diff --git a/reference/PAN-OS/addressed/10.2.0-h1.html b/reference/PAN-OS/addressed/10.2.0-h1.html new file mode 100644 index 0000000..ba64293 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.0-h1.html @@ -0,0 +1,37 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-190311
+ |
+
+
+ (PA-220 and PA-220R firewalls and PA-800 Series firewalls only) Fixed an issue where management connectivity to the firewall was
+ lost due to the expiration of the DHCP lease, which caused the IP
+ configuration on the management port to be purged in PAN-OS 10.2.0. To
+ upgrade, download PAN-OS 10.2.0 (no installation), then download and
+ install PAN-OS 10.2.0-h1.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-237871
+ |
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ PAN-202450
+ |
+
+
+ Fixed an issue where the
+ device-client-cert was set to
+ expire on December 31, 2023. With this fix, the expiration date has
+ been extended.
+
+ |
+
|
+ PAN-198372
+ |
+
+
+ Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+
+ PAN-231823
+
+ |
+
+
+ A fix was made to address
+ CVE-2024-5916.
+
+ |
+
|
+ PAN-186143
+ |
+
+
+ Fixed an issue where no local changes could be made on a ZTP-enabled
+ device after an upgrade to PAN-OS 10.1.x.
+
+ |
+
|
+ PAN-182634
+ |
+
+
+ (PA-400 series firewalls only) Fixed an issue
+ where the firewall detected a Power Supply Unit (PSU) failure for the
+ opposite side when disconnecting a PSU from the device. This issue
+ occurred when redundant PSUs were connected.
+
+ |
+
|
+ PAN-178165
+ |
+
+
+ Fixed an issue where the CLI command
+ set system setting ctd ctd-agent-assigned-cores 0
+ to change assigned cores for the ctd-agent failed.
+
+ |
+
|
+ PAN-175950
+ |
+
+
+ Fixed an issue where IoT Security (without
+ Strata Logging Service) onboarding failed.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-239241
+ |
+
+
+ Extended the root certificate for WildFire appliances to December 31,
+ 2032.
+
+ |
+
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-237871
+ |
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ PAN-202450
+ |
+
+
+ Fixed an issue where the
+ device-client-cert was set to
+ expire on December 31, 2023. With this fix, the expiration date has
+ been extended.
+
+ |
+
|
+ PAN-198372
+ |
+
+
+ Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WIF-495
+ |
+
+
+ Fixed an issue on Panorama where edits made to an existing data
+ filtering profile resulted in matching traffic not being detected by
+ Enterprise DLP.
+
+ |
+
|
+
+ PAN-231823
+
+ |
+
+
+ A fix was made to address
+ CVE-2024-5916.
+
+ |
+
|
+ PAN-190311
+ |
+
+
+ (PA-220 and PA-220R firewalls and PA-800 Series firewalls only) Fixed an issue where management connectivity to the firewall was
+ lost due to the expiration of the DHCP lease, which caused the IP
+ configuration on the management port to be purged in PAN-OS 10.2.0. To
+ upgrade, download PAN-OS 10.2.0 (no installation), then download and
+ install PAN-OS 10.2.0-h1.
+
+ |
+
|
+ PAN-190175 and PAN-190223
+ |
+
+
+ A fix was made to address an OpenSSL infinite loop vulnerability in
+ the PAN-OS software (CVE-2022-0778).
+
+ |
+
|
+ PAN-189665
+ |
+
+
+ (FIPS-CC enabled firewalls only) Fixed an issue
+ where the firewall was unable to connect to log collectors after an
+ upgrade due to missing cipher suites.
+
+ |
+
|
+ PAN-189565
+ |
+
+
+ Fixed an issue after upgrading to PAN-OS 10.2 where the
+ tund
+ process stopped responding on multiple GlobalProtect clients.
+
+ |
+
|
+ PAN-189468
+ |
+
+
+ Fixed an issue where the firewall onboard packet processor used by the
+ PAN-OS content-inspection (CTD) engine can generate high dataplane
+ resource usage when overwhelmed by a session with an unusually high
+ number of packets. This can result in
+ resource-unavailable messages due
+ to the content inspection queue filling up. Factors related to the
+ likelihood of an occurrence include enablement of content-inspection
+ based features that are configured in such a way that might process
+ thousands of packets in rapid succession (such as SMB file transfers).
+ This can cause poor performance for the affected session and other
+ sessions using the same packet processor. PA-3000 series and VM-Series
+ firewalls are not impacted.
+
+ |
+
|
+ PAN-189361
+ |
+
+
+ Fixed an issue where Panorama was unable to distribute antivirus
+ signature updates to firewalls with an Advanced Threat Prevention
+ license only.
+
+ |
+
|
+ PAN-189298
+ |
+
+
+ Fixed an issue where existing traffic sessions were not synced after
+ restarting the active dataplane when it became passive.
+
+ |
+
|
+ PAN-189230
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue that
+ caused the
+ pan_task
+ process to stop responding with floating point exception (FPE) when
+ there was a module of 0 on the queue number.
+
+ |
+
|
+ PAN-189214
+ |
+
+
+ Fixed an issue that prevented antivirus signature update packages that
+ are normally available to install from displaying properly on the
+ firewall when the Advanced Threat Prevention license is present on a
+ firewall without a Threat Prevention license.
+
+ |
+
|
+ PAN-189206
+ |
+
+
+ Fixed an issue where Device Group and Template administrator roles
+ didn't support a context switch between the Panorama and firewall web
+ interfaces.
+
+ |
+
|
+ PAN-189106
+ |
+
+
+ Fixed an issue on Panorama where you were unable to successfully
+ downgrade to a PAN-OS 10.1 release unless you uninstalled the ZTP
+ Plugin 2.0.
+
+ |
+
|
+ PAN-189094
+ |
+
+
+ Fixed an issue where, after upgrading a CN-Series firewall from a
+ PAN-OS 10.1 release to PAN-OS 10.2.0, show session commands did not
+ return output.
+
+ |
+
|
+ PAN-189032
+ |
+
+
+ Fixed an issue where, when Advanced Routing was enabled on the
+ firewall, an OSPFv3 interface configured with the p2mp link type
+ caused commits to fail.
+
+ |
+
|
+ PAN-188956
+ |
+
+
+ Fixed an issue where, after a successful upgrade to PAN-OS 10.2,
+ logging into the firewall or Panorama web interface from the same
+ internet browser window or session from which the firewall or Panorama
+ was upgraded did not work.
+
+ |
+
|
+ PAN-188883
+ |
+
+
+ Fixed an issue where, when pre-generated license key files were
+ manually uploaded via the web interface, they weren't properly
+ recognized by PAN-OS and didn't display a serial number or initiate a
+ reboot.
+
+ |
+
|
+ PAN-188828
+ |
+
+
+ Fixed an intermittent issue where web pages and web page contents did
+ not properly load when cloud inline categorization was enabled.
+
+ |
+
|
+ PAN-188009
+ |
+
+
+ Fixed an issue where a firewall import to Panorama running a PAN-OS
+ 10.1 release or a PAN-OS 10.2 release resulted in corrupted private
+ information when the master key was not used.
+
+ |
+
|
+ PAN-187846
+ |
+
+
+ Fixed an issue on Panorama where a selective push pushed an incorrect
+ configuration to the managed firewalls, which caused the firewalls to
+ display as out of sync. This issue occurred if the Panorama-pushed
+ version for the
+ Shared Policy and Template
+ configuration were 20 or more versions older than the current local
+ running configuration on Panorama.
+
+ |
+
|
+ PAN-187769
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed a Data Plane Development Kit (DPDK) issue where interfaces
+ remained in a link-down state after an Azure hot plug event. This
+ issue occurred due to a hot plug of Accelerated Networking interfaces
+ on the Azure backend caused by host updates, which led to Virtual
+ Function unregister/Register messages on the VM side.
+
+ |
+
|
+ PAN-186886
+ |
+
+
+ Fixed an issue where individual configuration objects were not
+ viewable after committing selective configuration changes on a
+ multi-vsys firewall.
+
+ |
+
|
+ PAN-186785
+ |
+
+
+ Fixed an issue where, after logging in, Panorama displayed a 500 error
+ page after five minutes of logging for dynamic group template admin
+ types with access to approximately 115 managed devices or 120 dynamic
+ groups.
+
+ |
+
|
+ PAN-186516
+ |
+
+
+ Fixed an issue where log queries that included WildFire submission
+ logs returned more slowly than expected.
+
+ |
+
|
+ PAN-186487
+ |
+
+
+ Fixed an issue with snmpd.log overflow caused by continuous hourly
+ repeating errors.
+
+ |
+
|
+ PAN-186402
+ |
+
+
+ (PA-440 Series firewalls only) Fixed an issue
+ where the firewall's maximum tunnel limit was incorrect.
+
+ |
+
|
+ PAN-186137
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall management interface incorrectly displayed 10G port
+ speed as an option even though 10G speed is not supported and can't be
+ configured.
+
+ |
+
|
+ PAN-185616
+ |
+
+
+ Fixed an issue where the firewall sent fewer logs to the system log
+ server than expected. With this fix, the firewall accommodates a
+ larger send queue for syslog forwarding to TCP syslog receivers.
+
+ |
+
|
+ PAN-185164
+ |
+
+
+ Fixed an issue where processing corrupted IoT messages caused the
+ wificlient process to restart.
+
+ |
+
|
+ PAN-184224
+ |
+
+
+ Fixed an issue on Panorama where you were unable to select a template
+ variable in
+ Templates > Device > Log Forwarding Card > Log Forwarding
+ Card Interface > Network > IP address location.
+
+ |
+
|
+ PAN-183826
+ |
+
+
+ Fixed an issue where, after clicking
+ WildFire Analysis Report, the web
+ interface failed to display the report with the following error
+ message: refused to connect.
+
+ |
+
|
+ PAN-183567
+ |
+
+
+ Fixed an issue on Panorama where ZTP Plugin 2.0 was not available for
+ download before upgrading Panorama to PAN-OS 10.2.
+
+ |
+
|
+ PAN-182492
+ |
+
+
+ Fixed an issue where the WildFire analysis report was not viewable
+ from the firewall WildFire submission log entry page.
+
+ |
+
|
+ PAN-181839
+ |
+
+
+ Fixed an issue where Panorama Global Search reported
+ No Matches found while still
+ returning results for matching entries on large configurations.
+
+ |
+
|
+ PAN-181039
+ |
+
+
+ Fixed an issue with DNS cache depletion that caused continuous DNS
+ retries.
+
+ |
+
|
+ PAN-181031
+ |
+
+
+ Fixed an issue where the CN-NGFW (DP) folder on the CN-MGMT pod
+ eventually consumed a large amount of space in the /var/log/pan
+ because the old registered stale next-generation firewall logs were
+ not being cleared.
+
+ |
+
|
+ PAN-180338
+ |
+
+
+ Fixed an issue where the CTD loop count wasn't accurately incremented.
+
+ |
+
|
+ PAN-180095
+ |
+
+
+ Fixed an issue where Panorama serial-number-based redistribution
+ agents did not redistribute HIP reports.
+
+ |
+
|
+ PAN-179966
+ |
+
+
+ Fixed an issue where, after upgrading to a PAN-OS 8.1 release, the
+ port on the firewall stayed up, but the port on the connected device
+ reported down. This occurred because, on force mode, autoneg was
+ disabled by default. With this fix, autoneg is enabled by default on
+ force mode.
+
+ |
+
|
+ PAN-179420
+ |
+
+
+ Fixed an issue on Panorama where a selective push to managed firewalls
+ failed after renaming an existing device group, template, or template
+ stack that was already pushed to the managed firewalls and you
+ selectively committed specific configuration objects from the renamed
+ device group, template, or template stack.
+
+ |
+
|
+ PAN-179321
+ |
+
+
+ A validation error was added to inform an administrator when a policy
+ field contained the value any.
+
+ |
+
|
+ PAN-178195
+ |
+
+
+ Fixed an issue where the URL filtering logs generated by traffic
+ analyzed by Advanced URL filtering cloud inline categorization didn't
+ display the URL name.
+
+ |
+
|
+ PAN-177072
+ |
+
+
+ Fixed an intermittent issue where Panorama did not show new logs from
+ firewalls.
+
+ |
+
|
+ PAN-176889
+ |
+
+
+ Fixed an issue where the log collector continuously disconnected from
+ Panorama due to high latency and a high number of packets in Send-Q.
+
+ |
+
|
+ PAN-176693
+ |
+
+
+ (M-300 and M-700 appliances only) Fixed an
+ issue where the Activity (ACT) LEDs on the RJ-45 ports did not blink
+ when processing network traffic.
+
+ |
+
|
+ PAN-174607
+ |
+
+
+ Fixed an intermittent issue where, when Security profiles were
+ attached to a policy, files that were downloaded across TLS sessions
+ decrypted by the firewall were malformed.
+
+ |
+
|
+ PAN-145833
+ |
+
+
+ (PA-3200 Series firewalls only) Fixed an issue
+ where the firewall stopped recording dataplane diagnostic data in
+ dp-monitor.log after a few hours of uptime.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-195517
+ |
+
+
+ Fixed an issue where
+ CommitAll operations from Panorama
+ to Prisma Access device groups failed due to missing configuration
+ files.
+
+ |
+
|
+ PAN-194107
+ |
+
+
+ Fixed an issue where the expiry date for the Advanced Threat
+ Protection license was incorrect for BND3 payg VM-Series firewalls on
+ Amazon Web Services (AWS), Oracle Cloud Infrastructure (OCI), Google
+ Cloud Platform (GCP), and Microsoft Azure.
+
+ |
+
|
+ PAN-186075
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall rebooted after receiving large packets while in DPDK mode
+ on Azure virtual machines running CX4 (MLx5) drivers.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-192999
+ |
+
+
+ A fix was made to address
+ CVE-2022-0028.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237935
+ |
+
+
+ Extended the offline PAN-DB, Panorama, and WildFire certificates which
+ were previously set to expire on September 2, 2024.
+
+ |
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-237871
+ |
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ PAN-202450
+ |
+
+
+ Fixed an issue where the
+ device-client-cert was set to
+ expire on December 31, 2023. With this fix, the expiration date has
+ been extended.
