});
|
||||
|
||||
finalizeMarkdownIssue(currentIssue, issues);
|
||||
return issues;
|
||||
}
|
||||
|
||||
function finalizeMarkdownIssue(issue, issues) {
|
||||
if (!issue || !issue.id) {
|
||||
return;
|
||||
}
|
||||
|
||||
const description = issue.descriptionLines
|
||||
.map(line => line.trimEnd())
|
||||
.join('\n')
|
||||
.replace(/\n{3,}/g, '\n\n')
|
||||
.trim();
|
||||
|
||||
let summary = description;
|
||||
if (issue.caveat) {
|
||||
summary = summary
|
||||
? `[Caveat: ${issue.caveat}] ${summary}`
|
||||
: `[Caveat: ${issue.caveat}]`;
|
||||
}
|
||||
|
||||
issues.push({
|
||||
id: issue.id,
|
||||
summary
|
||||
});
|
||||
}
|
||||
|
||||
function normalizeIssuesFromPayload(data) {
|
||||
if (Array.isArray(data)) {
|
||||
return data.map(item => {
|
||||
if (typeof item === 'string') {
|
||||
return parseIssueLine(item);
|
||||
}
|
||||
|
||||
if (item && typeof item === 'object') {
|
||||
if (item.id && (item.description || item.summary)) {
|
||||
return {
|
||||
id: String(item.id).trim(),
|
||||
summary: String(item.summary || item.description).trim()
|
||||
};
|
||||
}
|
||||
|
||||
return parseIssueLine(JSON.stringify(item));
|
||||
}
|
||||
|
||||
return parseIssueLine(String(item));
|
||||
});
|
||||
}
|
||||
|
||||
if (data && typeof data === 'object' && Array.isArray(data.issues)) {
|
||||
return data.issues.map(issue => {
|
||||
if (issue && typeof issue === 'object' && issue.id && issue.description) {
|
||||
return {
|
||||
id: String(issue.id).trim(),
|
||||
summary: String(issue.description).trim()
|
||||
};
|
||||
}
|
||||
return parseIssueLine(JSON.stringify(issue));
|
||||
});
|
||||
}
|
||||
|
||||
if (data && typeof data === 'object') {
|
||||
return [parseIssueLine(JSON.stringify(data))];
|
||||
}
|
||||
|
||||
return [];
|
||||
}
|
||||
|
||||
function displayIssues(issues, issueType, elementId) {
|
||||
const issuesContainer = document.getElementById(elementId);
|
||||
issuesContainer.innerHTML = '';
|
||||
|
||||
if (issues.length === 0) {
|
||||
renderNone(issuesContainer);
|
||||
return;
|
||||
}
|
||||
|
||||
if (issueType === 'addressed') {
|
||||
renderAddressedTable(issues, issuesContainer);
|
||||
return;
|
||||
}
|
||||
|
||||
renderKnownList(issues, issuesContainer);
|
||||
}
|
||||
|
||||
function renderAddressedTable(issues, container) {
|
||||
const deduped = dedupeAddressedIssues(issues);
|
||||
if (deduped.length === 0) {
|
||||
renderNone(container);
|
||||
return;
|
||||
}
|
||||
|
||||
const table = document.createElement('table');
|
||||
table.className = 'issues-table';
|
||||
|
||||
const thead = document.createElement('thead');
|
||||
const headerRow = document.createElement('tr');
|
||||
['Issue ID', 'Addressed in', 'Summary'].forEach((heading, idx) => {
|
||||
const th = document.createElement('th');
|
||||
th.textContent = heading;
|
||||
if (idx === 0) {
|
||||
th.className = 'issue-id-col';
|
||||
}
|
||||
if (idx === 1) {
|
||||
th.className = 'issue-version-col';
|
||||
}
|
||||
headerRow.appendChild(th);
|
||||
});
|
||||
thead.appendChild(headerRow);
|
||||
table.appendChild(thead);
|
||||
|
||||
const tbody = document.createElement('tbody');
|
||||
deduped.forEach(issue => {
|
||||
const row = document.createElement('tr');
|
||||
row.className = 'issue-search-item';
|
||||
|
||||
const idCell = document.createElement('td');
|
||||
idCell.className = 'issue-id-col';
|
||||
idCell.textContent = issue.id;
|
||||
|
||||
const addressedInCell = document.createElement('td');
|
||||
addressedInCell.className = 'issue-version-col';
|
||||
addressedInCell.textContent = issue.addressedIn.join(', ');
|
||||
|
||||
const summaryCell = document.createElement('td');
|
||||
renderSummaryCell(summaryCell, issue);
|
||||
|
||||
row.appendChild(idCell);
|
||||
row.appendChild(addressedInCell);
|
||||
row.appendChild(summaryCell);
|
||||
tbody.appendChild(row);
|
||||
});
|
||||
table.appendChild(tbody);
|
||||
container.appendChild(table);
|
||||
}
|
||||
|
||||
function renderKnownList(issues, container) {
|
||||
const deduped = dedupeIssues(issues, 'knownIn');
|
||||
if (deduped.length === 0) {
|
||||
renderNone(container);
|
||||
return;
|
||||
}
|
||||
|
||||
const table = document.createElement('table');
|
||||
table.className = 'issues-table';
|
||||
|
||||
const thead = document.createElement('thead');
|
||||
const headerRow = document.createElement('tr');
|
||||
['Issue ID', 'Known in', 'Summary'].forEach((heading, idx) => {
|
||||
const th = document.createElement('th');
|
||||
th.textContent = heading;
|
||||
if (idx === 0) th.className = 'issue-id-col';
|
||||
if (idx === 1) th.className = 'issue-version-col';
|
||||
headerRow.appendChild(th);
|
||||
});
|
||||
thead.appendChild(headerRow);
|
||||
table.appendChild(thead);
|
||||
|
||||
const tbody = document.createElement('tbody');
|
||||
deduped.forEach(issue => {
|
||||
const row = document.createElement('tr');
|
||||
row.className = 'issue-search-item';
|
||||
|
||||
const idCell = document.createElement('td');
|
||||
idCell.className = 'issue-id-col';
|
||||
idCell.textContent = issue.id;
|
||||
|
||||
const knownInCell = document.createElement('td');
|
||||
knownInCell.className = 'issue-version-col';
|
||||
knownInCell.textContent = issue.knownIn.join(', ');
|
||||
|
||||
const summaryCell = document.createElement('td');
|
||||
renderSummaryCell(summaryCell, issue);
|
||||
|
||||
row.appendChild(idCell);
|
||||
row.appendChild(knownInCell);
|
||||
row.appendChild(summaryCell);
|
||||
tbody.appendChild(row);
|
||||
});
|
||||
table.appendChild(tbody);
|
||||
container.appendChild(table);
|
||||
}
|
||||
|
||||
function dedupeAddressedIssues(issues) {
|
||||
return dedupeIssues(issues, 'addressedIn');
|
||||
}
|
||||
|
||||
function dedupeIssues(issues, versionKey) {
|
||||
const map = new Map();
|
||||
|
||||
issues.forEach(issue => {
|
||||
const id = (issue.id || '').trim();
|
||||
const summary = (issue.summary || '').trim();
|
||||
if (!id) return;
|
||||
|
||||
if (!map.has(id)) {
|
||||
map.set(id, { id, summary, [versionKey]: [] });
|
||||
}
|
||||
|
||||
const entry = map.get(id);
|
||||
if (!entry.summary && summary) {
|
||||
entry.summary = summary;
|
||||
}
|
||||
|
||||
const version = (issue.sourceVersion || '').trim();
|
||||
if (version && !entry[versionKey].includes(version)) {
|
||||
entry[versionKey].push(version);
|
||||
}
|
||||
});
|
||||
|
||||
return Array.from(map.values()).sort((a, b) => b.id.localeCompare(a.id));
|
||||
}
|
||||
|
||||
function parseIssueLine(text) {
|
||||
const value = String(text || '').trim();
|
||||
const match = value.match(/^([A-Z]{2,6}-\d{4,8})\s*[:\-]?\s*(.*)$/i);
|
||||
if (match) {
|
||||
return {
|
||||
id: match[1].toUpperCase(),
|
||||
summary: (match[2] || '').trim()
|
||||
};
|
||||
}
|
||||
|
||||
return {
|
||||
id: '',
|
||||
summary: value
|
||||
};
|
||||
}
|
||||
|
||||
function getSourceVersionFromFileName(fileName) {
|
||||
const value = String(fileName || '').trim();
|
||||
const underscoreIndex = value.indexOf('_');
|
||||
if (underscoreIndex > 0) {
|
||||
return value.slice(0, underscoreIndex);
|
||||
}
|
||||
|
||||