+
+ |
+
|
+ PAN-198372
+ |
+
+
+ Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+
+ PAN-231823
+
+ |
+
+
+ A fix was made to address
+ CVE-2024-5916.
+
+ |
+
|
+ PAN-193579
+ |
+
+
+ Fixed an issue where new logs viewed from the CLI (show log
+ <log_type>) and new syslogs forwarded to a syslog server
+ contained additional, erroneous entries.
+
+ |
+
|
+ PAN-192930
+ |
+
+
+ Fixed an issue where, when the default port was not TCP/443,
+ implicitly used SSL applications were blocked by the Security policy
+ as an SSL application and did not shift to the correct application.
+
+ |
+
|
+ PAN-192880
+ |
+
+
+ Fixed an issue where, when the firewall was configured for jumbo
+ frames, an internal interface was not set with the correct MTU, which
+ caused byte frames larger than 1500 to be dropped when a DF bit was
+ set.
+
+ |
+
|
+ PAN-192725
+ |
+
+
+ Fixed an issue where the firewall failed to forward logs to Panorama
+ when configured with IPv6 addressing only.
+
+ |
+
|
+ PAN-192089
+ |
+
+
+ Fixed an issue on the web interface where the IPSec tunnel did not
+ gray out after disabling it.
+
+ |
+
|
+ PAN-191629
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the hourly summary log was limited to 100,001 lines when summarized,
+ which resulted in inconsistent report results when using summary logs.
+
+ |
+
|
+ PAN-191513
+ |
+
+
+ Fixed an issue on multi-vsys firewalls where the DLP cloud service
+ continued to exclude an application added to a shared application
+ group () from non-file traffic inspection. This issue occurred when the
+ application was removed from the application group or filter that was
+ added to the
+ App Exclusion List ().
+
+ |
+
|
+ PAN-191470
+ |
+
+
+ Fixed an issue on Panorama where encrypted passwords were sent to
+ firewalls on PAN-OS 10.1 releases during a multi-device group push,
+ which caused client-based External Dynamic Lists (EDL) to fail.
+
+ |
+
|
+ PAN-191466
+ |
+
+
+ Fixed an issue where you were unable to use the web interface to
+ override IPsec tunnels pushed from Panorama
+
+ |
+
|
+ PAN-191288
+ |
+
+
+ Fixed an issue where the firewall restarted due to a
+ dnsproxy
+ process crash.
+
+ |
+
|
+ PAN-190811
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ logs were forwarded through the management interface instead of the
+ configured log interface to be used for forwarding.
+
+ |
+
|
+ PAN-190675
+ |
+
+
+ Fixed an IoT cloud connectivity issue with the firewall dataplane when
+ the Data Services service route was
+ used and the egress interface had VLAN tagging.
+
+ |
+
|
+ PAN-190492
+ |
+
+
+ Fixed an issue where the Panorama log collector group level SSH
+ settings were not migrated to the new format when upgrading from a
+ PAN-OS 9.1 release to a PAN-OS 10.0 release.
+
+ |
+
|
+ PAN-189429
+ |
+
+
+ Fixed a memory leak that occurred when enabling XFF (x-forwarded-for)
+ logging in a Security policy.
+
+ |
+
|
+ PAN-189395
+ |
+
+
+ (PA-400 Series firewalls only) Fixed an issue
+ where running a PAN-OS 10.2 release caused dataplane processes to
+ restart unexpectedly.
+
+ |
+
|
+ PAN-189010
+ |
+
+
+ Fixed an issue on Panorama where a deadlock in the
+ configd
+ process caused both the web interface and the CLI to be inaccessible.
+
+ |
+
|
+ PAN-188872
+ |
+
+
+ Fixed an OOM condition caused by a memory leak issue on the
+ useridd
+ process.
+
+ |
+
|
+ PAN-188833
+ |
+
+
+ Fixed an issue where shared address objects used as a source or
+ destination in policies were cloned but not freed back after
+ configuration commits.
+
+ |
+
|
+ PAN-188097
+ |
+
+
+ Fixed an issue where the firewall stopped allocating new sessions with
+ increments in the counter session_alloc_failure. This was caused by
+ GPRS tunneling protocol (GTP-U) tunnel session aging processing issue.
+
+ |
+
|
+ PAN-187558
+ |
+
+
+ Fixed an issue where the following error message flooded the system
+ log:
+ Incremental update to DP failed.
+
+ |
+
|
+ PAN-187429
+ |
+
+
+ (PA-3400 Series firewalls and PA-5410, PA-5420, and PA-5430
+ firewalls only) Fixed an issue where the CLI and SNMP MIB walk did not display the
+ model and serial number of the fan tray and PSUs.
+
+ |
+
|
+ PAN-187151
+ |
+
+
+ Fixed an issue where tunnel-monitoring interface was incorrectly shown
+ as up instead of down.
+
+ |
+
|
+ PAN-186913
+ |
+
+
+ Fixed an issue on Panorama where
+ Validate Device Group () incorrectly issued a commit all operation instead of a validate all
+ operation. This issue occurred when multiple device groups were
+ included in the push.
+
+ |
+
|
+ PAN-186750
+ |
+
+
+ Fixed an issue where, after upgrading to a PAN-OS 10.1 release, SaaS
+ reports generated on Panorama did not display
+ Applications at a glance and most
+ charts were missing data on the right side of the chart.
+
+ |
+
|
+ PAN-185844
+ |
+
+
+ Fixed an issue where Decryption Log entries were associated with the
+ wrong Security policy rule.
+
+ |
+
|
+ PAN-185558
+ |
+
+
+ Fixed an issue where Panorama log migration failed when old logs
+ migrated to a newer format. This was due to older indices failing to
+ close.
+
+ |
+
|
+ PAN-184474
+ |
+
+
+ Fixed an issue where, when the firewall had Advanced Routing enabled,
+ a static route remained active after an interface went down.
+
+ |
+
|
+ PAN-183579
+ |
+
+
+ Fixed an issue where SD-WAN path monitoring failed over the interface
+ directly connected to the ISP due to an unsupported ICMP probe format.
+
+ |
+
|
+ PAN-183319
+ |
+
+
+ Fixed an issue on Panorama where commits remained at 99% due to
+ multiple firewalls sending out CSR singing requests every 10 minutes.
+
+ |
+
|
+ PAN-182087
+ |
+
+
+ Fixed an issue where commit failures occurred due to validity checks
+ performed against self-signing certificates not evaluating
+ Authentication Key Identifier and
+ Subject Key Identifier fields were
+ present.
+
+ |
+
|
+ PAN-180396
+ |
+
+
+ Fixed an issue where Panorama displayed an error when generating a
+ ticket to disable GlobalProtect for Prisma Access.
+
+ |
+
|
+ PAN-180147
+ |
+
+
+ Fixed an issue where the
+ bcm.log and
+ brdagent_stdout.log-<datestamp>
+ files filled up the root disk space.
+
+ |
+
|
+ PAN-178450
+ |
+
+
+ Fixed an issue where icons weren't displayed for clientless VPN
+ applications.
+
+ |
+
|
+ PAN-177671
+ |
+
+
+ Fixed an issue where, when SIP traffic traversing the firewall was
+ sent with a high Quality of Service (QoS) differentiated service code
+ (DSCP) value, the DSCP value was reset to the default setting (CS0)
+ for the first data packet.
+
+ |
+
|
+ PAN-177455
+ |
+
+
+ PA-7000 Series firewalls with HA clustering enabled and using HA4
+ communication links only) Fixed an issue where loading PAN-OS 10.2.0 on the firewall caused
+ the PA-7000 100G NPC (Network Processing Card) to go offline. As a
+ result, the firewall failed to boot normally and entered maintenance.
+
+ |
+
|
+ PAN-176156
+ |
+
+
+ Fixed an issue where executing the
+ show running resource-monitor with
+ the ingress-backlogs option
+ enabled displayed the error message `Dataplane is not up or invalid
+ target-dp(*.dp*)`.
+
+ |
+
|
+ PAN-174345
+ |
+
+
+ Fixed an issue where a process
+ all_pktproc
+ stopped responding after upgrading the firewall.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-205830
+ |
+
+
+ Fixed an issue with multi-vsys firewalls where custom applications and
+ shared objects pushed from Panorama did not populate in their
+ respective lists on the firewall.
+
+ |
+
|
+ PAN-205805
+ |
+ + Fixed an issue where Generic routing encapsulation (GRE) traffic was + only allowed in one direction when tunnel content inspection (TCI) was + enabled. + | +
|
+ PAN-205231
+ |
+
+
+ Fixed an issue where a commit operation remained at 55% for longer
+ than expected if more than 7,500 Security policy rules were
+ configured.
+
+ |
+
|
+ PAN-202795
+ |
+
+
+ Fixed an issue where file identification failed for files with minimal
+ data with large headers.
+
+ |
+
|
+ PAN-202535
+ |
+
+
+ Fixed an issue where the Device Telemetry configuration for a region
+ was unable to be set or edited via the web interface.
+
+ |
+
|
+ PAN-201872
+ |
+
+
+ Fixed an issue where SMB performance caused overall network latency
+ after an upgrade.
+
+ |
+
|
+ PAN-201714
+ |
+
+
+ Fixed an issue with GlobalProtect where attempting to authenticate
+ with the GlobalProtect gateway returned a 502 error code.
+
+ |
+
|
+ PAN-201357
+ |
+
+
+ The CLI command
+ debug dataplane set pow no-desched yes
+ was added to address an issue where the
+ all_pktproc
+ process stopped responding and caused traffic issues.
+
+ |
+
|
+ PAN-200946
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where GRE tunnels went down due to recursive routing when the passive
+ firewall was booting up. When the passive firewall became active and
+ no recursive routing was configured, the GRE tunnel remained down.
+
+ |
+
|
+ PAN-198718
+ |
+
+
+ (PA-5280 firewalls only) Fixed an issue where
+ memory allocation failures caused increased decryption failures.
+
+ |
+
|
+ PAN-196583
+ |
+
+
+ Fixed an issue where the Cisco TrustSEc plugin triggered a flood of
+ redundant register/unregister messages due to a failed IP address tag
+ database search.
+
+ |
+
|
+ PAN-195756
+ |
+
+
+ Fixed an issue that caused an API request timeout when parsing
+ requests using large header buffers.
+
+ |
+
|
+ PAN-195713
+ |
+
+
+ Fixed an issue where clientless VPN applications were not displayed in
+ the GlobalProtect portal page.
+
+ |
+
|
+ PAN-182732
+ |
+
+
+ Fixed an issue where the GlobalProtect gateway inactivity timer wasn't
+ refreshed even though traffic was passing through the tunnel.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-210513
+ |
+
+
+ Fixed an issue where Captive Portal authentication via SAML did not
+ work.
+
+ |
+
|
+ PAN-208737
+ |
+
+
+ Fixed an issue where domain information wasn't populated in IP
+ address-to-username matching after a successful GlobalProtect
+ authentication using an authentication override cookie.
+
+ |
+
|
+ PAN-208079
+ |
+ + (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the PAN-DB engine did not start when using a + VM-Series firewall Flex based CPU. + | +
|
+ PAN-207562
+ |
+
+
+ Fixed an issue where the shard count displayed by the
+ show log-collector-es-cluster health
+ CLI command was higher than the recommended limit. The recommended
+ limit can be calculated with the formula
+ 20*heap-memory*no-of-data-nodes.
+
+ |
+
|
+ PAN-206963
+ |
+
+
+ (M-700 Appliances only) A CLI command was added
+ to check the status of each physical port of a bond1 interface.
+
+ |
+
|
+ PAN-206921
+ |
+
+
+ Fixed an issue where the GlobalProtect client pre-login was
+ successful, but the certificate authentication failed.
+
+ |
+
|
+ PAN-206466
+ |
+
+
+ Fixed an issue where the push scope was displaying duplicate shared
+ objects for each device group that were listed under the
+ shared-object group.
+
+ |
+
|
+ PAN-206069
+ |
+
+
+ Fixed an issue where the firewall was unable to boot up on older Intel
+ CPUs.
+
+ |
+
|
+ PAN-205698
+ |
+
+
+ Fixed an issue where GlobalProtect authentication did not work on
+ Apple MacOS devices when the authentication method used was CIE with
+ SAML Authentication.
+
+ |
+
|
+ PAN-204892
+ |
+
+
+ Fixed an issue on Panorama where the web interface was not accessible
+ and displayed the error
+ 504 Gateway Not Reachable due to the
+ mgmtsrvr
+ process not responding.
+
+ |
+
|
+ PAN-204838
+ |
+
+
+ Fixed an issue where the
+ dot1q VLAN tag in ARP reply
+ packets were not displayed.
+
+ |
+
|
+ PAN-204572
+ |
+
+
+ Fixed an issue where python scripts were not working as expected.
+
+ |
+
|
+ PAN-197339
+ |
+
+
+ Fixed an issue where template configuration for the User-ID agent was
+ not reflected on the template stack on Panorama appliances on PAN-OS
+ 10.2.1.
+
+ |
+
|
+ PAN-196954
+ |
+
+
+ Fixed a memory leak issue related to the
+ distributord process.
+
+ |
+
|
+ PAN-195149
+ |
+
+
+ Fixed an issue where firewall administrators were unable to log in to
+ the web interface when RADIUS two-factor authentication was used.
+
+ |
+
|
+ PAN-186270
+ |
+
+
+ Fixed an issue where, when high availability (HA) was enabled and a
+ dynamic update schedule was configured, the
+ configd
+ process unexpectedly stopped responding during configuration commits.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-202450
+ |
+
+
+ Fixed an issue where the
+ device-client-cert was set to
+ expire on December 31, 2023. With this fix, the expiration date has
+ been extended.
+
+ |
+
|
+ PAN-198372
+ |
+
+
+ Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+
+ PAN-231823
+
+ |
+
+
+ A fix was made to address
+ CVE-2024-5916.
+
+ |
+
|
+ PAN-209275
+ |
+
+
+ Fixed an issue where Override cookie authentication into the
+ GlobalProtect gateway failed when an allow list was configured under
+ the authentication profile.
+
+ |
+
|
+ PAN-201627
+ |
+
+
+ Fixed an issue in next-generation firewall deployments where, when
+ SD-WAN was configured, the dataplane restarted if all SD-WAN member
+ links were down due to an out-of-memory (OOM) condition or during a
+ reboot when all SD-WAN tunnels were down.
+
+ |
+
|
+ PAN-200771
+ |
+
+
+ Fixed an issue where
+ syslog-ng
+ was unable to start due to a design change in the syslog configuration
+ file.
+
+ |
+
|
+ PAN-199654
+ |
+
+
+ Fixed an issue where ACC reports did not work for custom RBAC users
+ when more than 12 access domains were associated with the username.
+
+ |
+
|
+ PAN-199311
+ |
+
+
+ Fixed an issue where the Log Forwarding Card (LFC) failed to forward
+ logs to the syslog server.
+
+ |
+
|
+ PAN-199099
+ |
+
+
+ Fixed an issue where, when decryption was enabled, Safari and Google
+ Chrome browsers on Apple Mac computers rejected the server certificate
+ created by the firewall because the Authority Key Identifier was
+ copied from the original server certificate and did not match the
+ Subject Key Identifier on the forward trust certificate.
+
+ |
+
|
+ PAN-198733
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ dmin tcpdump was hardcoded to
+ eth0 instead of bond0.
+
+ |
+
|
+ PAN-198332
+ |
+
+
+ (PA-5400 Series only) Fixed an issue where
+ swapping Network Processing Cards (NPCs) caused high root partition
+ use.
+
+ |
+
|
+ PAN-198266
+ |
+
+
+ Fixed an issue where, when predicts for UDP packets were created, a
+ configuration change occurred that triggered a new policy lookup,
+ which caused the dataplane stopped responding when converting the
+ predict. This resulted in a dataplane restart.
+
+ |
+
|
+ PAN-198244
+ |
+
+
+ Fixed an issue where using the
+ load config partial CLI command
+ to x-paths removed address object entries from address groups.
+
+ |
+
|
+ PAN-197576
+ |
+
+
+ Fixed an issue where commits pushed from Panorama caused a memory leak
+ related to the
+ mgmtsrvr
+ process.
+
+ |
+
|
+ PAN-197484
+ |
+
+
+ (PA-5400 Series firewalls) Fixed an issue where
+ the firewall forwarded packets to the incorrect aggregate ethernet
+ interface when Policy Based Forwarding (PBF) was used.
+
+ |
+
|
+ PAN-197383
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2 release, the
+ firewall ran a RAID rebuild for the log disk after ever every reboot.
+
+ |
+
|
+ PAN-197244
+ |
+
+
+ Fixed an issue on firewalls with Forward Proxy enabled where the
+ all_pktproc
+ process stopped responding due to missed heartbeats.
+
+ |
+
|
+ PAN-196993
+ |
+
+
+ Fixed an issue where an incorrect regex key was generated to
+ invalidate the completions cache, which caused the
+ configd
+ process to stop responding.
+
+ |
+
|
+ PAN-196953
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ jumbo frames were dropped.
+
+ |
+
|
+ PAN-196445
+ |
+
+
+ Fixed an issue where restarting the Network Processing Card (NPC) or
+ the Data Processing Card (DPC) did not bring up all the network
+ interfaces.
+
+ |
+
|
+ PAN-196398
+ |
+
+
+ (PA-7000 Series SMC-B firewalls only) Fixed an
+ issue where the firewall did not capture data when the active
+ management interface was MGT-B.
+
+ |
+
|
+ PAN-196227
+ |
+
+
+ Fixed an issue where the
+ logd
+ process stopped responding, which caused Panorama to reboot into
+ maintenance mode.
+
+ |
+
|
+ PAN-196005
+ |
+
+
+ (PA-3200 Series, PA-5200 Series, and PA-5400 Series firewalls
+ only) Fixed an issue where GlobalProtect IPSec tunnels disconnected at
+ half the inactivity logout timer value.
+
+ |
+
|
+ PAN-195707
+ |
+
+
+ Fixed an issue on Panorama appliances configured as log collectors
+ where Panorama repeatedly rebooted into maintenance mode.
+
+ |
+
|
+ PAN-195689
+ |
+
+
+ Fixed an issue where WildFire submission logs did not load on the
+ firewall web interface.
+
+ |
+
|
+ PAN-195628
+ |
+
+
+ Fixed an issue that caused the
+ pan_task
+ process to miss heartbeats and stop responding.
+
+ |
+
|
+ PAN-195625
+ |
+
+
+ Fixed an issue where
+ authd
+ frequently created SSL sessions, which resulted in an OOM condition.
+
+ |
+
|
+ PAN-195360
+ |
+
+
+ Fixed an issue with firewalls in Microsoft Azure environments where
+ BGP flapping occurred due to the firewall incorrectly treating
+ capability from BGP peering as unsupported.
+
+ |
+
|
+ PAN-195223
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process restarted when receiving a GTPv2 Modify Bearer Request packet
+ if the Serving GPRS Support Node (SGSN) used the same key as the
+ Serving Gateway (SGW).
+
+ |
+
|
+ PAN-195181
+ |
+
+
+ Added enhancements to improve the load on the
+ pan_comm
+ process during SNMP polling.
+
+ |
+
|
+
+ PAN-194993
+
+ |
+
+
+ Fixed an issue that occurred when authenticating into GlobalProtect
+ with authentication override cookies and SAML where, if the cookie was
+ invalid, authentication did not fall back to SAML.
+
+ |
+
|
+ PAN-194826
+ |
+
+
+ (WF-500 and WF-500-B appliances only) Fixed an
+ issue where log system forwarding did not work over a TLS connection.
+
+ |
+
|
+ PAN-194782
+ |
+
+
+ Fixed an issue on Panorama where, if you added a new local or
+ non-local administrator account or an admin user to a template,
+ authentication profiles were incorrectly referenced.
+
+ |
+
|
+ PAN-194708
+ |
+
+
+ Fixed an issue where URL filtering logs () incorrectly truncated a 16KB Header value and did not display the
+ Header values that followed the truncated 16KB header.
+
+ |
+
|
+ PAN-194694
+ |
+
+
+ Fixed an issue where multiple SNMP requests being made to the firewall
+ caused in the
+ pan_comm
+ process to stop responding.
+
+ |
+
|
+ PAN-194601
+ |
+
+
+ Fixed an issue that caused the
+ all_task
+ process to stop responding.
+
+ |
+
|
+ PAN-194588
+ |
+
+
+ (PA-7000 Series firewalls with LFCs (Log Forwarding Cards), PA-7050
+ firewalls with SMC-B (Switch Management Cards), and PA-7080
+ firewalls only) Fixed an issue where the
+ logrcvr_statistics output was not
+ recorded in mp-monitor.log.
+
+ |
+
|
+ PAN-194481
+ |
+
+
+ Fixed an issue in ESXi where the bootstrapped VM-Series firewalls with
+ the Software Licensing Plugin had
+ :xxx appended to their hostnames.
+
+ |
+
|
+ PAN-194408
+ |
+
+
+ Fixed an issue where, when policy rules had the apps that implicitly
+ depended on web browsing configured with the service
+ application default, traffic did not match the rule correctly.
+
+ |
+
|
+ PAN-194406
+ |
+
+
+ Fixed an issue where the MTU from SD-WAN interfaces was recalculated
+ after a configuration push from Panorama or a local commit, which
+ caused traffic disruption.
+
+ |
+
|
+ PAN-194262
+ |
+
+
+ Fixed an issue where the GlobalProtect application failed to connect
+ when a user or group was configured under the portal
+ Config Selection Criteria.
+
+ |
+
|
+ PAN-194152
+ |
+
+
+ (PA-5410, PA-5420, PA-5430, and PA-5440 firewalls in HA
+ configurations only) Fixed an issue where HA1-A and HA1-B port information didn't match
+ to front panel mappings and, when one firewall was on PAN-OS 10.2.3 or
+ a later release and the other was on PAN-OS 10.2.2 or an earlier
+ release, a split-brain situation occurred.
+
+ |
+
|
+ PAN-194129
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ slot 2 did not use all features correctly if a DPC was used instead of
+ an NPC.
+
+ |
+
|
+ PAN-194097
+ |
+
+
+ Fixed an issue on firewalls in high availability (HA) active/passive
+ configurations where
+ _ha_d_session_msgbuf overflowed
+ on the passive firewall during an upgrade, which caused the firewall
+ to enter a non-functional state.
+
+ |
+
|
+ PAN-193981
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall stopped monitoring HA failure and
+ floating IP addresses did not get moved to the newly active firewall.
+
+ |
+
|
+ PAN-193899
+ |
+
+
+ Fixed an issue where advanced mode factory reset () was only compatible with PAN-OS 10.1.3 or later version images.
+
+ |
+
|
+ PAN-193818
+ |
+
+
+ Fixed an issue where the firewall device server failed to resolve URL
+ cloud FQDNs, which interrupted URL category lookup.
+
+ |
+
|
+ PAN-193766
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the GlobalProtect portal was not accessible.
+
+ |
+
|
+ PAN-193765
+ |
+
+
+ Fixed an issue where commits failed the following error displayed in
+ the
+ configd
+ log:
+ Unable to populate ids into candidate config: Error: Error
+ populating id for 'sg2+DMZ to FirstAM Scanner-1.
+
+ |
+
|
+ PAN-193763
+ |
+
+
+ Fixed an issue on the firewall where the dataplane CPU spiked, which
+ caused traffic to be affected during commits or content updates.
+
+ |
+
|
+ PAN-193744
+ |
+
+
+ (PA-3200 Series firewalls only) Fixed an issue
+ where, when the HA2 HSCI connection was down, the system log displayed
+ Port HA1-b: down instead of
+ Port HSCI: Down.
+
+ |
+
|
+ PAN-193732
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where the firewall incorrectly handled internal transactions.
+
+ |
+
|
+ PAN-193707
+ |
+
+
+ Fixed an issue where SAML authentication failed during commits with
+ the following error message:
+ revocation status could not be verified (reason: ).
+
+ |
+
|
+ PAN-193483
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue
+ where, during Layer-7 packet inspection where traffic was being
+ inspected for threat signature and data patterns, multiple processes
+ stopped responding.
+
+ |
+
|
+ PAN-193392
+ |
+
+
+ Fixed an issue where RTP packets dropped due to conflicting duplicate
+ flows.
+
+ |
+
|
+ PAN-193251
+ |
+
+
+ Fixed an issue where, when SAML was configured as the authentication
+ method for GlobalProtect, the SAML page did not load when using a
+ browser.
+
+ |
+
|
+ PAN-193235
+ |
+
+
+ Fixed an issue where duplicate log entries were displayed on Panorama.
+
+ |
+
|
+ PAN-193201
+ |
+
+
+ Fixed an issue where auto-commits failed after an upgrade if an
+ imported certificate size was greater than the size of a buffer.
+
+ |
+
|
+ PAN-193132
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where a
+ commit and push from Panorama caused high dataplane CPU utilization.
+
+ |
+
|
+ PAN-192944
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process caused an OOM condition.
+
+ |
+
|
+ PAN-192739
+ |
+
+
+ Fixed an issue where the error message
+ Machine Learning found virus was
+ displayed in threat CSV logs as
+ Threat ID/Name when WildFire Inline
+ ML detected malware.
+
+ |
+
|
+ PAN-192726
+ |
+
+
+ Fixed an issue where the firewall dropped TCP traffic inside IPSec
+ tunnels.
+
+ |
+
|
+ PAN-192673
+ |
+
+
+ (PA-7050-SMC-B firewalls only) Fixed an issue
+ where the LFC syslog-ng service failed to start after an upgrade.
+
+ |
+
|
+ PAN-192666
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ uploading certificates via API failed within the first 30 minutes of a
+ bootstrap.
+
+ |
+
|
+ PAN-192551
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where the firewall incorrectly processed path monitoring packets.
+
+ |
+
|
+ PAN-192404
+ |
+
+
+ Fixed an issue where ARP broadcasts occurring in the same time
+ interval and network segment as HA path monitoring pings triggered an
+ ARP cache request, which prevented the firewall from sending ICMP echo
+ requests to the monitored destination IP address and caused an HA path
+ monitoring failover.
+
+ |
+
|
+ PAN-192330
+ |
+
+
+ (Bootstrapped VM-Series firewalls in Microsoft Azure environments
+ only) Fixed an issue where the firewall did not automatically receive the
+ Strata Logging Service license.
+
+ |
+
|
+ PAN-192052
+ |
+
+
+ Fixed an issue where, when next hop MAC address entries weren't found
+ on the offload processor for active traffic, update messages flooded
+ the firewall, which caused resource contention and traffic disruption.
+
+ |
+
|
+ PAN-191874
+ |
+
+
+ Fixed an issue where monthly scheduled reports did not display
+ information after upgrading to PAN-OS 10.2.0.
+
+ |
+
|
+ PAN-191847
+ |
+
+
+ Fixed an issue where the Panorama appliance was unable to generate
+ scheduled custom reports due to the large number of files stored in
+ the
+ opt/pancfg/mgmt/custom-reports
+ directory.
+
+ |
+
|
+ PAN-191726
+ |
+
+
+ Fixed an issue where an SCP export of the device state from the
+ firewall added single quotes ( ' ) to the filename.
+
+ |
+
|
+ PAN-191558
+ |
+
+
+ Fixed an issue where, after an upgrade to PAN-OS 10.1.5, Global Find
+ did not display all results related to a searched item.
+
+ |
+
|
+ PAN-191269
+ |
+
+
+ Fixed an issue where the NAT pool leaked for passive mode FTP predict
+ sessions.
+
+ |
+
|
+ PAN-191222
+ |
+
+
+ Fixed an issue where Panorama became inaccessible when after a push to
+ the collector group.
+
+ |
+
|
+ PAN-191218
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where the session log storage quota could not be changed via the web
+ interface.
+
+ |
+
|
+ PAN-191216
+ |
+
+
+ Fixed an issue where, on Apple iOS devices, SAML authentication did
+ not connect to the GlobalProtect portal.
+
+ |
+
|
+ PAN-191214
+ |
+
+
+ Fixed an issue where the Elasticsearch process stopped responding,
+ which caused an OOM condition.