return value.replace(/\.(json|md)$/i, '');
|
||||
}
|
||||
|
||||
function renderSummaryCell(cell, issue) {
|
||||
cell.innerHTML = markdownSummaryToHtml(issue.summary);
|
||||
|
||||
const refs = getSocialRefsForIssue(issue.id);
|
||||
if (!refs.length) {
|
||||
return;
|
||||
}
|
||||
|
||||
const refsContainer = document.createElement('div');
|
||||
refsContainer.style.marginTop = '6px';
|
||||
|
||||
refs.forEach((ref, index) => {
|
||||
const link = document.createElement('a');
|
||||
link.href = ref.url;
|
||||
link.target = '_blank';
|
||||
link.rel = 'noopener noreferrer';
|
||||
link.textContent = `(${ref.label})`;
|
||||
|
||||
refsContainer.appendChild(link);
|
||||
if (index < refs.length - 1) {
|
||||
refsContainer.appendChild(document.createTextNode(' '));
|
||||
}
|
||||
});
|
||||
|
||||
cell.appendChild(refsContainer);
|
||||
}
|
||||
|
||||
function getSocialRefsForIssue(issueId) {
|
||||
const normalizedIssueId = String(issueId || '').trim().toUpperCase();
|
||||
if (!normalizedIssueId) {
|
||||
return [];
|
||||
}
|
||||
|
||||
return socialRefsByIssueId.get(normalizedIssueId) || [];
|
||||
}
|
||||
|
||||
function normalizeSocialRefs(data) {
|
||||
const map = new Map();
|
||||
if (!data || typeof data !== 'object') {
|
||||
return map;
|
||||
}
|
||||
|
||||
Object.keys(data).forEach(sourceKey => {
|
||||
const sourceValue = data[sourceKey];
|
||||
const entries = getSourceEntries(sourceValue);
|
||||
const label = getSourceDisplayLabel(sourceKey, sourceValue);
|
||||
|
||||
entries.forEach(entry => {
|
||||
if (!entry || typeof entry !== 'object') {
|
||||
return;
|
||||
}
|
||||
|
||||
const id = String(entry.id || '').trim().toUpperCase();
|
||||
const url = String(entry.url || '').trim();
|
||||
if (!id || !url) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (!map.has(id)) {
|
||||
map.set(id, []);
|
||||
}
|
||||
|
||||
map.get(id).push({ label, url });
|
||||
});
|
||||
});
|
||||
|
||||
return map;
|
||||
}
|
||||
|
||||
function getSourceEntries(sourceValue) {
|
||||
if (Array.isArray(sourceValue)) {
|
||||
return sourceValue;
|
||||
}
|
||||
|
||||
if (sourceValue && typeof sourceValue === 'object' && Array.isArray(sourceValue.entries)) {
|
||||
return sourceValue.entries;
|
||||
}
|
||||
|
||||
return [];
|
||||
}
|
||||
|
||||
function getSourceDisplayLabel(sourceKey, sourceValue) {
|
||||
if (sourceValue && typeof sourceValue === 'object' && !Array.isArray(sourceValue)) {
|
||||
const display = String(sourceValue.display || '').trim();
|
||||
if (display) {
|
||||
return display;
|
||||
}
|
||||
}
|
||||
|
||||
return sourceLabelFromKey(sourceKey);
|
||||
}
|
||||
|
||||
function sourceLabelFromKey(sourceKey) {
|
||||
const key = String(sourceKey || '').trim().toLowerCase();
|
||||
if (!key) {
|
||||
return 'Link';
|
||||
}
|
||||
|
||||
return key
|
||||
.split(/[_\-\s]+/)
|
||||
.filter(Boolean)
|
||||
.map(part => part.charAt(0).toUpperCase() + part.slice(1))
|
||||
.join(' ');
|
||||
}
|
||||
|
||||
function markdownSummaryToHtml(summaryText) {
|
||||
const input = String(summaryText || '').trim();
|
||||
if (!input) {
|
||||
return '';
|
||||
}
|
||||
|
||||
const caveatMatch = input.match(/^\[Caveat:\s*([^\]]+)\]\s*/i);
|
||||
const caveatText = caveatMatch ? caveatMatch[1].trim() : '';
|
||||
const body = caveatMatch ? input.slice(caveatMatch[0].length) : input;
|
||||
|
||||
const htmlParts = [];
|
||||
if (caveatText) {
|
||||
htmlParts.push(`<div><em>Caveat: ${escapeHtml(caveatText)}</em></div>`);
|
||||
}
|
||||
|
||||
htmlParts.push(renderMarkdownBodyToHtml(body));
|
||||
return htmlParts.join('');
|
||||
}
|
||||
|
||||
function renderMarkdownBodyToHtml(markdownText) {
|
||||
const lines = String(markdownText || '').split(/\r?\n/);
|
||||
const htmlParts = [];
|
||||
let paragraphLines = [];
|
||||
|
||||
function flushParagraph() {
|
||||
if (paragraphLines.length === 0) {
|
||||
return;
|
||||
}
|
||||
const text = paragraphLines.join(' ').replace(/\s+/g, ' ').trim();
|
||||
if (text) {
|
||||
htmlParts.push(`<p>${escapeHtml(text)}</p>`);
|
||||
}
|
||||
paragraphLines = [];
|
||||
}
|
||||
|
||||
for (let i = 0; i < lines.length; i++) {
|
||||
const line = lines[i];
|
||||
const trimmed = line.trim();
|
||||
|
||||
if (!trimmed) {
|
||||
flushParagraph();
|
||||
continue;
|
||||
}
|
||||
|
||||
const next = i + 1 < lines.length ? lines[i + 1].trim() : '';
|
||||
if (isTableRow(trimmed) && isTableSeparator(next)) {
|
||||
flushParagraph();
|
||||
|
||||
const headerCells = parseMarkdownTableRow(trimmed);
|
||||
const rows = [];
|
||||
i += 2;
|
||||
while (i < lines.length && isTableRow(lines[i].trim())) {
|
||||
rows.push(parseMarkdownTableRow(lines[i].trim()));
|
||||
i++;
|
||||
}
|
||||
i -= 1;
|
||||
|
||||
htmlParts.push(renderHtmlTable(headerCells, rows));
|
||||
continue;
|
||||
}
|
||||
|
||||
paragraphLines.push(trimmed);
|
||||
}
|
||||
|
||||
flushParagraph();
|
||||
return htmlParts.join('');
|
||||
}
|
||||
|
||||
function isTableRow(line) {
|
||||
return /\|/.test(line);
|
||||
}
|
||||
|
||||
function isTableSeparator(line) {
|
||||
return /^\|?\s*:?-{3,}:?(\s*\|\s*:?-{3,}:?)*\s*\|?$/.test(line);
|
||||
}
|
||||
|
||||
function parseMarkdownTableRow(line) {
|
||||
const raw = line.trim().replace(/^\|/, '').replace(/\|$/, '');
|
||||
return raw.split('|').map(cell => cell.trim());
|
||||
}
|
||||
|
||||
function renderHtmlTable(headerCells, rows) {
|
||||
const colCount = headerCells.length;
|
||||
const thead = `<thead><tr>${headerCells.map(cell => `<th>${escapeHtml(cell)}</th>`).join('')}</tr></thead>`;
|
||||
const tbodyRows = rows.map(row => {
|
||||
const normalized = [...row];
|
||||
while (normalized.length < colCount) {
|
||||
normalized.push('');
|
||||
}
|
||||
return `<tr>${normalized.slice(0, colCount).map(cell => `<td>${escapeHtml(cell)}</td>`).join('')}</tr>`;
|
||||
}).join('');
|
||||
|
||||
return `<table class="issues-table">${thead}<tbody>${tbodyRows}</tbody></table>`;
|
||||
}
|
||||
|
||||
function escapeHtml(value) {
|
||||
return String(value)
|
||||
.replace(/&/g, '&')
|
||||
.replace(/</g, '<')
|
||||
.replace(/>/g, '>')
|
||||
.replace(/"/g, '"')
|
||||
.replace(/'/g, ''');
|
||||
}
|
||||
|
||||
function renderNone(container) {
|
||||
const li = document.createElement('li');
|
||||
li.textContent = 'None';
|
||||
li.style.fontStyle = 'italic';
|
||||
li.style.color = '#999';
|
||||
container.appendChild(li);
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
export function isVersionKey(key) {
|
||||
return /^\d+(\.\d+)*$/.test(key);
|
||||
}
|
||||
|
||||
export function compareVersionDesc(a, b) {
|
||||
const aParts = a.split('.').map(Number);
|
||||
const bParts = b.split('.').map(Number);
|
||||
const maxLen = Math.max(aParts.length, bParts.length);
|
||||
|
||||
for (let i = 0; i < maxLen; i++) {
|
||||
const aVal = aParts[i] || 0;
|
||||
const bVal = bParts[i] || 0;
|
||||
if (aVal !== bVal) {
|
||||
return bVal - aVal;
|
||||
}
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
export function getSortedKeys(obj) {
|
||||
return Object.keys(obj).sort((a, b) => {
|
||||
const aIsVersion = isVersionKey(a);