+
+ |
+
|
+ PAN-190657
+ |
+
+
+ Fixed an issue where IPSec tunnels did not rekey due to the security
+ association being deleted too early.
+
+ |
+
|
+ PAN-190448
+ |
+
+
+ Fixed an issue in ACC reports where IPv6 addresses were displayed
+ instead of IPv4 addresses.
+
+ |
+
|
+ PAN-189894
+ |
+
+
+ Fixed an issue with the web interface where the template stack didn't
+ show inherited values of
+ Template > Authentication Portal Settings.
+
+ |
+
|
+ PAN-189861
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where intermittent
+ system alerts on the active firewall caused the
+ pan_comm
+ process to restart continuously.
+
+ |
+
|
+ PAN-189859
+ |
+
+
+ Fixed an issue on the firewall where an administrator was unable to
+ Import Custom URL Category Content.
+
+ |
+
|
+ PAN-189762
+ |
+
+
+ Fixed an issue where a predict session didn't match with the traffic
+ when both source NAT and destination NAT were enabled.
+
+ |
+
|
+ PAN-189723
+ |
+
+
+ Fixed an issue where you were unable to configure dynamic address
+ groups to use more than 64,000 IP addresses in a Security policy.
+
+ |
+
|
+ PAN-189414
+ |
+
+
+ Fixed an issue where TCP packets were dropped during the first zone
+ transfer when DNS security was enabled.
+
+ |
+
|
+ PAN-189304
+ |
+
+
+ Fixed an issue where the Panorama appliance didn't display logs or
+ generate reports for a device group containing MIPs platform that
+ forwarded logs to Strata Logging Service.
+
+ |
+
|
+ PAN-189270
+ |
+
+
+ Fixed an issue that caused a memory leak on the
+ reportd
+ process.
+
+ |
+
|
+ PAN-189225
+ |
+
+
+ Fixed an issue where BGP routes were lost or uninstalled after
+ disabling jumbo frames on the firewall.
+
+ |
+
|
+ PAN-189114
+ |
+
+
+ Fixed an issue where the dataplane went down, which caused an HA
+ failover.
+
+ |
+
|
+ PAN-188867
+ |
+
+
+ Fixed an issue where the firewall dropped packets when the session
+ payload was too large.
+
+ |
+
|
+ PAN-188489
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ dynamic content updates weren't automatically pushed to the firewall
+ licensed using the Panorama Software Firewall License plugin when
+ Automatically push content when software device registers to
+ Panorama
+ () was enabled.
+
+ |
+
|
+ PAN-188338
+ |
+
+
+ Fixed an issue where canceling a commit caused the commit process to
+ remain at 70% and the firewall had to be rebooted.
+
+ |
+
|
+ PAN-188303
+ |
+
+
+ Fixed an issue where the serial number displayed as
+ unknown after running the
+ show system state CLI command.
+
+ |
+
|
+ PAN-188096
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue
+ where, on firewalls licensed with Software NGFW Credit (VM-FLEX-4 and
+ higher), HA clustering was unable to be established.
+
+ |
+
|
+ PAN-187985
+ |
+
+
+ Fixed an issue where you were unable to configure a QoS Profile as
+ percentage for Clear Text Traffic.
+
+ |
+
|
+ PAN-187890
+ |
+
+
+ Fixed an issue where the
+ Strata Logging Service connection incorrectly
+ displayed as disconnected when a service route was in use.
+
+ |
+
|
+ PAN-187805
+ |
+
+
+ Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted during certificate
+ construction or destruction.
+
+ |
+
|
+ PAN-187476
+ |
+
+
+ Fixed an issue where, when hip-redistribution is enabled, Panorama
+ doesn't display a part of HIP information.
+
+ |
+
|
+ PAN-187234
+ |
+
+
+ Fixed an intermittent issue where web pages submitted for analysis by
+ Advanced URL Filtering cloud inline categorization experienced high
+ latency.
+
+ |
+
|
+ PAN-186891
+ |
+
+
+ Fixed an issue where NetFlow packets contained incorrect octet counts.
+
+ |
+
|
+ PAN-186418
+ |
+
+
+ Fixed an issue where Panorama displayed a discrepancy in RAM
+ configured on the VMware host.
+
+ |
+
|
+ PAN-186134
+ |
+
+
+ Fixed an issue on Panorama where performing a commit and push
+ intermittently failed to push the committed configuration to managed
+ firewalls.
+
+ |
+
|
+ PAN-186075
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall rebooted after receiving large packets while in DPDK mode
+ on Azure virtual machines running CX4 (MLx5) drivers.
+
+ |
+
|
+ PAN-185787
+ |
+
+
+ Fixed an issue where logging in to the Panorama web interface did not
+ work and the following error message displayed:
+ Timed out while getting config lock. Please try again.
+
+ |
+
|
+ PAN-185283
+ |
+
+
+ Fixed an issue on Panorama where using the
+ name-of-threatid contains log4j
+ filter didn't produce expected results.
+
+ |
+
|
+ PAN-184702
+ |
+
+
+ (M-700 appliances in Log Collector mode only)
+ Fixed an issue on the Panorama management server where the Panorama
+ appliance failed to connect to Panorama when added as a managed log
+ collector.
+
+ |
+
|
+ PAN-184068
+ |
+
+
+ (PA-5200 Series firewalls only) Fixed an issue
+ where the firewall generated pause frames, which caused network
+ latency.
+
+ |
+
|
+ PAN-183788
+ |
+
+
+ Fixed an issue with SCEP certificate enrollment where the incorrect
+ Registration Authority (RA) certificate was chosen to encrypt the
+ enrollment request.
+
+ |
+
|
+ PAN-185750
+ |
+
+
+ Updated an issue to eliminate failed
+ pan_comm
+ software issues that caused the dataplane to restart unexpectedly
+
+ |
+
|
+ PAN-183270
+ |
+
+
+ Fixed an issue where a bootstrapped firewall connected only to the
+ first log collector in a log collector group.
+
+ |
+
|
+ PAN-183184
+ |
+
+
+ Fixed an issue where enabling SSL decryption with a Hardware Security
+ Model (HSM) caused a dataplane restart.
+
+ |
+
|
+ PAN-183166
+ |
+
+
+ Fixed an issue where system, configuration, and alarm logs were queued
+ up on the
+ logrcvr
+ process and were not forwarded out or written to disk until an
+ autocommit was passed.
+
+ |
+
|
+ PAN-182689
+ |
+
+
+ Fixed an issue where a signature from a previous WildFire package
+ triggered virus detection even though the signature was no longer
+ present in the current WildFire package.
+
+ |
+
|
+ PAN-182539
+ |
+
+
+ Fixed an issue with Panorama appliances in HA configurations where
+ dedicated log collectors did not send local system or configuration
+ logs to both Panorama appliances.
+
+ |
+
|
+ PAN-182212
+ |
+
+
+ Fixed an issue where SNMP reported the
+ panVsysActiveTcpCps and
+ panVsysActiveUdpCps value to be
+ 0.
+
+ |
+
|
+ PAN-181277
+ |
+
+
+ Fixed an issue where VPN tunnels in SD-WAN flapped due to duplicate
+ tunnel IDs.
+
+ |
+
|
+ PAN-179543
+ |
+
+
+ Fixed an issue where the
+ flow_mgmt
+ process stopped responding when attempting to clear the session table,
+ which caused the dataplane to restart.
+
+ |
+
|
+ PAN-179258
+ |
+
+ Fixed an issue where system disk migration failed.
+ |
+
|
+ PAN-178243
+ |
+
+
+ Fixed an issue where
+ Shared Gateway was not visible in
+ the Virtual System drop down when
+ configuring a Layer3 aggregate subinterface.
+
+ |
+
|
+ PAN-178194
+ |
+
+
+ Fixed an issue with the web interface where, when only the Advanced
+ URL Filtering license was activated, the message
+ License required for URL filtering to function
+ was incorrectly displayed and the
+ URL Filtering Profile > Inline ML
+ section was disabled.
+
+ |
+
|
+ PAN-177482
+ |
+
+
+ Fixed an issue where
+ ACC > App Scope > Threat Monitor
+ showed NO DATA TO DISPLAY.
+
+ |
+
|
+ PAN-172501
+ |
+
+
+ Fixed an issue where you were unable to revert HA mode settings to the
+ default values from the web interface.
+
+ |
+
|
+ PAN-171714
+ |
+
+
+ Fixed an issue where, when NetBIOS format (domain\user) was used for
+ the IP address-to-username mapping and the firewall received the group
+ mapping information from the Cloud Identity Engine, the firewall did
+ not match the user to the correct group.
+
+ |
+
|
+ PAN-157215
+ |
+
+
+ Fixed an issue that occurred when two FQDNs were resolved to the same
+ IP address and were configured as the same src/dst of the same rule.
+ If one FQDN was later resolved to a different IP address, the IP
+ address resolved for the second FQDN was also changed, which caused
+ traffic with the original IP address to hit the incorrect rule.
+
+ |
+
|
+ PAN-151469
+ |
+
+
+ Fixed an issue where packets were dropped unexpectedly due to errors
+ parsing the IP version field.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
| PAN-218285 | ++ Fixed an issue where after switching the SPN by suspending the active + SPN, the forwarding rule was not correctly pointing to the new active + node when moved from 3 rules (TCP/UDP/ICMP) to 1 Layer 3 default rule in + GCP. + | +
|
+ PAN-217484
+ |
+
+
+ Fixed an issue where the
+ rasmgr
+ process used 100% CPU due to a maximum duration timer not being set,
+ which caused the GlobalProtect gateway to be unavailable.
+
+ |
+
| PAN-217431 | ++ Fixed an issue with slot 2 DPCs where URL Filtering did not work as + expected after upgrading to PAN-OS 10.1.9. + | +
| PAN-216710 | ++ Fixed an issue with firewalls in active/active HA configurations where + GlobalProtect disconnected when the original suspected active-primary + firewall became active-secondary. + | +
| PAN-216036 | ++ Fixed an issue where the + all_pktproc process stopped responding, + which caused the firewall to enter a nonfunctional state. + | +
| PAN-215823 | ++ Fixed an issue on log collectors where the + reportd process stopped responding. + | +
| PAN-215496 | ++ Fixed an issue where 100G ports did not come up with BIDI QSFP modules. + | +
| PAN-214406 | ++ Fixed an issue with Elasticsearch where ES tunnels weren’t started and + were forked incorrectly, which caused them to fail. + | +
| PAN-213079 | ++ Fixed an issue with Captive Portal SAML authentication by increasing the + number of retries in the Nginx configuration. + | +
|
+ PAN-212726
+ PAN-211519
+ |
+ + Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP + ALG when the source NAT translation type was persistent + Dynamic IP And Port. + | +
| PAN-211870 | ++ Fixed an issue where path monitoring failure occurred, which caused high + availability failover. + | +
| PAN-195912 | ++ Fixed an issue where connections from the firewall to + Strata Logging Service failed. + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-222035
+ |
+
+
+ Fixed an issue where when multiple portals were configured in Prisma
+ Access deployments, CIE SAML authentication failed on the secondary
+ portal.
+
+ |
+
|
+ PAN-221068
+ |
+
+
+ Fixed an issue where the firewall restarted after a failed push from
+ Panorama, which resulted in autocommit failures.
+
+ |
+
|
+ PAN-219355
+ |
+
+
+ Fixed an issue where disk space became full due to a GPSVC FD leak.
+
+ |
+
|
+ PAN-219333
+ |
+
+
+ Fixed an issue where a secondary Prisma Access Portal address with
+ port 8443 did not work.
+
+ |
+
|
+ PAN-218620
+ |
+
+
+ Fixed an issue where scheduled configuration exports and SCP server
+ connection testing failed.
+
+ |
+
|
+ PAN-218368
+ |
+
+
+ Fixed an issue with incorrect VLAN tagging on Intel based platforms
+ that occurred when opening a response page from a virtual-wire
+ subinterface.
+
+ |
+
|
+ PAN-218340
+ |
+
+
+ Fixed a memory leak issue related to the
+ configd
+ process that affected selective pushes on Panorama.
+
+ |
+
|
+ PAN-218267
+ |
+
+
+ Fixed an issue where a partial commit and push operation from Panorama
+ to managed firewalls did not work as expected.
+
+ |
+
|
+ PAN-218046
+ |
+
+
+ Fixed an issue where the
+ Virtual Routers () setting was not available when configuring a custom admin role
+ .
+
+ |
+
|
+ PAN-217053
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding after a selective push to multiple device
+ groups failed.
+
+ |
+
|
+ PAN-215899
+ |
+
+
+ Fixed an issue with Panorama appliances in high availability (HA)
+ configurations where configuration synchronization between the HA
+ peers failed.
+
+ |
+
|
+ PAN-215767
+ |
+
+
+ Fixed an issue where, after a high availability failover, IKE SA
+ negotiation failed with the error message
+ INVALID_SPI, which resulted in
+ temporary loss of traffic over some proxy IDs.
+
+ |
+
|
+ PAN-215324
+ |
+ + (PA-5400 Series firewalls with Jumbo Frames enabled only) Fixed an issue with CPU throttling and buffer depletion. + | +
|
+ PAN-215315
+ |
+
+
+ Fixed an issue where the dataplane stopped responding due to ager and
+ inline packet processing occurring concurrently on different cores for
+ the same session.
+
+ |
+
|
+ PAN-214463
+ |
+
+
+ Fixed an issue where IKE rekey negotiation failed with a third-party
+ vendor and the firewall acting as the initiator received a response
+ with the VENDOR_ID payload and the error message
+ unexpected critical payload (type 43).
+
+ |
+
|
+ PAN-213973
+ |
+
+
+ Fixed an issue where the
+ authd
+ process stopped responding during a cleanup of authentication server
+ context.
+
+ |
+
|
+ PAN-212978
+ |
+
+
+ Fixed an issue where the firewall stopped responding when executing an
+ SD-WAN configuration or operational CLI command.
+
+ |
+
|
+ PAN-210366
+ |
+
+
+ Fixed an issue where deleting a device group when a selective
+ configuration push was in progress caused the
+ configd
+ process to stop responding.
+
+ |
+
|
+ PAN-208240
+ |
+
+
+ Fixed an issue where, when attempting to replace an existing
+ certificate, importing a new certificate with the same name as the
+ existing certificate failed due to mismatched public and private keys.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-223501
+ |
+
+
+ Fixed an issue where diagnostic information for the dataplane in the
+ dp-monitor.log file was not complete.
+
+ |
+
|
+ PAN-222712
+ |
+
+
+ (PA-5450 firewalls only) Fixed a low frequency
+ DPC restart issue.
+
+ |
+
|
+ PAN-221984
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where an interface went down after a hotplug event
+ and was only recoverable by restarting the firewall.
+
+ |
+
|
+ PAN-221836
+ |
+
+
+ Fixed an issue where improper SNI detection caused incorrect URL
+ categorization.
+
+ |
+
|
+ PAN-219508
+ |
+
+
+ (VM-Series, PA-400 Series, PA-1400, PA-3400, and PA-5400 Series
+ firewalls only) Fixed an issue where Bidirectional Forwarding Detection (BFD)
+ packets experienced a delay in processing, which caused the BFD
+ connection to flap.
+
+ |
+
|
+ PAN-217489
+ |
+ + Fixed an issue with firewalls in active/passive high availability (HA) + configurations where the passive firewall MAC flapping occurred when the + passive firewall was rebooted. + | +
|
+ PAN-216043
+ |
+
+
+ Fixed an issue where wifclient stopped responding due to shared memory
+ corruption.
+
+ |
+
|
+ PAN-215655
+ |
+
+
+ Fixed an issue where, after a multi-dynamic group push, Security
+ policies with the target device tag was added to a firewall that did
+ not have the tag.
+
+ |
+
|
+ PAN-215066
+ |
+
+
+ Fixed an issue on Panorama where push scope rendering caused the
+ commit and push or push operation window to hang for several minutes.
+
+ |
+
|
+ PAN-214187
+ |
+
+
+ Fixed an issue where superreaders were able to execute the
+ request restart system CLI command.
+
+ |
+
|
+ PAN-211191
+ |
+
+
+ Fixed an issue where the firewall restarted after initiating a
+ mgmtsrvr
+ process restart.
+
+ |
+
|
+ PAN-210661
+ |
+
+
+ Fixed an issue where firewalls disconnected from
+ Strata Logging Service after renewing the
+ device certificate.
+
+ |
+
|
+ PAN-210429
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the HTTP service failed to come up on DHCP dataplane interfaces after
+ rebooting the firewall, which resulted in health-check failure on
+ HTTP/80 with a 503 error code on the public load balancer.
+
+ |
+
|
+ PAN-195439
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the dataplane interface status went down after
+ a hotplug event triggered by Azure infrastructure.
+
+ |
+
|
+ PAN-169586
+ |
+
+
+ Fixed an issue where scheduled log view reports in emails didn't match
+ the monitor page query result for the same time interval.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-5976
+ |
+
+
+ (WF-500 appliances only) Fixed an issue where
+ files were incorrectly detected as malicious.
+
+ |
+
|
+ WF500-5953
+ |
+
+
+ Fixed an issue where testing the same file sample using a PowerShell
+ script returned different verdicts in Private Cloud and Public Cloud.
+
+ |
+
|
+ WF500-5920
+ |
+
+ Fixed an issue where an elink parser did not work.
+ |
+
|
+
+ PAN-231823
+
+ |
+
+
+ A fix was made to address
+ CVE-2024-5916.
+
+ |
+
|
+ PAN-220741
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where, when redistribution agent connections to the
+ passive firewall failed, excessive system alerts for the failed
+ connection were generated. With this fix, system alerts are logged
+ every 5 hours instead of 10 minutes.
+
+ |
+
|
+ PAN-219686
+ |
+
+
+ Fixed an issue where a device group push operation from Panorama
+ failed with the following error on managed firewalls.
+
+
+ vsys -> vsys1 -> plugins unexpected here
+
+
+ vsys is invalid
+
+ Commit failed
+ |
+
|
+ PAN-216656
+ |
+
+
+ Fixed an issue where the firewall was unable to fully process the user
+ list from a child group when the child group contained more than 1,500
+ users.
+
+ |
+
|
+ PAN-216314
+ |
+
+
+ (PA-3200 Series firewalls only) Fixed an issue
+ where, after upgrading to or from PAN-OS 10.1.9 or PAN-OS 10.1.9-h1,
+ offloaded application traffic sessions disconnected even when a
+ session was active. This occurred due to the application default
+ session timeout value being exceeded.
+
+ |
+
|
+ PAN-215911
+ |
+
+
+ Fixed an issue that resulted in a race condition, which caused the
+ configd
+ process to stop responding.
+
+ |
+
|
+ PAN-215488
+ |
+
+
+ Fixed an issue where an expired Trusted Root CA was used to sign the
+ forward proxy leaf certificate during SSL Decryption.
+
+ |
+
|
+ PAN-215461
+ |
+
+
+ Fixed an issue where the packet descriptor leaked over time with GRE
+ tunnels and keepalives.
+
+ |
+
|
+ PAN-215125
+ |
+
+
+ Fixed an issue where false negatives occurred for some script samples.
+
+ |
+
|
+ PAN-214634
+ |
+
+ Fixed an issue where an elink parser did not work.
+ |
+
|
+ PAN-214624
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-214337
+ |
+
+
+ Fixed an issue on the firewall related to the
+ gp_broker configuration transform
+ that led to longer commit times.
+
+ |
+
|
+ PAN-214037
+ |
+
+
+ (PA-5440, PA-5430, PA-5420, and PA-5410 firewalls only) Fixed an issue where firewalls in active/active HA configurations
+ experienced packet drop when running asymmetric traffic.
+
+ |
+
|
+ PAN-213973
+ |
+
+
+ Fixed an issue where the
+ authd
+ process stopped responding during a cleanup of authentication server
+ context.
+
+ |
+
|
+ PAN-213661
+ |
+
+
+ Fixed an issue where memory allocation failure caused dataplane
+ processes to restart. This issue occurred when decryption was enabled
+ and the device was under heavy L7 usage.
+
+ |
+
|
+ PAN-213011
+ |
+
+
+ Fixed an issue where, when using multi-factor authentication (MFA)
+ with RADIUS OTP, the challenge message
+ Enter Your Microsoft verification code
+ did not appear when accessing the GlobalProtect portal via browser.
+
+ |
+
|
+ PAN-212982
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding with MICA HTTP2 traffic.
+
+ |
+
|
+ PAN-212409
+ |
+
+
+ Fixed an issue where there were duplicate IPSec Security Associations
+ (SAs) for the same tunnel, gateway, or proxy ID.
+
+ |
+
|
+ PAN-211242
+ |
+
+
+ Fixed an issue where missed heartbeats caused the Data Processing Card
+ (DPC) and its corresponding Network Processing Card (NPC) to restart
+ due to internal packet path monitoring failure.
+
+ |
+
|
+ PAN-210919
+ |
+
+
+ Fixed an issue where the Data Processing Card remained in a
+ Starting state after a restart.
+
+ |
+
|
+ PAN-210892
+ |
+
+
+ (M-600 and M-700 appliances only) Fixed an
+ issue where the Elasticsearch shard count grew continuously without
+ limit.
+
+ |
+
|
+ PAN-210875
+ |
+
+
+ Fixed an issue where the
+ pan_task
+ process stopped responding due to software packet buffer 3 trailer
+ corruption, which caused the firewall to restart.
+
+ |
+
|
+ PAN-210561
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process repeatedly restarted due to missed heartbeats.
+
+ |
+
|
+ PAN-210481
+ |
+
+
+ Fixed an issue where botnet reports were not generated on the
+ firewall.
+
+ |
+
|
+ PAN-210449
+ |
+
+
+ Fixed an issue where the value for shared objects used in policy rules
+ were not displayed on multi-vsys firewalls when pushed from Panorama.
+
+ |
+
|
+ PAN-210331
+ |
+
+
+ Fixed an issue where the firewall did not send device telemetry files
+ to Strata Logging Service with the error
+ message
+ Send File to Strata Logging Service Receiver Failed.
+
+ |
+
|
+ PAN-210327
+ |
+
+
+ (PA-5200 Series firewalls only) Fixed an issue
+ where upgrading to PAN-OS 10.1.7, an internal loop caused an increase
+ in the packets received per second.
+
+ |
+
|
+ PAN-210237
+ |
+
+
+ Fixed an issue where system logs generated by Panorama for commit
+ operations showed the severity as
+ High instead of
+ Informational.
+
+ |
+
|
+ PAN-210080
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding when add and delete member parameters in an
+ incremental sync query were empty.
+
+ |
+
|
+ PAN-209660
+ |
+
+
+ Fixed an issue where a selective push from Panorama to multiple
+ firewalls failed due to a missing configuration file, which caused a
+ communication error.
+
+ |
+
|
+ PAN-209346
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.3, HA peers
+ received conflicting ARP messages that indicated a duplicate IP
+ address.
+
+ |
+
|
+ PAN-209305
+ |
+
+
+ Fixed a memory space issue where the content and threat detection
+ (CTD) process flow cleanup during inline cloud analysis did not work.
+
+ |
+
|
+ PAN-209226
+ |
+
+
+ Fixed an issue where the feature bits function reused shared memory,
+ which resulted in a memory allocation error and caused the dataplane
+ to go down.
+
+ |
+
|
+ PAN-209069
+ |
+
+
+ Fixed an issue where IP addresses in the
+ X-Forwarded-For (XFF) field were not
+ logged when the IP address contained an associated port number.
+
+ |
+
|
+ PAN-209021
+ |
+
+
+ Fixed an issue where packets were fragmented when SD-WAN VPN tunnel
+ was configured on aggregate ethernet interfaces and sub-interfaces.
+
+ |
+
|
+ PAN-208987
+ |
+
+
+ (PA-5400 Series only) Fixed an issue where
+ packets were not transmitted from the firewall if its fragments were
+ received on different slots. This occurred when aggregate ethernet
+ (AE) members in an AE interface were placed on a different slot.
+
+ |
+
|
+
+ PAN-208922
+
+ |
+
+
+ A fix was made to address an issue where an authenticated
+ administrator was able to commit a specifically created configuration
+ to read local files and resources from the system (CVE-2023-38046).
+
+ |
+
|
+ PAN-208930
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where auto-tagging in log forwarding did not work.
+
+ |
+
|
+ PAN-208877
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding when freeing the HTTP2 stream, which caused
+ the dataplane to go down.
+
+ |
+
|
+ PAN-208737
+ |
+
+
+ Fixed an issue where domain information wasn't populated in IP
+ address-to-username matching after a successful GlobalProtect
+ authentication using an authentication override cookie.
+
+ |
+
|
+ PAN-208724
+ |
+
+
+ Fixed an issue where port pause frame settings did not work as
+ expected and incorrect pause frames occurred.
+
+ |
+
|
+ PAN-208718
+ |
+
+
+ Additional debug information was added to capture internal details
+ during traffic congestion.
+
+ |
+
|
+ PAN-208711
+ |
+
+
+ (PA-5200 Series firewalls only) The CLI command
+ debug dataplane set pow no-desched yes/no
+ was added to address an issue where the
+ all_pktproc
+ process stopped responding and caused traffic issues.
+
+ |
+
|
+ PAN-208537
+ |
+
+
+ Fixed an issue where the
+ licensed-device-capacity was
+ reduced when multiple device management license key files were
+ present.
+
+ |
+
|
+ PAN-208485
+ |
+
+
+ Fixed an issue where NAT policies were not visible on the CLI if they
+ contained more than 32 characters.
+
+ |
+
|
+ PAN-208189
+ |
+
+
+ Fixed an issue when traffic failed to match and reach all destinations
+ if a Security policy rule includes FQDN objects that resolve to two or
+ more IP addresses.
+
+ |
+
|
+ PAN-208157
+ |
+
+
+ Fixed an issue where malformed hints sent from the firewall caused the
+ logd
+ process to stop responding on Panorama, which caused a system reboot
+ into maintenance mode.
+
+ |
+
|
+ PAN-208079
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the PAN-DB engine did not start when using a
+ VM-Series firewall Flex based CPU.
+
+ |
+
|
+ PAN-207983
+ |
+
+
+ Fixed an issue on Panorama in Management Only mode where the logdb
+ database incorrectly collected traffic, threat, GTP, decryption, and
+ corresponding summary logs.
+
+ |
+
|
+ PAN-207940
+ |
+
+
+ Fixed an issue where platforms with RAID disk checks were performed
+ weekly, which caused logs to incorrectly state that RAID was
+ rebuilding.
+
+ |
+
|
+ PAN-207891
+ |
+
+
+ Fixed an issue on Panorama where log migration did not complete after
+ an upgrade.
+
+ |
+
|
+ PAN-207740
+ |
+
+
+ Fixed an issue that resulted in a race condition, which caused the
+ configd
+ process to stop responding.
+
+ |
+
|
+ PAN-207738
+ |
+
+
+ Fixed an issue where the
+ ocsp-next-update-time CLI command
+ did not execute for leaf certificates with certificate chains that did
+ not specify OCSP or CRL URLs. As a result, the next update time was 60
+ minutes even if a different time was set.
+
+ |
+
|
+ PAN-207663
+ |
+
+
+ Fixed a Clientless VPN issue where JSON stringify caused issues with
+ the application rewrite.
+
+ |
+
|
+ PAN-207629
+ |
+
+
+ Fixed an issue where a selective push to firewalls failed if the
+ firewalls were enabled with multiple vsys and the push scope contained
+ shared objects in device groups.
+
+ |
+
|
+ PAN-207623
+ |
+
+
+ Fixed an issue on Panorama where log migration did not complete as
+ expected.
+
+ |
+
|
+ PAN-207610
+ |
+
+
+ (PA-5200 Series and PA-7000 Series firewalls only) Fixed an issue where
+ Log Admin Activity was not visible
+ on the web interface.
+
+ |
+
|
+ PAN-207602
+ |
+
+
+ Fixed an issue where file streams were opened or closed twice due to a
+ race condition which caused Linux to stop responding.
+
+ |
+
|
+ PAN-207601
+ |
+
+
+ Fixed an issue where URL cloud connections were unable to resolve the
+ proxy server hostname.