|
||||
const bIsVersion = isVersionKey(b);
|
||||
|
||||
if (aIsVersion && bIsVersion) {
|
||||
return compareVersionDesc(a, b);
|
||||
}
|
||||
|
||||
if (aIsVersion && !bIsVersion) {
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (!aIsVersion && bIsVersion) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
return a.localeCompare(b);
|
||||
});
|
||||
}
|
||||
+229
@@ -0,0 +1,229 @@
|
||||
import { getSortedKeys } from './sort.js';
|
||||
|
||||
let treeContainer = null;
|
||||
let onSelectionChangeHandler = null;
|
||||
|
||||
export function initializeTree(containerId, onSelectionChange) {
|
||||
treeContainer = document.getElementById(containerId);
|
||||
onSelectionChangeHandler = onSelectionChange;
|
||||
}
|
||||
|
||||
export function renderProductTree(productsData) {
|
||||
if (!treeContainer) {
|
||||
throw new Error('Tree is not initialized. Call initializeTree first.');
|
||||
}
|
||||
|
||||
treeContainer.innerHTML = '';
|
||||
|
||||
getSortedKeys(productsData).forEach(product => {
|
||||
const productNode = createTreeNode(product, productsData[product], [product]);
|
||||
treeContainer.appendChild(productNode);
|
||||
});
|
||||
}
|
||||
|
||||
export function getCheckedPaths() {
|
||||
if (!treeContainer) {
|
||||
return [];
|
||||
}
|
||||
|
||||
const checkedBoxes = treeContainer.querySelectorAll('input[type="checkbox"]:checked');
|
||||
|
||||
return Array.from(checkedBoxes)
|
||||
.map(cb => cb.dataset.path)
|
||||
.filter(Boolean)
|
||||
.map(pathText => {
|
||||
try {
|
||||
return JSON.parse(pathText);
|
||||
} catch (error) {
|
||||
console.error('Invalid checkbox path data:', pathText, error);
|
||||
return null;
|
||||
}
|
||||
})
|
||||
.filter(pathArray => Array.isArray(pathArray) && pathArray.length > 0);
|
||||
}
|
||||
|
||||
export function getCheckedFileRefs() {
|
||||
if (!treeContainer) {
|
||||
return {
|
||||
addressedFiles: [],
|
||||
knownFiles: []
|
||||
};
|
||||
}
|
||||
|
||||
const addressedFiles = [];
|
||||
const knownFiles = [];
|
||||
const checkedBoxes = treeContainer.querySelectorAll('input[type="checkbox"]:checked[data-has-files="1"]');
|
||||
|
||||
checkedBoxes.forEach(cb => {
|
||||
const pathText = cb.dataset.path;
|
||||
if (!pathText) {
|
||||
return;
|
||||
}
|
||||
|
||||
let path;
|
||||
try {
|
||||
path = JSON.parse(pathText);
|
||||
} catch (error) {
|
||||
console.error('Invalid checkbox path data:', pathText, error);
|
||||
return;
|
||||
}
|
||||
|
||||
if (!Array.isArray(path) || path.length === 0) {
|
||||
return;
|
||||
}
|
||||
|
||||
const productKey = path[0];
|
||||
|
||||
const addressed = parseJsonArray(cb.dataset.addressed);
|
||||
addressed.forEach(fileName => addressedFiles.push({ productKey, fileName }));
|
||||
|
||||
const known = parseJsonArray(cb.dataset.known);
|
||||
known.forEach(fileName => knownFiles.push({ productKey, fileName }));
|
||||
});
|
||||
|
||||
return {
|
||||
addressedFiles,
|
||||
knownFiles
|
||||
};
|
||||
}
|
||||
|
||||
function createTreeNode(name, value, path) {
|
||||
const container = document.createElement('div');
|
||||
container.className = 'tree-item';
|
||||
|
||||
const isLeafWithFiles = value && typeof value === 'object' && ('addressed' in value || 'known' in value);
|
||||
const hasChildren = value && typeof value === 'object' && !isLeafWithFiles && Object.keys(value).length > 0;
|
||||
|
||||
if (hasChildren) {
|
||||
container.classList.add('parent');
|
||||
|
||||
const toggle = document.createElement('span');
|
||||
toggle.className = 'tree-toggle';
|
||||
toggle.textContent = '▼';
|
||||
toggle.style.cursor = 'pointer';
|
||||
|
||||
const label = document.createElement('label');
|
||||
const checkbox = createCheckbox(path);
|
||||
label.appendChild(checkbox);
|
||||
label.appendChild(document.createTextNode(name));
|
||||
|
||||
const childrenContainer = document.createElement('div');
|
||||
childrenContainer.className = 'tree-children';
|
||||
|
||||
getSortedKeys(value).forEach(childKey => {
|
||||
const childNode = createTreeNode(childKey, value[childKey], [...path, childKey]);
|
||||
childrenContainer.appendChild(childNode);
|
||||
});
|
||||
|
||||
toggle.addEventListener('click', event => {
|
||||
event.stopPropagation();
|
||||
childrenContainer.classList.toggle('collapsed');
|
||||
toggle.textContent = childrenContainer.classList.contains('collapsed') ? '▶' : '▼';
|
||||
});
|
||||
|
||||
container.appendChild(toggle);
|
||||
container.appendChild(label);
|
||||
container.appendChild(childrenContainer);
|
||||
return container;
|
||||
}
|
||||
|
||||
const label = document.createElement('label');
|
||||
if (isLeafWithFiles) {
|
||||
const checkbox = createCheckbox(path, value);
|
||||
label.appendChild(checkbox);
|
||||
}
|
||||
|
||||
label.appendChild(document.createTextNode(name));
|
||||
container.appendChild(label);
|
||||
return container;
|
||||
}
|
||||
|
||||
function createCheckbox(path, value) {
|
||||
const checkbox = document.createElement('input');
|
||||
checkbox.type = 'checkbox';
|
||||
checkbox.value = path.join('/');
|
||||
checkbox.dataset.path = JSON.stringify(path);
|
||||
|
||||
if (value && typeof value === 'object' && ('addressed' in value || 'known' in value)) {
|
||||
checkbox.dataset.hasFiles = '1';
|
||||
checkbox.dataset.addressed = JSON.stringify(Array.isArray(value.addressed) ? value.addressed : []);
|
||||
checkbox.dataset.known = JSON.stringify(Array.isArray(value.known) ? value.known : []);
|
||||
}
|
||||
|
||||
checkbox.addEventListener('change', event => {
|
||||
handleCheckboxChange(event);
|
||||
});
|
||||
|
||||
return checkbox;
|
||||
}
|
||||
|
||||
function parseJsonArray(value) {
|
||||
if (!value) {
|
||||
return [];
|
||||
}
|
||||
|
||||
try {
|
||||
const parsed = JSON.parse(value);
|
||||
return Array.isArray(parsed) ? parsed : [];
|
||||
} catch (error) {
|
||||
console.error('Invalid checkbox file metadata:', value, error);
|
||||
return [];
|
||||
}
|
||||
}
|
||||
|
||||
function handleCheckboxChange(event) {
|
||||
const checkbox = event.target;
|
||||
const container = checkbox.closest('.tree-item');
|
||||
const childrenContainer = container.querySelector('.tree-children');
|
||||
|
||||
if (childrenContainer) {
|
||||
const childCheckboxes = childrenContainer.querySelectorAll('input[type="checkbox"]');
|
||||
childCheckboxes.forEach(cb => {
|
||||
cb.checked = checkbox.checked;
|
||||
cb.indeterminate = false;
|
||||
});
|
||||
}
|
||||
|
||||
checkbox.indeterminate = false;
|
||||
updateParentCheckboxes(checkbox);
|
||||
|
||||
if (typeof onSelectionChangeHandler === 'function') {
|
||||
onSelectionChangeHandler();
|
||||
}
|
||||
}
|
||||
|
||||
function updateParentCheckboxes(checkbox) {
|
||||
let currentItem = checkbox.closest('.tree-item');
|
||||
let parentItem = currentItem.parentElement.closest('.tree-item');
|
||||
|
||||
while (parentItem) {
|
||||
const parentLabel = parentItem.querySelector(':scope > label');
|
||||
if (!parentLabel) {
|
||||
parentItem = parentItem.parentElement.closest('.tree-item');
|
||||
continue;
|
||||
}
|
||||
|
||||
const parentCheckbox = parentLabel.querySelector('input[type="checkbox"]');
|
||||
if (!parentCheckbox) {
|
||||
parentItem = parentItem.parentElement.closest('.tree-item');
|
||||
continue;
|
||||
}
|
||||
|
||||
const children = parentItem.querySelectorAll(':scope > .tree-children > .tree-item > label > input[type="checkbox"]');
|
||||
const checkedCount = Array.from(children).filter(cb => cb.checked || cb.indeterminate).length;
|
||||
|
||||
if (checkedCount === 0) {
|
||||
parentCheckbox.checked = false;
|
||||
parentCheckbox.indeterminate = false;
|
||||
} else if (checkedCount === children.length) {
|
||||
parentCheckbox.checked = true;
|
||||
parentCheckbox.indeterminate = false;
|
||||
} else {
|
||||
parentCheckbox.checked = false;
|
||||
parentCheckbox.indeterminate = true;
|
||||
}
|
||||
|
||||
currentItem = parentItem;
|
||||
parentItem = currentItem.parentElement.closest('.tree-item');
|
||||
}
|
||||
}
|
||||
+135
@@ -0,0 +1,135 @@
|
||||
const TYPE_FILTER_KEY = 'bugmedley.ui.typeFilters.v1';
|
||||
|
||||
let issueSearchTerm = '';
|
||||
let issueTypeFilters = loadTypeFilters();
|
||||
|
||||
function loadTypeFilters() {
|
||||
try {
|
||||
const saved = localStorage.getItem(TYPE_FILTER_KEY);
|
||||
if (saved) {
|
||||
const parsed = JSON.parse(saved);
|
||||
if (typeof parsed.addressed === 'boolean' && typeof parsed.known === 'boolean') {
|
||||
return parsed;
|
||||
}
|
||||
}
|
||||
} catch (_) {}
|
||||
return { addressed: true, known: true };
|
||||
}
|
||||
|
||||
function saveTypeFilters() {
|
||||
try {
|
||||
localStorage.setItem(TYPE_FILTER_KEY, JSON.stringify(issueTypeFilters));
|
||||
} catch (_) {}
|
||||
}
|
||||
|
||||
export function initializeUI({ onSelectionChange }) {
|
||||
initializeIssueSearch();
|
||||
initializeIssueTypeFilters(onSelectionChange);
|
||||
updateIssueSectionVisibility();
|
||||
updateIssueCounts();
|
||||
}
|
||||
|
||||
export function getIssueTypeFilters() {
|
||||
return issueTypeFilters;
|
||||
}
|
||||
|
||||
export function applyIssueSearchFilter() {
|
||||
const issueItems = document.querySelectorAll('.issue-search-item');
|
||||
|
||||
issueItems.forEach(item => {
|
||||
const itemText = item.textContent.toLowerCase();
|
||||
const matches = issueSearchTerm === '' || itemText.includes(issueSearchTerm);
|
||||
if (item.tagName === 'TR') {
|
||||
item.style.display = matches ? 'table-row' : 'none';
|
||||
} else {
|
||||
item.style.display = matches ? '' : 'none';
|
||||
}
|
||||
});
|
||||
|
||||
updateIssueCounts();
|
||||
}
|
||||
|
||||
function initializeIssueSearch() {
|
||||
const searchInput = document.getElementById('issue-search');
|
||||
searchInput.addEventListener('input', () => {
|
||||
issueSearchTerm = searchInput.value.trim().toLowerCase();
|
||||
applyIssueSearchFilter();
|
||||
});
|
||||
}
|
||||
|
||||
function initializeIssueTypeFilters(onSelectionChange) {
|
||||
const addressedFilter = document.getElementById('filter-addressed');
|
||||
const knownFilter = document.getElementById('filter-known');
|
||||
|
||||
// Restore checkbox state from persisted filters
|
||||
addressedFilter.checked = issueTypeFilters.addressed;
|
||||
knownFilter.checked = issueTypeFilters.known;
|
||||
|
||||
addressedFilter.addEventListener('change', () => {
|
||||
if (!addressedFilter.checked && !knownFilter.checked) {
|
||||
addressedFilter.checked = true;
|
||||
}
|
||||
|
||||
issueTypeFilters = {
|
||||
addressed: addressedFilter.checked,
|
||||
known: knownFilter.checked
|
||||
};
|
||||
|
||||
saveTypeFilters();
|
||||
updateIssueSectionVisibility();
|
||||
if (typeof onSelectionChange === 'function') {
|
||||
onSelectionChange();
|
||||
}
|
||||
});
|
||||
|
||||
knownFilter.addEventListener('change', () => {
|
||||
if (!knownFilter.checked && !addressedFilter.checked) {
|
||||
knownFilter.checked = true;
|
||||
}
|
||||
|
||||
issueTypeFilters = {
|
||||
addressed: addressedFilter.checked,
|
||||
known: knownFilter.checked
|
||||
};
|
||||
|
||||
saveTypeFilters();
|
||||
updateIssueSectionVisibility();
|
||||
if (typeof onSelectionChange === 'function') {
|
||||
onSelectionChange();
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
function updateIssueSectionVisibility() {
|
||||
const addressedSection = document.getElementById('addressed-section');
|
||||
const knownSection = document.getElementById('known-section');
|
||||
|
||||
addressedSection.style.display = issueTypeFilters.addressed ? 'block' : 'none';
|
||||
knownSection.style.display = issueTypeFilters.known ? 'block' : 'none';
|
||||
}
|
||||
|
||||
function updateIssueCounts() {
|
||||
const addressedCount = countVisibleIssueItems('addressed-issues');
|
||||
const knownCount = countVisibleIssueItems('known-issues');
|
||||
|
||||
const addressedCountEl = document.getElementById('addressed-count');
|
||||
const knownCountEl = document.getElementById('known-count');
|
||||
|
||||
if (addressedCountEl) {
|
||||
addressedCountEl.textContent = `(${addressedCount})`;
|
||||
}
|
||||
|
||||
if (knownCountEl) {
|
||||
knownCountEl.textContent = `(${knownCount})`;
|
||||
}
|
||||
}
|
||||
|
||||
function countVisibleIssueItems(containerId) {
|
||||
const container = document.getElementById(containerId);
|
||||
if (!container) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
const items = container.querySelectorAll('.issue-search-item');
|
||||
return Array.from(items).filter(item => item.style.display !== 'none').length;
|
||||
}
|
||||
@@ -0,0 +1,136 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>Process Issues - Palo Alto Issues Tracker</title>
|
||||
<link rel="stylesheet" href="styles.css">
|
||||
<style>
|
||||
.process-container {
|
||||
max-width: 1200px;
|
||||
margin: 20px auto;
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 20px;
|
||||
}
|
||||
.form-section, .preview-section {
|
||||
border: 1px solid #ccc;
|
||||
padding: 20px;
|
||||
border-radius: 5px;
|
||||
}
|
||||
.form-section h2, .preview-section h2 {
|
||||
margin-top: 0;
|
||||
}
|
||||
.form-group {
|
||||
margin-bottom: 15px;
|
||||
}
|
||||
label {
|
||||
display: block;
|
||||
margin-bottom: 5px;
|
||||
font-weight: bold;
|
||||
color: #333;
|
||||
}
|
||||
input[type="text"], select, textarea {
|
||||
width: 100%;
|
||||
padding: 8px;
|
||||
border: 1px solid #ddd;
|
||||
border-radius: 3px;
|
||||
font-size: 14px;
|
||||
box-sizing: border-box;
|
||||
}
|
||||
textarea {
|
||||
font-family: monospace;
|
||||
resize: vertical;
|
||||
}
|
||||
#issuesInput {
|
||||
height: 200px;
|
||||
}
|
||||
#markdownOutput {
|
||||
height: 350px;
|
||||
background-color: #f5f5f5;
|
||||
}
|
||||
button {
|
||||
background-color: #4CAF50;
|
||||
color: white;
|
||||
padding: 10px 20px;
|
||||
border: none;
|
||||
border-radius: 3px;
|
||||
cursor: pointer;
|
||||
font-size: 14px;
|
||||
}
|
||||
button:hover {
|
||||
background-color: #45a049;
|
||||
}
|
||||
.button-group {
|
||||
display: flex;
|
||||
gap: 10px;
|
||||
}
|
||||
.checkbox-group {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
gap: 8px;
|
||||
}
|
||||
.checkbox-label {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
font-weight: normal;
|
||||
margin: 0;
|
||||
}
|
||||