+
+ |
+
|
+ PAN-207533
+ |
+
+
+ Fixed an issue with firewalls in HA configurations where ARP and IPv6
+ multicast packets were transmitted from the passive firewall.
+
+ |
+
|
+ PAN-207455
+ |
+
+
+ Fixed an issue where the
+ pan_task
+ process stopped responding when processing client certificate requests
+ from the server in TLS1.3.
+
+ |
+
|
+ PAN-207426
+ |
+
+
+ Fixed an issue where a selective push did not include the
+ Share Unused Address and Service Objects with Devices
+ option on Panorama, which caused the firewall to not receive the
+ objects during the configuration push.
+
+ |
+
|
+ PAN-207400
+ |
+
+
+ Fixed an issue on Octeon based platforms where fragmented VLAN tagged
+ packets dropped on an aggregate interface.
+
+ |
+
|
+ PAN-207390
+ |
+
+
+ Fixed an issue where, even after disabling Telemetry, Telemetry system
+ logs were still generated.
+
+ |
+
|
+ PAN-207260
+ |
+
+
+ A commit option was enabled for Device Group and Template
+ administrators after a password change.
+
+ |
+
|
+ PAN-207045
+ |
+
+
+ (PA-800 Series firewalls only) Fixed an issue
+ where PAN-SFP-SX transceivers used on ports 5 to 8 did not renegotiate
+ with peer ports after a reload.
+
+ |
+
|
+ PAN-207043
+ |
+
+
+ Fixed an issue on PAN-OS 10.2.3 where ports 41-44 remained down when
+ the PAN-QSFP28-DAC-5M cable was connected.
+
+ |
+
|
+ PAN-206963
+ |
+
+
+ (M-700 Appliances only) A CLI command was added
+ to check the status of each physical port of a bond1 interface.
+
+ |
+
|
+ PAN-206921
+ |
+
+
+ Fixed an issue where GlobalProtect client certificate authentication
+ failed on a gateway when the gateway was placed behind a NAT.
+
+ |
+
|
+ PAN-206858
+ |
+
+
+ Fixed an issue where a segmentation fault occurred due to the
+ useridd
+ process being restarted.
+
+ |
+
|
+ PAN-206796
+ |
+
+
+ Fixed an issue where
+ cfg.lcaas-region was not reset
+ when it was empty, which caused
+ Strata Logging Service onboarding to fail.
+
+ |
+
|
+ PAN-206755
+ |
+
+
+ Fixed an issue when a scheduled multi-device group push occurred, the
+ configd
+ process stopped responding, which caused the push to fail.
+
+ |
+
|
+ PAN-206658
+ |
+
+
+ Fixed a timeout issue in the Intel
+ ixgbe driver that resulted in
+ internal path monitoring failure.
+
+ |
+
|
+ PAN-206629
+ |
+
+
+ (VM-Series firewalls in AWS environments only)
+ Fixed an issue where a newly bootstrapped firewalls did not forward
+ logs to Panorama.
+
+ |
+
|
+ PAN-206393
+ |
+
+
+ (PA-5280 firewalls only) Fixed an issue where
+ memory allocation errors caused decryption failures that disrupted
+ traffic with SSL forward proxy enabled.
+
+ |
+
|
+ PAN-206382
+ |
+
+
+ Fixed an issue where authentication sequences were not populated in
+ the drop down when selecting authentication profiles during
+ administrator creation in a template.
+
+ |
+
|
+ PAN-206253
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the default log rate value was too low, and the maximum
+ configurable log rate was capped incorrectly, which caused the
+ firewall to not generate more than 6826 logs per second.
+
+ |
+
|
+ PAN-206251
+ |
+
+
+ (PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only) Fixed an issue where the
+ logrcvr
+ process did not send the
+ system-start SNMP trap during
+ startup.
+
+ |
+
|
+ PAN-206233
+ |
+
+
+ Fixed an issue where the
+ pan_comm
+ process stopped responding when a content update and a cloud
+ application update occurred at the same time.
+
+ |
+
|
+ PAN-206128
+ |
+
+
+ (PA-7000 Series firewalls with NPCs (Network Processing Cards)
+ only) Improved debugging capability for an issue where the firewall
+ restarted due to heartbeat failures and then failed with the following
+ error message: Power not OK.
+
+ |
+
|
+ PAN-206077
+ |
+
+
+ Fixed an issue on firewalls in active/active HA configurations where,
+ after upgrading to PAN-OS 10.1.6-h6, the active primary firewall did
+ not send HIP reports to the active secondary firewall.
+
+ |
+
|
+ PAN-206069
+ |
+
+
+ Fixed an issue where the firewall was unable to boot up on older Intel
+ CPUs.
+
+ |
+
|
+ PAN-206017
+ |
+
+
+ Fixed an issue where the
+ show dos-protection rule command
+ displayed a character limit error.
+
+ |
+
|
+ PAN-206005
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the l7_misc memory pool was
+ undersized and caused connectivity loss when the limit was reached.
+
+ |
+
|
+ PAN-205995
+ |
+
+
+ Fixed an issue where logs from unaffected log collector groups were
+ not displayed when a log collector was down.
+
+ |
+
|
+ PAN-205955
+ |
+
+
+ Fixed an issue where RAID rebuilds occurred even with healthy disks
+ and a clean shutdown.
+
+ |
+
|
+ PAN-205877
+ |
+
+
+ (PA-5450 firewalls only) Added debug commands
+ for an issue where a MAC address flap occurred on a neighbor firewall
+ when connecting both MGT-A and MGT-B interfaces.
+
+ |
+
|
+ PAN-205829
+ |
+
+
+ Fixed an issue where logs did not display
+ Host-ID details for GlobalProtect
+ users despite having a quarantine Security policy rule. This occurred
+ due to a missed local cache lookup.
+
+ |
+
|
+ PAN-205804
+ |
+
+
+ Fixed an issue on Panorama where a WildFire scheduled update for
+ managed devices triggered multiple
+ UploadInstall jobs per minute.
+
+ |
+
|
+ PAN-205729
+ |
+
+
+ (PA-3200 Series and PA-7000 Series firewalls only) Fixed an issue where the CPLD watchdog timeout caused the firewall
+ to reboot unexpectedly.
+
+ |
+
|
+ PAN-205699
+ |
+
+
+ Fixed an issue where the cloud plugin configuration was automatically
+ deleted from Panorama after a reboot or a
+ configd
+ process restart.
+
+ |
+
|
+ PAN-205590
+ |
+
+
+ Fixed an issue where the fan tray fault LED light was on even though
+ no alarm was reported in the system environment.
+
+ |
+
|
+ PAN-205473
+ |
+
+
+ (VM-Series firewalls on Microsoft Hyper-V only)
+ Fixed an issue where the firewall did not receive any traffic on Layer
+ 3 sub-interfaces from the trunk port.
+
+ |
+
|
+ PAN-205453
+ |
+
+
+ Fixed an issue where running reports or queries under a user group
+ caused the
+ reportd
+ process to stop responding.
+
+ |
+
|
+ PAN-205451
+ |
+
+
+ Fixed an issue where the
+ pan_com
+ process stopped responding due to aggressive commits.
+
+ |
+
|
+ PAN-205428
+ |
+
+
+ Fixed an issue where WildFire submissions failed if the file name
+ contained special characters.
+
+ |
+
|
+ PAN-205396
+ |
+
+
+ Fixed an issue where SD-WAN adaptive SaaS path monitoring did not work
+ correctly during a next hop link down failure.
+
+ |
+
|
+ PAN-205337
+ |
+
+
+ Fixed an issue in the
+ Run Now section of custom reports
+ where Threat/Content Name displayed
+ in hypertext, and hovering over the text with the mouse displayed the
+ message
+ undefined.
+
+ |
+
|
+ PAN-205260
+ |
+
+
+ Fixed an issue where there was an IP address conflict after a reboot
+ due to a transaction ID collision.
+
+ |
+
|
+ PAN-205255
+ |
+
+
+ Fixed a rare issue that caused the dataplane to restart unexpectedly.
+
+ |
+
|
+ PAN-205231
+ |
+
+
+ Fixed an issue where a commit operation remained at 55% for longer
+ than expected if more than 7,500 Security policy rules were
+ configured.
+
+ |
+
|
+ PAN-205222
+ |
+
+
+ Fixed an issue where you were unable to add a new application in a
+ selected policy rule.
+
+ |
+
|
+ PAN-205211
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding while querying logs (Monitor > Logs > <logtype>).
+
+ |
+
|
+ PAN-205187
+ |
+
+
+ Fixed an issue where Elasticsearch did not start properly when a newly
+ installed Panorama virtual appliance powered on for the first time,
+ which caused the Panorama virtual appliance to not query logs
+ forwarded from the managed firewall to a Log Collector.
+
+ |
+
|
+ PAN-205096
+ |
+
+
+ Fixed an issue where promoted sessions were not synced with all
+ cluster members in an HA cluster.
+
+ |
+
|
+ PAN-205030
+ |
+
+
+ Fixed an issue where, when a session hit policy based forwarding with
+ symmetric return enabled was not offloaded, the firewall received
+ excessive return-mac update messages, which resulted in resource
+ contention and traffic disruption.
+
+ |
+
|
+ PAN-204892
+ |
+
+
+ Fixed an issue on Panorama where the web interface was not accessible
+ and displayed the error
+ 504 Gateway Not Reachable due to
+ the
+ mgmtsrvr
+ process not responding.
+
+ |
+
|
+ PAN-204851
+ |
+
+
+ Fixed an issue where, when performing an advanced factory reset from
+ maintenance mode on a firewall running PAN-OS 10.2.2 or an earlier
+ release and downgrading to PAN-OS 10.1.0 or an earlier release, the
+ firewall entered into maintenance mode after the reboot.
+
+ |
+
|
+ PAN-204838
+ |
+
+
+ Fixed an issue where the
+ dot1q VLAN tag was missing in ARP
+ reply packets.
+
+ |
+
|
+ PAN-204830
+ |
+
+
+ Fixed an issue where logging in via the web interface or CLI did not
+ work until an auto-commit was complete.
+
+ |
+
|
+ PAN-204749
+ |
+
+
+ Fixed an issue where sudden, large bursts of traffic destined for an
+ interface that was down caused packet buffers to fill, which stalled
+ path monitor heartbeat packets.
+
+ |
+
|
+ PAN-204690
+ |
+
+
+ Fixed an issue where selective configuration pushes failed due to
+ schema validation when both the device group and template stack had
+ the same name.
+
+ |
+
|
+ PAN-204663
+ |
+
+
+ Fixed an issue on Panorama where you were unable to context switch
+ from one managed firewall to another.
+
+ |
+
|
+ PAN-204582
+ |
+
+
+ Fixed an issue where, when a firewall acting as a DHCP client received
+ a new DHCP IP address, the firewall did not release old DHCP IP
+ addresses from the IP address stack.
+
+ |
+
|
+ PAN-204581
+ |
+
+
+ Fixed an issue where, when accessing a web application via the
+ GlobalProtect Clientless VPN, the web application landing page
+ continuously reloaded.
+
+ |
+
|
+ PAN-204575
+ |
+
+
+ (PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only) Fixed an issue where the firewall did not forward logs to the log
+ collector.
+
+ |
+
|
+ PAN-204482
+ |
+
+
+ Fixed an issue where searching threat logs (Monitor > Logs > Threat) using the
+ partial hash parameter did not
+ work, which resulted in an invalid operator error.
+
+ |
+
|
+ PAN-204456
+ |
+
+
+ Fixed an issue related to the
+ logd
+ process that caused high memory consumption.
+
+ |
+
|
+ PAN-204335
+ |
+
+
+ Fixed an issue where Panorama became unresponsive, and when refreshed,
+ the error
+ 504 Gateway not Reachable was
+ displayed.
+
+ |
+
|
+ PAN-204307
+ |
+
+
+ (PA-5440, PA-5430, PA-5420 and PA-5410 firewalls only) Fixed an issue where, when moving interfaces from one aggregate
+ group to another while the interface's link state was down, traffic
+ was not properly routed through the aggregate group until after a
+ second commit.
+
+ |
+
|
+ PAN-204271
+ |
+
+
+ Fixed an issue where the quarantine device list did not display due to
+ the maximum memory being reached.
+
+ |
+
|
+ PAN-204238
+ |
+
+
+ Fixed an issue where, when
+ View Rulebase as Groups was enabled,
+ the Tags field did not display a
+ scroll down arrow for navigation.
+
+ |
+
|
+ PAN-204216
+ |
+
+
+ Fixed an issue where URL categorization failed and the firewall
+ displayed the URL category as
+ not-resolved for all traffic and
+ the following error message was displayed in the device server logs
+ Error(43): A libcurl function was given a bad argument.
+
+ |
+
|
+ PAN-204118
+ |
+
+
+ Fixed an issue where browser sessions stopped responding for device
+ group template admin users with access domains that had many device
+ groups or templates.
+
+ |
+
|
+ PAN-204068
+ |
+
+
+ Fixed an issue where a newly created vsys (virtual system) in a
+ template was not able to be pushed from Panorama to the firewall.
+
+ |
+
|
+ PAN-203964
+ |
+
+
+ (Firewalls in FIPS-CC mode only) Fixed an issue
+ where the firewall went into maintenance mode due to downloading a
+ corrupted software image, which resulted in the error message
+ FIPS-CC failure. Image File Authentication Error.
+
+ |
+
|
+ PAN-203851
+ |
+
+
+ Fixed an issue with firewalls in HA configurations where host
+ information profile (HIP) sync did not work between peer firewalls.
+
+ |
+
|
+ PAN-203796
+ |
+
+
+ Fixed an issue where legitimate syn+ack packets were dropped after an
+ invalid syn+ack packet was ingressed.
+
+ |
+
|
+ PAN-203681
+ |
+
+
+ (Panorama appliances in FIPS-CC mode only)
+ Fixed an issue where a leaf certificate was unable to be imported into
+ a template stack.
+
+ |
+
|
+ PAN-203663
+ |
+
+
+ Fixed an issue where administrators were unable to change the password
+ of a local database for users configured as a local admin user via an
+ authentication profile.
+
+ |
+
|
+ PAN-203653
+ |
+
+
+ Fixed an issue where dynamic updates were completed even when
+ configuration commits failed, which caused the
+ all_task
+ process to stop responding.