.checkbox-label input[type="checkbox"] {
|
||||
width: auto;
|
||||
margin-right: 8px;
|
||||
cursor: pointer;
|
||||
}
|
||||
@media (max-width: 768px) {
|
||||
.process-container {
|
||||
grid-template-columns: 1fr;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<header>
|
||||
<h1>Process Issues</h1>
|
||||
</header>
|
||||
<main>
|
||||
<div class="process-container">
|
||||
<section class="form-section">
|
||||
<h2>Input</h2>
|
||||
<div class="form-group">
|
||||
<label for="productSelect">Software Product:</label>
|
||||
<select id="productSelect">
|
||||
<option value="">-- Select a product --</option>
|
||||
</select>
|
||||
</div>
|
||||
<div class="form-group">
|
||||
<label for="issueTypeSelect">Type of Issue:</label>
|
||||
<select id="issueTypeSelect">
|
||||
<option value="">-- Select type --</option>
|
||||
<option value="Addressed">Addressed</option>
|
||||
<option value="Known">Known</option>
|
||||
</select>
|
||||
</div>
|
||||
<div class="form-group">
|
||||
<label for="versionInput">Version:</label>
|
||||
<input type="text" id="versionInput" placeholder="e.g., 6.3.3">
|
||||
</div>
|
||||
<div class="form-group">
|
||||
<label for="issuesInput">Issues Table HTML (paste table node here):</label>
|
||||
<textarea id="issuesInput" placeholder="Paste the full HTML table element that contains Issue ID and Description columns..."></textarea>
|
||||
</div>
|
||||
<div id="parseStatus" style="margin-top: 10px; font-size: 13px; color: #333;"></div>
|
||||
</section>
|
||||
|
||||
<section class="preview-section">
|
||||
<h2>Markdown Preview</h2>
|
||||
<label for="markdownOutput">Copy the Markdown below:</label>
|
||||
<textarea id="markdownOutput" readonly></textarea>
|
||||
<button onclick="copyToClipboard(event)" style="margin-top: 10px; width: 100%;">Copy Markdown</button>
|
||||
<a id="downloadMarkdownLink" href="#" style="display: block; margin-top: 10px; text-align: center; color: #2c7be5; text-decoration: none; pointer-events: none; opacity: 0.6;">Download Markdown File</a>
|
||||
</section>
|
||||
</div>
|
||||
</main>
|
||||
|
||||
<script src="process.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
+488
@@ -0,0 +1,488 @@
|
||||
document.addEventListener('DOMContentLoaded', () => {
|
||||
loadProducts();
|
||||
setupEventListeners();
|
||||
restoreFormState();
|
||||
});
|
||||
|
||||
let activeDownloadUrl = null;
|
||||
const PROCESS_FORM_STATE_KEY = 'bugmedley.process.formState.v1';
|
||||
|
||||
function loadProducts() {
|
||||
fetch('products.json')
|
||||
.then(response => response.json())
|
||||
.then(data => {
|
||||
const productSelect = document.getElementById('productSelect');
|
||||
const products = Object.keys(data || {});
|
||||
|
||||
products.forEach(product => {
|
||||
const option = document.createElement('option');
|
||||
option.value = product;
|
||||
option.textContent = product;
|
||||
productSelect.appendChild(option);
|
||||
});
|
||||
|
||||
applyPersistedProductSelection();
|
||||
})
|
||||
.catch(error => {
|
||||
console.error('Error loading products:', error);
|
||||
setParseStatus('Could not load products.json', true);
|
||||
});
|
||||
}
|
||||
|
||||
function setupEventListeners() {
|
||||
document.getElementById('issuesInput').addEventListener('input', generateJSON);
|
||||
document.getElementById('productSelect').addEventListener('change', generateJSON);
|
||||
document.getElementById('issueTypeSelect').addEventListener('change', generateJSON);
|
||||
document.getElementById('versionInput').addEventListener('input', generateJSON);
|
||||
|
||||
document.getElementById('productSelect').addEventListener('change', persistFormState);
|
||||
document.getElementById('issueTypeSelect').addEventListener('change', persistFormState);
|
||||
document.getElementById('versionInput').addEventListener('input', persistFormState);
|
||||
}
|
||||
|
||||
function generateJSON() {
|
||||
const product = document.getElementById('productSelect').value;
|
||||
const issueType = document.getElementById('issueTypeSelect').value;
|
||||
const version = document.getElementById('versionInput').value.trim();
|
||||
const inputText = document.getElementById('issuesInput').value;
|
||||
|
||||
persistFormState();
|
||||
|
||||
if (!product || !issueType || !version || !inputText.trim()) {
|
||||
document.getElementById('markdownOutput').value = '';
|
||||
resetDownloadLink();
|
||||
setParseStatus('');
|
||||
return;
|
||||
}
|
||||
|
||||
const parsedIssues = parseIssuesInput(inputText);
|
||||
|
||||
if (parsedIssues.length === 0) {
|
||||
document.getElementById('markdownOutput').value = '';
|
||||
resetDownloadLink();
|
||||
setParseStatus('No issues found in pasted input. Make sure it includes Issue ID and Description rows.', true);
|
||||
return;
|
||||
}
|
||||
|
||||
const issues = parsedIssues.map(issue => ({
|
||||
id: issue.id,
|
||||
description: issue.description,
|
||||
caveat: issue.caveat || ''
|
||||
}));
|
||||
|
||||
const jsonData = {
|
||||
type: issueType,
|
||||
product,
|
||||
version,
|
||||
issues
|
||||
};
|
||||
|
||||
const markdownText = buildMarkdownOutput(jsonData);
|
||||
document.getElementById('markdownOutput').value = markdownText;
|
||||
updateDownloadLink(markdownText, version);
|
||||
setParseStatus(`Parsed ${issues.length} issues from input.`);
|
||||
}
|
||||
|
||||
function buildMarkdownOutput(payload) {
|
||||
const lines = [];
|
||||
lines.push('---');
|
||||
lines.push(`type: ${payload.type}`);
|
||||
lines.push(`product: ${payload.product}`);
|
||||
lines.push(`version: ${payload.version}`);
|
||||
lines.push('---');
|
||||
lines.push('');
|
||||
|
||||
if (!payload.issues || payload.issues.length === 0) {
|
||||
lines.push('_No issues_');
|
||||
lines.push('');
|
||||
return lines.join('\n');
|
||||
}
|
||||
|
||||
payload.issues.forEach(issue => {
|
||||
lines.push(`## ${issue.id}`);
|
||||
lines.push('');
|
||||
|
||||
if (issue.caveat) {
|
||||
lines.push('```caveat');
|
||||
lines.push(issue.caveat);
|
||||
lines.push('```');
|
||||
lines.push('');
|
||||
}
|
||||
|
||||
const paragraphs = String(issue.description || '')
|
||||
.split(/\n{2,}/)
|
||||
.map(text => text.trim())
|
||||
.filter(Boolean);
|
||||
|
||||
if (paragraphs.length === 0) {
|
||||
lines.push('');
|
||||
} else {
|
||||
paragraphs.forEach(paragraph => {
|
||||
lines.push(paragraph);
|
||||
lines.push('');
|
||||
});
|
||||
}
|
||||
|
||||
if (Array.isArray(issue.platforms) && issue.platforms.length > 0) {
|
||||
lines.push(`Platforms: ${issue.platforms.join(', ')}`);
|
||||
lines.push('');
|
||||
}
|
||||
});
|
||||
|
||||
return lines.join('\n');
|
||||
}
|
||||
|
||||
function parseIssuesInput(inputText) {
|
||||
const fromHtml = parseIssuesFromHtmlTable(inputText);
|
||||
if (fromHtml.length > 0) {
|
||||
return fromHtml;
|
||||
}
|
||||
|
||||
return parseIssuesFromLinePairs(inputText);
|
||||
}
|
||||
|
||||
function parseIssuesFromHtmlTable(htmlText) {
|
||||
const parser = new DOMParser();
|
||||
const doc = parser.parseFromString(htmlText, 'text/html');
|
||||
const table = doc.querySelector('table');
|
||||
|
||||
if (!table) {
|
||||
return [];
|
||||
}
|
||||
|
||||
const rows = table.querySelectorAll(':scope > tr, :scope > tbody > tr, :scope > thead > tr, :scope > tfoot > tr');
|
||||
const issues = [];
|
||||
|
||||
rows.forEach(row => {
|
||||
const cells = row.querySelectorAll('td, th');
|
||||
if (cells.length < 2) {
|
||||
return;
|
||||
}
|
||||
|
||||
const leftCellText = normalizeWhitespace(cells[0].textContent || '');
|
||||
const issueDetails = extractIssueDetails(cells[1]);
|
||||
const rightCellText = issueDetails.description;
|
||||
|
||||
if (/^issue\s*id$/i.test(leftCellText) || /^description$/i.test(rightCellText)) {
|
||||
return;
|
||||
}
|
||||
|
||||
const issueIdMatch = leftCellText.match(/\b([A-Z]{2,6}-\d{4,8})\b/i);
|
||||
if (!issueIdMatch) {
|
||||
return;
|
||||
}
|
||||
|
||||
const id = issueIdMatch[1].toUpperCase();
|
||||
const description = rightCellText;
|
||||
|
||||
if (!description) {
|
||||
return;
|
||||
}
|
||||
|
||||
issues.push({
|
||||
id,
|
||||
description,
|
||||
caveat: issueDetails.caveat
|
||||
});
|
||||
});
|
||||
|
||||
return issues;
|
||||
}
|
||||
|
||||
function extractIssueDetails(cell) {
|
||||
const caveatNode = cell.querySelector('tt');
|
||||
const caveat = caveatNode ? normalizeWhitespace(caveatNode.textContent || '') : '';
|
||||
|
||||
if (!caveatNode) {
|
||||
return {
|
||||
description: extractCellText(cell),
|
||||
caveat: ''
|
||||
};
|
||||
}
|
||||
|
||||
const clone = cell.cloneNode(true);
|
||||
const cloneCaveatNode = clone.querySelector('tt');
|
||||
if (cloneCaveatNode) {
|
||||
cloneCaveatNode.remove();
|
||||
}
|
||||
|
||||
let description = extractCellText(clone);
|
||||
description = description.replace(/^\(\s*\)\s*/, '').trim();
|
||||
|
||||
return {
|
||||
description,
|
||||
caveat
|
||||
};
|
||||
}
|
||||
|
||||
function extractCellText(cell) {
|
||||
const clone = cell.cloneNode(true);
|
||||
const nestedTables = Array.from(clone.querySelectorAll('table'));
|
||||
const markdownTables = nestedTables
|
||||
.map(table => convertHtmlTableToMarkdown(table))
|
||||
.filter(Boolean);
|
||||
|
||||
nestedTables.forEach(table => table.remove());
|
||||
|
||||
const blockLikeNodes = clone.querySelectorAll('div, p, li, pre, code');
|
||||
let mainText = '';
|
||||
|
||||
if (blockLikeNodes.length > 0) {
|
||||
const parts = [];
|
||||
blockLikeNodes.forEach(node => {
|
||||
const text = normalizeWhitespace(node.textContent || '');
|
||||
if (text) {
|
||||
parts.push(text);
|
||||
}
|
||||
});
|
||||
|
||||
if (parts.length > 0) {
|
||||
mainText = parts.join('\n\n');
|
||||
}
|
||||
}
|
||||
|
||||
if (!mainText) {
|
||||
const withLineBreaks = (clone.innerHTML || '')
|
||||
.replace(/<br\s*\/?>/gi, '\n')
|
||||
.replace(/<[^>]+>/g, ' ');
|
||||
|
||||
mainText = normalizeWhitespace(withLineBreaks).replace(/\s*\n\s*/g, '\n').trim();
|
||||
}
|
||||
|
||||
if (markdownTables.length === 0) {
|
||||
return mainText;
|
||||
}
|
||||
|
||||
if (!mainText) {
|
||||
return markdownTables.join('\n\n');
|
||||
}
|
||||
|
||||
return [mainText, ...markdownTables].join('\n\n');
|
||||
}
|
||||
|
||||
function convertHtmlTableToMarkdown(table) {
|
||||
const rows = Array.from(table.querySelectorAll('tr'))
|
||||
.map(row => Array.from(row.querySelectorAll('th, td')))
|
||||
.filter(cells => cells.length > 0);
|
||||
|
||||
if (rows.length === 0) {
|
||||
return '';
|
||||
}
|
||||
|
||||
const headerCells = rows[0].map(cell => sanitizeTableCellText(cell.textContent || ''));
|
||||
const columnCount = headerCells.length;
|
||||
|
||||
const lines = [];
|
||||
lines.push(`| ${headerCells.join(' | ')} |`);
|
||||
lines.push(`| ${Array(columnCount).fill('---').join(' | ')} |`);
|
||||
|
||||
rows.slice(1).forEach(cells => {
|
||||
const values = cells.map(cell => sanitizeTableCellText(cell.textContent || ''));
|
||||
while (values.length < columnCount) {
|
||||
values.push('');
|
||||
}
|
||||
|
||||
lines.push(`| ${values.slice(0, columnCount).join(' | ')} |`);
|
||||
});
|
||||
|
||||
return lines.join('\n');
|
||||
}
|
||||
|
||||
function sanitizeTableCellText(text) {
|
||||
return normalizeWhitespace(text).replace(/\|/g, '\\|');
|
||||
}
|
||||
|
||||
function extractCellTextLegacy(cell) {
|
||||
const withLineBreaks = (cell.innerHTML || '')
|
||||
.replace(/<br\s*\/?>/gi, '\n')
|
||||
.replace(/<[^>]+>/g, ' ');
|
||||
|
||||
return normalizeWhitespace(withLineBreaks).replace(/\s*\n\s*/g, '\n').trim();
|
||||
}
|
||||
|
||||
function parseIssuesFromLinePairs(rawText) {
|
||||
const lines = rawText
|
||||
.split(/\r?\n/)
|
||||
.map(line => line.trim())
|
||||
.filter(Boolean);
|
||||
|
||||
const issues = [];
|
||||
|
||||
for (let i = 0; i < lines.length; i += 2) {
|
||||
if (i + 1 >= lines.length) {
|
||||
continue;
|
||||
}
|
||||
|
||||
const issueIdMatch = lines[i].match(/\b([A-Z]{2,6}-\d{4,8})\b/i);
|
||||
if (!issueIdMatch) {
|
||||
continue;
|
||||
}
|
||||
|
||||
issues.push({
|
||||
id: issueIdMatch[1].toUpperCase(),
|
||||
description: lines[i + 1]
|
||||
});
|
||||
}
|
||||
|
||||
return issues;
|
||||
}
|
||||
|
||||
function normalizeWhitespace(value) {
|
||||
return value.replace(/\s+/g, ' ').trim();
|
||||
}
|
||||
|
||||
function setParseStatus(message, isError = false) {
|
||||
const status = document.getElementById('parseStatus');
|
||||
status.textContent = message;
|
||||
status.style.color = isError ? '#b00020' : '#333';
|
||||
}
|
||||
|
||||
function copyToClipboard(event) {
|
||||
const markdownOutput = document.getElementById('markdownOutput');
|
||||
if (!markdownOutput.value) {
|
||||
setParseStatus('Nothing to copy yet.', true);
|
||||
return;
|
||||
}
|
||||
|
||||
navigator.clipboard.writeText(markdownOutput.value)
|
||||
.then(() => {
|
||||
const button = event && event.target ? event.target : null;
|
||||
if (!button) {
|
||||
setParseStatus('Copied to clipboard.');
|
||||
return;
|
||||
}
|
||||
|
||||
const originalText = button.textContent;
|
||||
button.textContent = 'Copied!';
|
||||
setTimeout(() => {
|
||||
button.textContent = originalText;
|
||||
}, 1200);
|
||||
})
|
||||
.catch(() => {
|
||||
setParseStatus('Clipboard copy failed. Copy manually from preview.', true);
|
||||
});
|
||||
}
|
||||
|
||||
function clearForm() {
|
||||
document.getElementById('productSelect').value = '';
|
||||
document.getElementById('issueTypeSelect').value = '';
|
||||
document.getElementById('versionInput').value = '';
|
||||
document.getElementById('issuesInput').value = '';
|
||||
document.getElementById('markdownOutput').value = '';
|
||||
resetDownloadLink();
|
||||
setParseStatus('');
|
||||
clearPersistedFormState();
|
||||
}
|
||||
|
||||
function persistFormState() {
|
||||
const formState = {
|
||||
product: document.getElementById('productSelect').value || '',
|
||||
issueType: document.getElementById('issueTypeSelect').value || '',
|
||||
version: document.getElementById('versionInput').value || ''
|
||||
};
|
||||
|
||||
try {
|
||||
localStorage.setItem(PROCESS_FORM_STATE_KEY, JSON.stringify(formState));
|
||||
} catch (error) {
|
||||
console.warn('Could not persist process form state:', error);
|
||||
}
|
||||
}
|
||||
|
||||