+
+ |
+
|
+ PAN-203618
+ |
+
+
+ Fixed an issue where, when SSL/TLS Handshake Inspection was enabled,
+ SSL/TLS sessions were incorrectly reset if a Security policy rule with
+ no Security profiles configured was matched.
+
+ |
+
|
+ PAN-203604
+ |
+
+
+ Fixed an issue where GlobalProtect authentication failed for SAML
+ username with a special character.
+
+ |
+
|
+ PAN-203563
+ |
+
+
+ Fixed an issue with Content and Threat Detection allocation storage
+ space where performing a commit failed with a
+ CUSTOM_UPDATE_BLOCK error
+ message.
+
+ |
+
|
+ PAN-203430
+ |
+
+
+ Fixed an issue where, when the User-ID agent had
+ collector name/secret configured,
+ the configuration was mandatory on clients on PAN-OS 10.0 and later
+ releases.
+
+ |
+
|
+ PAN-203402
+ |
+
+
+ Fixed an intermittent issue where forward session installs were
+ delayed, which resulted in latencies.
+
+ |
+
|
+ PAN-203362
+ |
+
+
+ Fixed an issue where the
+ rasmgr
+ process restarted due to a null reference.
+
+ |
+
|
+ PAN-203339
+ |
+
+
+ Fixed an issue where services failed due to the RAID rebuild not being
+ completed on time.
+
+ |
+
|
+ PAN-203330
+ |
+
+
+ Fixed an issue where the certificate for an External Dynamic List
+ (EDL) incorrectly changed from invalid to valid, which caused the EDL
+ file to be removed.
+
+ |
+
|
+ PAN-203320
+ |
+
+
+ Fixed an issue where configuring the firewall to connect with Panorama
+ using an auth key and creating the auth key without adding the managed
+ firewall to Panorama first, the auth key was incorrectly decreased
+ incrementally.
+
+ |
+
|
+ PAN-203147
+ |
+
+
+ (Firewalls in FIPS-CC mode only) Fixed an issue
+ where the firewall unexpectedly rebooted when downloading a new PAN-OS
+ software image.
+
+ |
+
|
+ PAN-203137
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ HSCI ports did not come up when QSFP DAC cables were used.
+
+ |
+
|
+ PAN-202946
+ |
+
+
+ Fixed an issue where the
+ request high-availability session-reestablish
+ command was not available for API.
+
+ |
+
|
+ PAN-202918
+ |
+
+
+ Fixed an issue where processing route-table entries did not work as
+ expected.
+
+ |
+
|
+ PAN-202872
+ |
+
+
+ Fixed an issue where an incorrect URL list limit displayed during a
+ commit.
+
+ |
+
|
+ PAN-202783
+ |
+
+
+ (PA-7000 Series firewalls with 100G NPC (Network Processing Cards)
+ only) Fixed an issue where sudden, large bursts of traffic destined for
+ an interface that was down caused packet buffers to fill, which
+ stalled path monitor heartbeat packets.
+
+ |
+
|
+ PAN-202722
+ |
+
+
+ Fixed an issue where the factor completion time for login events
+ learned through XML API displayed as
+ 1969/12/31 19:00:00.
+
+ |
+
|
+ PAN-202593
+ |
+
+
+ Fixed an issue where expanding Global Find results displayed only the
+ top level and second level of a searched item.
+
+ |
+
|
+ PAN-202544
+ |
+
+
+ An enhancement was made to collect CPLD register data after a path
+ monitor failure.
+
+ |
+
|
+ PAN-202543
+ |
+
+
+ An enhancement was made to improve path monitor data collection by
+ verifying the status of the control network.
+
+ |
+
|
+ PAN-202535
+ |
+
+
+ Fixed an issue where the Device Telemetry configuration for a region
+ was unable to be set or edited via the web interface.
+
+ |
+
|
+ PAN-202451
+ |
+
+
+ Fixed an issue where
+ Retrieve Framed-IP-Address attribute
+ from the authentication server fails generating GlobalProtect
+ connection failure with the error
+ Assign private IP address failed.
+
+ |
+
|
+ PAN-202450
+ |
+
+
+ Fixed an issue where the
+ device-client-cert was set to
+ expire on December 31, 2023. With this fix, the expiration date has
+ been extended.
+
+ |
+
|
+ PAN-202295
+ |
+
+
+ Fixed an issue where read-only superusers were unable to see the
+ Commit All job status, warnings, or errors for Panorama device groups.
+
+ |
+
|
+ PAN-202282
+ |
+
+
+ Fixed an issue where stats dump files did not display all necessary
+ reports.
+
+ |
+
|
+ PAN-202264
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ an automatic site license activation for a PAYG license did not
+ register in the Customer Support Portal.
+
+ |
+
|
+ PAN-202248
+ |
+
+
+ Fixed an issue where, due to a tunnel content inspection (TCI) policy
+ match, IPSec traffic did not pass through the firewall when NAT was
+ performed on the traffic.
+
+ |
+
|
+ PAN-202194
+ |
+
+
+ Fixed an SD-WAN link issue that occurred when Aggregate Ethernet
+ without a member interface was configured as an SD-WAN interface.
+
+ |
+
|
+ PAN-202140
+ |
+
+
+ Fixed an issue where the
+ comm
+ process stopped responding due to an OOM condition.
+
+ |
+
|
+ PAN-202101
+ |
+
+
+ Fixed an issue where firewalls stopped responding after an upgrade due
+ to configuration corruption.
+
+ |
+
|
+ PAN-202095
+ |
+
+
+ Fixed an issue on the web interface where the language setting is not
+ retained.
+
+ |
+
|
+ PAN-202040
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ ECDSA fingerprints were not displayed.
+
+ |
+
|
+ PAN-202012
+ |
+
+
+ A debug command was introduced to control Gzip encoding for the
+ GlobalProtect Clientless VPN application.
+
+ |
+
|
+ PAN-201973
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the management interface could not be assigned as an HA port.
+
+ |
+
|
+ PAN-201954
+ |
+
+
+ Fixed an issue where NAT policy rules were deleted on managed devices
+ after a successful push from Panorama to multiple device groups. This
+ occurred when NAT policy rules had
+ device_tags selected in the target
+ section.
+
+ |
+
|
+ PAN-201910
+ |
+
+
+ Fixed an issue where some Security profiles consumed a large amount of
+ memory, which reduced the number of supported Security profiles below
+ the stated maximum for a platform.
+
+ |
+
|
+ PAN-201900
+ |
+
+
+ Fixed an internal path monitoring failure issue that caused the
+ dataplane to go down.
+
+ |
+
|
+ PAN-201860
+ |
+
+
+ Fixed an issue where the
+ Device Quarantine list was not
+ redistributed or updated on Panorama and Prisma Access in a full mesh
+ topology.
+
+ |
+
|
+ PAN-201858
+ |
+
+
+ Fixed an issue where the SD-WAN interface Maximum Transmission Unit
+ (MTU) led to incorrect fragmentation of IPSec traffic.
+
+ |
+
|
+ PAN-201839
+ |
+
+
+ Fixed an issue where GlobalProtect HIP match failed for Mac users due
+ to invalid characters being present in the subject alternative
+ attributes in the certificate on the HIP report.
+
+ |
+
|
+ PAN-201818
+ |
+
+
+ Fixed an issue where INIT SCTP packets were dropped after being
+ processed by the CTD, and silent drops occurred even with SCTP no-drop
+ function enabled.
+
+ |
+
|
+ PAN-201714
+ |
+
+
+ Fixed an issue with GlobalProtect where attempting to authenticate
+ with the GlobalProtect gateway returned a 502 error code.
+
+ |
+
|
+ PAN-201701
+ |
+
+
+ Fixed an issue where the firewall generated system log alerts if the
+ raid for a system or log disk was corrupted.
+
+ |
+
|
+ PAN-201639
+ |
+
+
+ Fixed an issue with Saas Application Usage reports where
+ Applications with Risky Characteristics
+ displayed only two applications per section.
+
+ |
+
|
+ PAN-201632
+ |
+
+
+ Fixed an issue where the
+ all_task
+ stopped responding with a segmentation fault due to an invalid
+ interface port.
+
+ |
+
|
+ PAN-201601
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding after adding customer hyperscan signatures.
+
+ |
+
|
+ PAN-201587
+ |
+
+
+ Fixed an issue where the
+ App Pcaps directory size was
+ incorrectly detected which caused commit errors.
+
+ |
+
|
+ PAN-201580
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding due to an invalid vsys_id request.
+
+ |
+
|
+ PAN-201561
+ |
+
+
+ Fixed an issue where LSVPN satellite authentication cookies were not
+ synced across high availability LSVPN portals.
+
+ |
+
|
+ PAN-201360
+ |
+
+
+ Fixed an issue with Panorama managed log collector statistics where
+ the oldest logs displayed on the primary Panorama appliance and the
+ secondary Panorama appliance did not match.
+
+ |
+
|
+ PAN-201357
+ |
+
+
+ The CLI command
+ debug dataplane set pow no-desched yes
+ was added to address an issue where the
+ all_pktproc
+ process stopped responding and caused traffic issues.
+
+ |
+
|
+ PAN-201136
+ |
+
+
+ Fixed an issue where IGMP packets were offloaded with frequent IGMP
+ Join and Leave messages from the client.
+
+ |
+
|
+ PAN-201085
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ inserting the NPC and DPC on slot2 created excessive logs in the
+ bcm.log file.
+
+ |
+
|
+ PAN-200946
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where GRE tunnels went down due to recursive routing when the passive
+ firewall was booting up. When the passive firewall became active and
+ no recursive routing was configured, the GRE tunnel remained down.
+
+ |
+
|
+ PAN-200914
+ |
+
+
+ (PA-3440 firewalls only) Fixed an issue where
+ the default NAT DIPP pool oversubscription was set to 2 instead of 4.
+
+ |
+
|
+ PAN-200845
+ |
+
+
+ (M-600 Appliances in Management-only mode only)
+ Fixed an issue where XML API queries failed due to the configuration
+ size being larger than expected.
+
+ |
+
|
+ PAN-200774
+ |
+
+
+ Fixed an issue where SCEP certificate import did not work on the
+ firewall when the certificate name contained a period ( . ).
+
+ |
+
|
+ PAN-200676
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where the user counts in the management plane were not synchronized
+ between the active and the passive firewall.
+
+ |
+
|
+ PAN-200463
+ |
+
+
+ Fixed an issue where disabling
+ strict-username-check did not
+ apply to admin users authenticating with SAML.
+
+ |
+
|
+ PAN-200356
+ |
+
+
+ Fixed an issue where the
+ Elapsed seconds field incorrectly
+ displayed as 0 for DHCP packets coming from the firewall.
+
+ |
+
|
+ PAN-200354
+ |
+
+
+ Fixed an issue where the firewall did not initiate scheduled log
+ reports.
+
+ |
+
|
+ PAN-200160
+ |
+
+
+ Fixed a memory leak issue on Panorama related to the
+ logd
+ process that caused an out-of-memory (OOM) condition.
+
+ |
+
|
+ PAN-200116
+ |
+
+
+ Fixed an issue where Elasticsearch displayed red due to frequent
+ tunnel check failures between HA clusters.
+
+ |
+
|
+ PAN-200103
+ |
+
+
+ Fixed an issue where decryption logs were not displayed under
+ Manage Custom Reports for custom
+ Panorama admin users.
+
+ |
+
|
+ PAN-200102
+ |
+
+
+ Fixed an issue on the firewall web interface that prevented
+ applications from loading under any policy or in any location where
+ application IDs were able to be refreshed.
+
+ |
+
|
+ PAN-200035
+ |
+
+
+ Fixed an issue where the firewall reported
+ General TLS Protocol Error for
+ TLSv1.3 when the firewall closed a TCP connection to the server via a
+ FIN packet without waiting for the handshake to complete.
+
+ |
+
|
+ PAN-200019
+ |
+
+
+ Fixed an issue on Panorama where
+ Virtual Routers (Network > Virtual Routers) was not available when configuring a custom Panorama admin role
+ (Panorama > Admin Roles).
+
+ |
+
|
+ PAN-199965
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding on log collectors during query and report
+ operations due to a race condition between request handling threads.
+
+ |
+
|
+ PAN-199821
+ |
+
+
+ Fixed an issue where the
+ Include/Exclude IPs filter under
+ Data Redistribution did not
+ consistently filter IP addresses correctly.
+
+ |
+
|
+ PAN-199807
+ |
+
+
+ Fixed an issue where the dataplane frequently restarted due to high
+ memory usage on wifclient.
+
+ |
+
|
+ PAN-199726
+ |
+
+
+ Fixed an issue with firewalls in HA configurations where both
+ firewalls responded with gARP messages after a switchover.
+
+ |
+
|
+ PAN-199661
+ |
+
+
+ (VM-Series firewalls in ESXI environments only)
+ Fixed an issue where the number of used packet buffers was not
+ calculated properly, and packet buffers displayed as a higher value
+ than the correct value, which triggered PBP Alerts. This occurred when
+ the driver name was not compatible with new DPDK versions.
+
+ |
+
|
+ PAN-199612
+ |
+
+
+ Fixed a sync issue with firewalls in active/active HA configurations.
+
+ |
+
|
+ PAN-199570
+ |
+
+
+ Fixed an issue where uploading certificates using a custom admin role
+ did not work as expected after a context switch.
+
+ |
+
|
+ PAN-199543
+ |
+
+
+ Resolved failed authentication for Radius and TLS where shared secret
+ was striped for FIPS mode
+
+ |
+
|
+ PAN-199500
+ |
+
+
+ Fixed an issue where, when many NAT policy rules were configured, the
+ pan_comm
+ process stopped responding after a configuration commit due to a high
+ number of debug messages.
+
+ |
+
|
+ PAN-199410
+ |
+
+
+ Fixed an issue where system logs for
+ syslog
+ activities were categorized as
+ general under
+ Type and
+ EVENT columns.
+
+ |
+
|
+ PAN-199214
+ |
+
+
+ Fixed an intermittent issue where downloading
+ threat pcap via XML API failed
+ with the following error message:
+ /opt/pancfg/session/pan/user_tmp/XXXXX/YYYYY.pcap does not
+ exist.