function restoreFormState() {
|
||||
try {
|
||||
const raw = localStorage.getItem(PROCESS_FORM_STATE_KEY);
|
||||
if (!raw) {
|
||||
return;
|
||||
}
|
||||
|
||||
const parsed = JSON.parse(raw);
|
||||
if (!parsed || typeof parsed !== 'object') {
|
||||
return;
|
||||
}
|
||||
|
||||
const productSelect = document.getElementById('productSelect');
|
||||
const issueTypeSelect = document.getElementById('issueTypeSelect');
|
||||
const versionInput = document.getElementById('versionInput');
|
||||
|
||||
if (typeof parsed.issueType === 'string') {
|
||||
issueTypeSelect.value = parsed.issueType;
|
||||
}
|
||||
|
||||
if (typeof parsed.version === 'string') {
|
||||
versionInput.value = parsed.version;
|
||||
}
|
||||
|
||||
if (typeof parsed.product === 'string' && productSelect.options.length > 1) {
|
||||
const optionExists = Array.from(productSelect.options).some(option => option.value === parsed.product);
|
||||
if (optionExists) {
|
||||
productSelect.value = parsed.product;
|
||||
}
|
||||
}
|
||||
} catch (error) {
|
||||
console.warn('Could not restore process form state:', error);
|
||||
}
|
||||
}
|
||||
|
||||
function applyPersistedProductSelection() {
|
||||
try {
|
||||
const raw = localStorage.getItem(PROCESS_FORM_STATE_KEY);
|
||||
if (!raw) {
|
||||
return;
|
||||
}
|
||||
|
||||
const parsed = JSON.parse(raw);
|
||||
if (!parsed || typeof parsed.product !== 'string') {
|
||||
return;
|
||||
}
|
||||
|
||||
const productSelect = document.getElementById('productSelect');
|
||||
const optionExists = Array.from(productSelect.options).some(option => option.value === parsed.product);
|
||||
if (optionExists) {
|
||||
productSelect.value = parsed.product;
|
||||
}
|
||||
} catch (error) {
|
||||
console.warn('Could not apply persisted product selection:', error);
|
||||
}
|
||||
}
|
||||
|
||||
function clearPersistedFormState() {
|
||||
try {
|
||||
localStorage.removeItem(PROCESS_FORM_STATE_KEY);
|
||||
} catch (error) {
|
||||
console.warn('Could not clear process form state:', error);
|
||||
}
|
||||
}
|
||||
|
||||
function updateDownloadLink(markdownText, version) {
|
||||
const link = document.getElementById('downloadMarkdownLink');
|
||||
resetDownloadLink();
|
||||
|
||||
const blob = new Blob([markdownText], { type: 'text/markdown;charset=utf-8' });
|
||||
const url = URL.createObjectURL(blob);
|
||||
activeDownloadUrl = url;
|
||||
|
||||
const dateStamp = new Date().toISOString().slice(0, 10);
|
||||
const safeVersion = String(version || 'version').replace(/[^a-zA-Z0-9.-]/g, '-');
|
||||
|
||||
link.href = url;
|
||||
link.download = `${safeVersion}_${dateStamp}.md`;
|
||||
link.style.pointerEvents = 'auto';
|
||||
link.style.opacity = '1';
|
||||
}
|
||||
|
||||
function resetDownloadLink() {
|
||||
const link = document.getElementById('downloadMarkdownLink');
|
||||
|
||||
if (activeDownloadUrl) {
|
||||
URL.revokeObjectURL(activeDownloadUrl);
|
||||
activeDownloadUrl = null;
|
||||
}
|
||||
|
||||
link.href = '#';
|
||||
link.style.pointerEvents = 'none';
|
||||
link.style.opacity = '0.6';
|
||||
}
|
||||
|
||||
window.generateJSON = generateJSON;
|
||||
window.copyToClipboard = copyToClipboard;
|
||||
window.clearForm = clearForm;
|
||||
@@ -0,0 +1,113 @@
|
||||
{
|
||||
"PAN-OS": {
|
||||
"12": {
|
||||
"12.2": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
},
|
||||
"12.1": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
}
|
||||
},
|
||||
"11": {
|
||||
"11.2": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
},
|
||||
"11.1": {
|
||||
"addressed": [
|
||||
"11.1.0_2026-03-13.md",
|
||||
"11.1.0-h1_2026-03-13.md",
|
||||
"11.1.6_2026-03-13.md",
|
||||
"11.1.6-h1_2026-03-13.md",
|
||||
"11.1.6-h3_2026-03-13.md",
|
||||
"11.1.6-h4_2026-03-13.md",
|
||||
"11.1.6-h5_2026-03-13.md",
|
||||
"11.1.6-h6_2026-03-13.md",
|
||||
"11.1.6-h7_2026-03-13.md",
|
||||
"11.1.6-h10_2026-03-13.md",
|
||||
"11.1.6-h14_2026-03-13.md",
|
||||
"11.1.6-h17_2026-03-13.md",
|
||||
"11.1.6-h19_2026-03-13.md",
|
||||
"11.1.6-h20_2026-03-13.md",
|
||||
"11.1.6-h21_2026-03-13.md",
|
||||
"11.1.6-h22_2026-03-13.md",
|
||||
"11.1.6-h23_2026-03-13.md",
|
||||
"11.1.6-h25_2026-03-13.md",
|
||||
"11.1.7_2026-03-13.md",
|
||||
"11.1.7-h1_2026-03-13.md",
|
||||
"11.1.7-h2_2026-03-13.md",
|
||||
"11.1.7-h4_2026-03-13.md",
|
||||
"11.1.8_2026-03-13.md",
|
||||
"11.1.9_2026-03-13.md",
|
||||
"11.1.10_2026-03-13.md",
|
||||
"11.1.10-h1_2026-03-13.md",
|
||||
"11.1.10-h4_2026-03-13.md",
|
||||
"11.1.10-h5_2026-03-13.md",
|
||||
"11.1.10-h7_2026-03-13.md",
|
||||
"11.1.10-h9_2026-03-13.md",
|
||||
"11.1.10-h10_2026-03-13.md",
|
||||
"11.1.10-h12_2026-03-13.md",
|
||||
"11.1.11_2026-03-13.md",
|
||||
"11.1.12_2026-03-13.md",
|
||||
"11.1.13_2026-03-13.md",
|
||||
"11.1.13-h1_2026-03-13.md",
|
||||
"11.1.13-h2_2026-03-13.md"
|
||||
],
|
||||
"known": [
|
||||
"11.1.11_2026-03-13.md"
|
||||
]
|
||||
}
|
||||
},
|
||||
"10": {
|
||||
"10.2": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
},
|
||||
"10.1": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
}
|
||||
}
|
||||
},
|
||||
"GlobalProtect": {
|
||||
"6": {
|
||||
"6.4": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
},
|
||||
"6.3": {
|
||||
"addressed": [
|
||||
"6.3.1_2026-03-13.md",
|
||||
"6.3.2_2026-03-13.md",
|
||||
"6.3.3_2026-03-13.md",
|
||||
"6.3.3-h1_2026-03-13.md"
|
||||
],
|
||||
"known": [
|
||||
"6.3.3_2026-03-12.json"
|
||||
]
|
||||
},
|
||||
"6.2": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
},
|
||||
"6.1": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
},
|
||||
"6.0": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
}
|
||||
},
|
||||
"5": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
}
|
||||
},
|
||||
"GlobalProtect-Linux": {
|
||||
"addressed": [],
|
||||
"known": []
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,94 @@
|
||||
import { loadIssuesForCheckedPaths } from './js/issues.js';
|
||||
import { getCheckedFileRefs, initializeTree, renderProductTree } from './js/tree.js';
|
||||
import { applyIssueSearchFilter, getIssueTypeFilters, initializeUI } from './js/ui.js';
|
||||
|
||||
document.addEventListener('DOMContentLoaded', () => {
|
||||
initializeUI({ onSelectionChange: refreshIssuesForCurrentSelection });
|
||||
initializeTree('product-tree', refreshIssuesForCurrentSelection);
|
||||
loadProductTree();
|
||||
});
|
||||
|
||||
let productsData = {};
|
||||
|
||||
function refreshIssuesForCurrentSelection() {
|
||||
loadIssuesForCheckedPaths({
|
||||
issueTypeFilters: getIssueTypeFilters(),
|
||||
checkedFileRefs: getCheckedFileRefs(),
|
||||
applyIssueSearchFilter
|
||||
});
|
||||
}
|
||||
|
||||
function loadProductTree() {
|
||||
fetch('products.json')
|
||||
.then(response => response.json())
|
||||
.then(data => {
|
||||
productsData = expandFilePrefixLevel(data);
|
||||
renderProductTree(productsData);
|
||||
})
|
||||
.catch(error => console.error('Error loading products:', error));
|
||||
}
|
||||
|
||||
function expandFilePrefixLevel(root) {
|
||||
if (!root || typeof root !== 'object') {
|
||||
return root;
|
||||
}
|
||||
|
||||
return transformNode(root);
|
||||
}
|
||||
|
||||
function transformNode(node) {
|
||||
if (!node || typeof node !== 'object' || Array.isArray(node)) {
|
||||
return node;
|
||||
}
|
||||
|
||||
const hasIssueArrays = Object.prototype.hasOwnProperty.call(node, 'addressed') ||
|
||||
Object.prototype.hasOwnProperty.call(node, 'known');
|
||||
|
||||
if (hasIssueArrays) {
|
||||
const addressed = Array.isArray(node.addressed) ? node.addressed : [];
|
||||
const known = Array.isArray(node.known) ? node.known : [];
|
||||
const allFiles = [...addressed, ...known];
|
||||
|
||||
if (allFiles.length === 0) {
|
||||
return {
|
||||
addressed: [],
|
||||
known: []
|
||||
};
|
||||
}
|
||||
|
||||
const grouped = {};
|
||||
|
||||
addressed.forEach(fileName => {
|
||||
const prefix = getFilePrefix(fileName);
|
||||
if (!grouped[prefix]) {
|
||||
grouped[prefix] = { addressed: [], known: [] };
|
||||
}
|
||||
grouped[prefix].addressed.push(fileName);
|
||||
});
|
||||
|
||||
known.forEach(fileName => {
|
||||
const prefix = getFilePrefix(fileName);
|
||||
if (!grouped[prefix]) {
|
||||
grouped[prefix] = { addressed: [], known: [] };
|
||||
}
|
||||
grouped[prefix].known.push(fileName);
|
||||
});
|
||||
|
||||
return grouped;
|
||||
}
|
||||
|
||||
const transformed = {};
|
||||
Object.keys(node).forEach(key => {
|
||||
transformed[key] = transformNode(node[key]);
|
||||
});
|
||||
return transformed;
|
||||
}
|
||||
|
||||
function getFilePrefix(fileName) {
|
||||
const baseName = String(fileName || '');
|
||||
const underscoreIndex = baseName.indexOf('_');
|
||||
if (underscoreIndex <= 0) {
|
||||
return baseName.replace(/\.json$/i, '') || 'unknown';
|
||||
}
|
||||
return baseName.slice(0, underscoreIndex);
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
{
|
||||
"reddit": {
|
||||
"display": "Reddit",
|
||||
"entries": [
|
||||
{
|
||||
"id": "PAN-290235",
|
||||
"url": "https://www.reddit.com/r/paloaltonetworks/comments/1qi7zoy/pan290235_dscd_and_low_quality_control/"
|
||||
}
|
||||
]
|
||||
},
|
||||
"facebook": {
|
||||
"display": "Facebook",
|
||||
"entries": []
|
||||
},
|
||||
"twitter": {
|
||||
"display": "Twitter",
|
||||
"entries": []
|
||||
},
|
||||
"other_web": {
|
||||
"display": "Other Web",
|
||||
"entries": []
|
||||
}
|
||||
}
|
||||
+242
@@ -0,0 +1,242 @@
|
||||
* {
|
||||
box-sizing: border-box;
|
||||
}
|
||||
|
||||
body {
|
||||
font-family: Arial, sans-serif;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
header {
|
||||
background-color: #2c3e50;
|
||||
color: white;
|
||||
padding: 20px;
|
||||
box-shadow: 0 2px 4px rgba(0, 0, 0, 0.1);
|
||||
}
|
||||
|
||||
h1 {
|
||||
margin: 0;
|
||||
}
|
||||
|
||||
h2 {
|
||||
color: #333;
|
||||
}
|
||||
|
||||
.container {
|
||||
display: flex;
|
||||
gap: 20px;
|
||||
padding: 20px;
|
||||
max-width: 1400px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
.sidebar {
|
||||
flex: 0 0 250px;
|
||||
background-color: #f8f9fa;
|
||||
border: 1px solid #ddd;
|
||||
border-radius: 4px;
|
||||
padding: 15px;
|
||||
height: fit-content;
|
||||
overflow-y: auto;
|
||||
}
|
||||
|
||||
.sidebar h2 {
|
||||
margin: 0 0 15px 0;
|
||||
font-size: 18px;
|
||||
}
|
||||
|
||||
.issue-search {
|
||||
width: 100%;
|
||||
margin-bottom: 12px;
|
||||
padding: 6px 8px;
|
||||
border: 1px solid #c8c8c8;
|
||||
border-radius: 4px;
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
.issue-search:focus {
|
||||
outline: 2px solid #9ec5fe;
|
||||
outline-offset: 1px;
|
||||
border-color: #6ea8fe;
|
||||
}
|
||||
|
||||
.issue-filters {
|
||||
display: flex;
|
||||
gap: 10px;
|
||||
margin-bottom: 10px;
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
.issue-filters label {
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
gap: 4px;
|
||||
cursor: pointer;
|
||||
user-select: none;
|
||||
}
|
||||
|
||||
.issue-filters input[type="checkbox"] {
|
||||
width: 14px;
|
||||
height: 14px;
|
||||
margin: 0;
|
||||
}
|
||||
|
||||
.content {
|
||||
flex: 1;
|
||||
min-width: 0;
|
||||
}
|
||||
|
||||
#product-tree {
|
||||
font-size: 14px;
|
||||
line-height: 1.4;
|
||||
}
|
||||
|
||||
.tree-item {
|
||||
margin: 1px 0;
|
||||
}
|
||||
|
||||
.tree-item > label {
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
padding: 2px 0;
|
||||
}
|
||||
|
||||
/* Keep label text aligned whether or not a node has a toggle icon. */
|
||||
.tree-item:not(.parent) > label {
|
||||
margin-left: 18px;
|
||||
}
|
||||
|
||||
.tree-item.parent > label {
|
||||
font-weight: 500;
|
||||
}
|
||||
|
||||
.tree-toggle {
|
||||
cursor: pointer;
|
||||
user-select: none;
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
width: 16px;
|
||||
height: 1.4em;
|
||||
margin-right: 2px;
|
||||
flex-shrink: 0;
|
||||
vertical-align: middle;
|
||||
}
|
||||
|
||||
.tree-children {
|
||||
margin-left: 16px;
|
||||
max-height: 1000px;
|
||||
overflow: hidden;
|
||||
transition: max-height 0.3s ease, opacity 0.3s ease;
|
||||
opacity: 1;
|
||||
}
|
||||
|
||||
.tree-children .tree-children {
|
||||
margin-left: 33px;
|
||||
}
|
||||
|
||||
.tree-children.collapsed {
|
||||
max-height: 0;
|
||||
opacity: 0;
|
||||
overflow: hidden;
|
||||
}
|
||||
|
||||
.tree-item input[type="checkbox"] {
|
||||
cursor: pointer;
|
||||
margin-right: 4px;
|
||||
flex-shrink: 0;
|
||||
width: 16px;
|
||||
height: 16px;
|
||||
}
|
||||
|
||||
.tree-item input[type="checkbox"]:indeterminate {
|
||||
accent-color: #f39c12;
|
||||
}
|
||||
|
||||
.tree-item label {
|
||||
cursor: pointer;
|
||||
user-select: none;
|
||||
}
|
||||
|
||||
.tree-item label:hover {
|
||||
color: #2c3e50;
|
||||
}
|
||||
|
||||
#issues {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
gap: 30px;
|
||||
}
|
||||
|
||||
#issues h2 {
|
||||
margin: 0 0 10px 0;
|
||||
border-bottom: 2px solid #2c3e50;
|
||||
padding-bottom: 8px;
|
||||
}
|
||||
|
||||
.issue-count {
|
||||
color: #5b6b7a;
|
||||
font-weight: 500;
|
||||
font-size: 0.9em;
|
||||
}
|
||||
|
||||
ul {
|
||||
list-style-type: none;
|
||||
padding: 0;
|
||||
margin: 0;
|
||||
}
|
||||
|
||||
#addressed-issues {
|
||||
overflow-x: auto;
|
||||
}
|
||||
|
||||
.issues-table {
|
||||
width: 100%;
|
||||
border-collapse: collapse;
|
||||
border: 1px solid #ddd;
|
||||
background-color: #fff;
|
||||
font-size: 14px;
|
||||
}
|
||||
|
||||
.issues-table th,
|
||||
.issues-table td {
|
||||
border: 1px solid #ddd;
|
||||
padding: 8px 10px;
|
||||
text-align: left;
|
||||
vertical-align: top;
|
||||
}
|
||||
|
||||
.issues-table th {
|
||||
background-color: #eef3f7;
|
||||
color: #22313f;
|
||||
position: sticky;
|
||||
top: 0;
|
||||
z-index: 1;
|
||||
}
|
||||
|
||||
.issues-table tbody tr:hover {
|
||||
background-color: #f7fbff;
|
||||
}
|
||||
|
||||
.issues-table .issue-id-col {
|
||||
width: 160px;
|
||||
white-space: nowrap;
|
||||
font-weight: 600;
|
||||
}
|
||||
|
||||
.issues-table .issue-version-col {
|
||||
width: 180px;
|
||||
}
|
||||
|
||||
li {
|
||||
padding: 10px;
|
||||
border: 1px solid #ddd;
|
||||
margin: 5px 0;
|
||||
border-radius: 4px;
|
||||
background-color: #fafafa;
|
||||
}
|
||||
|
||||
li:hover {
|
||||
background-color: #f0f0f0;
|
||||
}
|
||||
Reference in New Issue
Block a user