+
+ |
+
|
+ PAN-199141
+ |
+
+
+ Fixed an issue where renaming a device group and then performing a
+ partial commit led to the device group hierarchy being incorrectly
+ changed.
+
+ |
+
|
+ PAN-198920
+ |
+
+
+ Fixed an issue where configuration changes caused a previously valid
+ interface ID to become invalid due to HA switchovers delaying the
+ configuration push.
+
+ |
+
|
+ PAN-198889
+ |
+
+
+ Fixed an issue where the
+ logd
+ process stopped responding if some devices in a collector group were
+ on a PAN-OS 10.1 device and others were on a PAN-OS 10.0 release. This
+ issue affected the devices on a PAN-OS 10.0 release.
+
+ |
+
|
+ PAN-198871
+ |
+
+
+ Fixed an issue when both URL and Advanced URL licenses were installed,
+ the expiry date was not correctly checked.
+
+ |
+
|
+ PAN-198718
+ |
+
+
+ (PA-5280 firewalls only) Fixed an issue where
+ memory allocation failures caused increased decryption failures.
+
+ |
+
|
+ PAN-198693
+ |
+
+
+ Fixed an issue where decrypted SSH sessions were interrupted with a
+ decryption error.
+
+ |
+
|
+ PAN-198691
+ |
+
+
+ Added an alternate health endpoint to direct health probes on the
+ firewall (https://firewall/unauth/php/health.php) to address an issue
+ where /php/login.php performance
+ was slow when large amounts of traffic were being processed.
+
+ |
+
|
+ PAN-198575
+ |
+
+
+ Fixed an issue where data did not load when filtering by
+ Threat Name (ACC > Threat Activity).
+
+ |
+
|
+ PAN-198333
+ |
+
+
+ Fixed an issue where the SaaS PDF report incorrectly displayed the
+ sanctioned application tag count as 1.
+
+ |
+
|
+ PAN-198306
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process stopped responding when booting up the firewall.
+
+ |
+
|
+ PAN-198174
+ |
+
+
+ Fixed an issue where, when viewing traffic or threat logs from the
+ Application Command Center (ACC) or
+ Monitor tabs, performing a reverse
+ DNS lookup caused the
+ dnsproxy
+ process to restart if DNS server settings were not configured.
+
+ |
+
|
+ PAN-198078
+ |
+
+
+ Fixed an issue where VXLAN keepalive packets were dropped randomly.
+
+ |
+
|
+ PAN-198038
+ |
+
+
+ A CLI command was added to address an issue where long-lived sessions
+ were aging out even when there was ongoing traffic.
+
+ |
+
|
+ PAN-197953
+ |
+
+
+ Fixed an issue where the
+ logd
+ process stopped responding due to forwarded threat logs, which caused
+ Panorama to reboot into maintenance mode.
+
+ |
+
|
+ PAN-197935
+ |
+
+
+ Fixed an intermittent issue where XML API IP address tag registration
+ failed on firewalls in a multi-vsys environment.
+
+ |
+
|
+ PAN-197919
+ |
+
+
+ Fixed an issue where, when path monitoring for a static route was
+ configured with a new Ping Interval value, the value was not used as
+ intended.
+
+ |
+
|
+ PAN-197908
+ |
+
+
+ Fixed an issue where
+ Strata Logging Service flaps occurred for long
+ durations which caused a memory leak related to the
+ mgmtsrvr process.
+
+ |
+
|
+ PAN-197877
+ |
+
+
+ Fixed an intermittent issue on Panorama where the
+ distributord
+ process stopped responding.
+
+ |
+
|
+ PAN-197872
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process generated false positive critical errors.
+
+ |
+
|
+ PAN-197847
+ |
+
+
+ Fixed an issue where disabling the
+ enc-algo-aes-128-gcm cipher did
+ not work when using an SSL/TLS profile.
+
+ |
+
|
+ PAN-197737
+ |
+
+
+ Fixed an issue where the connection to the PAN-DB server failed with
+ following error message:
+ Failed to send req type[3], curl error: Couldn't resolve host
+ name.
+
+ |
+
|
+ PAN-197729
+ |
+
+
+ Fixed an issue where repeated configuration pushes from Panorama
+ resulted in a management server memory leak.
+
+ |
+
|
+ PAN-197678
+ |
+
+
+ Fixed an issue where the dataplane stopped responding, which caused
+ internal path monitoring failure.
+
+ |
+
|
+ PAN-197582
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.1.6, the firewall
+ reset SSL connections that used policy-based forwarding.
+
+ |
+
|
+ PAN-197563
+ |
+
+
+ Fixed an issue in the User Activity Report where output fields started
+ with the letter
+ b.
+
+ |
+
|
+ PAN-197549
+ |
+
+
+ Fixed an issue where making GlobalProtect gateway configuration
+ changes resulted in a HIP notification error.
+
+ |
+
|
+ PAN-197426
+ |
+
+
+ Fixed an issue on Panorama where, when attempting to view the
+ Monitor page, the error
+ invalid term was displayed.
+
+ |
+
|
+ PAN-197386
+ |
+
+
+ Fixed an issue where traffic that was subject to network packet broker
+ inspection entered a looping state due to incorrect session offload.
+
+ |
+
|
+ PAN-197339
+ |
+
+
+ Fixed an issue where template configuration for the User-ID agent was
+ not reflected on the template stack on Panorama appliances on PAN-OS
+ 10.2.1.
+
+ |
+
|
+ PAN-197298
+ |
+
+
+ Fixed an issue where the audit comment archive for Security rule
+ changes output had overlapping formats.
+
+ |
+
|
+ PAN-197203
+ |
+
+
+ Fixed an intermittent issue where, if SSL/TLS Handshake Inspection was
+ enabled, multiple processes stopped responding when the firewall was
+ processing packets.
+
+ |
+
|
+ PAN-197121
+ |
+
+
+ Fixed an issue where incorrect user details were displayed under the
+ USER DETAIL drop-down (ACC > Network activity > User activity).
+
+ |
+
|
+ PAN-197115
+ |
+
+
+ Fixed an issue where, when the total number of in-used HIP profiles
+ was greater than 32, traffic from the GlobalProtect Agent did not hit
+ the expected Security policy rule configured with the HIP profile even
+ though a HIP match log was generated.
+
+ |
+
|
+ PAN-197097
+ |
+
+
+ Fixed an issue where LSVPN did not support IPv6 addresses on the
+ satellite firewall.
+
+ |
+
|
+ PAN-196954
+ |
+
+
+ Fixed a memory leak issue related to the
+ distributord
+ process.
+
+ |
+
|
+ PAN-196874
+ |
+
+
+ Fixed an issue where, when the firewall accepted ICMP redirect
+ messages on the management interface, the firewall did not clear the
+ route from the cache.
+
+ |
+
|
+ PAN-196840
+ |
+
+
+ Fixed an issue where exporting a Security policy rule that contained
+ Korean language characters to CSV format resulted in the policy
+ description being in a non-readable format.
+
+ |
+
|
+ PAN-196811
+ |
+
+
+ Fixed an issue where logout events without a username caused high CPU
+ usage.
+
+ |
+
|
+ PAN-196715
+ |
+
+
+ Fixed an issue where you could not directly edit
+ Services and
+ Address objects from the
+ Policies tab.
+
+ |
+
|
+ PAN-196704
+ |
+
+
+ Fixed an issue where
+ Preview Changes on Panorama Push to Devices
+ incorrectly displayed changes to encrypted entries.
+
+ |
+
|
+ PAN-196701
+ |
+
+
+ Fixed an issue where the firewall did not properly measure the
+ Panorama connection keepalive timer, which caused a Panorama HA
+ failover to take longer than expected.
+
+ |
+
|
+ PAN-196671
+ |
+
+
+ (PA-3400 Series firewalls and PA-5410, PA-5420, and PA-5430
+ firewalls only) Addressed an issue to improve network latency,
+
+ |
+
|
+ PAN-196583
+ |
+
+
+ Fixed an issue where the Cisco TrustSEc plugin triggered a flood of
+ redundant register/unregister messages due to a failed IP address tag
+ database search.
+
+ |
+
|
+ PAN-196566
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process restarted repeatedly which let to an OOM condition.
+
+ |
+
|
+ PAN-196558
+ |
+
+
+ Fixed an issue where IP address tag policy updates were delayed.
+
+ |
+
|
+ PAN-196474
+ |
+
+
+ Fixed an issue where, when a decryption profile was configured with
+ TLSv1.2 or later, web pages utilizing TLS1.0 were blocked with an
+ incorrect ERR_TIME_OUT message
+ instead of an
+ ERR_CONNECTION_RESET message.
+
+ |
+
|
+ PAN-196467
+ |
+
+
+ Fixed an issue where enabling strict IP address checks in a Zone
+ Protection profile caused GRE tunnel packets to be dropped.
+
+ |
+
|
+ PAN-196457
+ |
+
+
+ Fixed an issue where extraneous logs displayed in the Traffic log when
+ Security policy settings were changed.
+
+ |
+
|
+ PAN-196452
+ |
+
+
+ Fixed an issue where DNS queries failed from source port 4789 with a
+ NAT configuration.
+
+ |
+
|
+ PAN-196450
+ |
+
+
+ Fixed an issue where certificates with whitespaces in the name or
+ common name (CN) were not able to be imported.
+
+ |
+
|
+ PAN-196410
+ |
+
+
+ Fixed an issue where you were unable to customize the risk value in
+ Risk-of-app.
+
+ |
+
|
+ PAN-196309
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where a
+ firewall configured with a Policy-Based Forwarding policy flapped when
+ a commit was performed, even when the next hop was reachable.
+
+ |
+
|
+ PAN-196131
+ |
+
+
+ Fixed an issue where the
+ comm
+ process stopped responding when a show command was executed in two
+ sessions.
+
+ |
+
|
+ PAN-196105
+ |
+
+
+ Fixed an issue on the firewall where using special characters in a
+ password caused authentication to fail when connecting to the
+ GlobalProtect portal with GlobalProtect satellite configured.
+
+ |
+
|
+ PAN-196050
+ |
+
+
+ Fixed an issue on Panorama where logs did not populate when one log
+ collector in a log collector group was down.
+
+ |
+
|
+ PAN-196003
+ |
+
+
+ Fixed an issue where the
+ Adjust Columns options for Panorama
+ traffic logs did not correctly auto-adjust the columns.
+
+ |
+
|
+ PAN-195988
+ |
+
+
+ Fixed an issue where commits failed when an AS path regular expression
+ that included the ( _ ) character was specified in the virtual router
+ BGP configuration export rule.
+
+ |
+
|
+ PAN-195893
+ |
+
+
+ Fixed an issue where daily PDF summary reports were not generated when
+ the Application Report was selected.
+
+ |
+
|
+ PAN-195869
+ |
+
+
+ Fixed an issue where scheduled custom reports based on firewall data
+ did not display any information.
+
+ |
+
|
+ PAN-195828
+ |
+
+
+ Fixed an issue where SNMP reported the
+ panVsysActiveTcpCps and
+ panVsysActiveUdpCps value to be
+ 0.
+
+ |
+
|
+ PAN-195792
+ |
+
+
+ Fixed an issue where, when generating a stats dump file for a managed
+ device from Panorama (Panorama > Support > Stats Dump File), the file did not display any data.
+
+ |
+
|
+ PAN-195790
+ |
+
+
+ Fixed an issue where syslog traffic that was sent from the management
+ interface to the syslog server even when a destination IP address
+ service route was configured.
+
+ |
+
|
+ PAN-195713
+ |
+
+
+ Fixed an issue where clientless VPN applications were not displayed in
+ the GlobalProtect portal page.
+
+ |
+
|
+ PAN-195695
+ |
+
+
+ Fixed an issue where the AppScope Summary report and PDF report export
+ function did not work as expected.
+
+ |
+
|
+ PAN-195669
+ |
+
+
+ Fixed an issue with Panorama appliances in HA configurations where a
+ passive Panorama appliance generated
+ CMS Redistribution Client is connected to global collector
+ messages.
+
+ |
+
|
+ PAN-195659
+ |
+
+
+ Fixed an issue with firewalls in HA configurations where ping
+ responses from the target IP addresses were much delayed after a
+ configuration push.
+
+ |
+
|
+ PAN-195583
+ |
+
+
+ Fixed an issue where, after renaming an object, configuration pushes
+ from Panorama failed with the commit error
+ object name is not an allowed keyword.
+
+ |
+
|
+ PAN-195526
+ |
+
+
+ Fixed an issue where the firewall system log received a large amount
+ of error messages when attempting a connection between the firewall
+ and Panorama.
+
+ |
+
|
+ PAN-195374
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where, when redistribution agent connections to the
+ passive firewall failed, excessive system alerts for the failed
+ connection were generated. With this fix, system alerts are logged
+ every 5 hours instead of 10 minutes.
+
+ |
+
|
+ PAN-195201
+ |
+
+
+ Fixed an issue where high volume DNS Security traffic caused the
+ firewall to reboot.
+
+ |
+
|
+ PAN-195200
+ |
+
+
+ Fixed an issue where Panorama did not attach and email scheduled
+ reports (Monitor > PDF > Reports > Email Scheduler) when the size of the email attachments was large.
+
+ |
+
|
+ PAN-195114
+ |
+
+
+ Fixed an issue where proxy ARP responded on the wrong interface when
+ the same subnet was in two virtual routers.
+
+ |
+
|
+ PAN-195107
+ |
+
+
+ (PA-7000s Series firewalls with LFCs only)
+ Fixed an issue where the IP address of the LFC displayed as
+ unknown.
+
+ |
+
|
+ PAN-195064
+ |
+
+
+ Fixed an issue where the log collector did not forward correlation
+ logs to the syslog server.
+
+ |
+
|
+ PAN-194912
+ |
+
+
+ Fixed an issue where the CLI command
+ show applications list did not
+ return any outputs.
+
+ |
+
|
+ PAN-194812
+ |
+
+
+ Fixed an issue where generating reports via XML API failed when the
+ serial number was set as
+ target in the query.
+
+ |
+
|
+ PAN-194805
+ |
+
+
+ Fixed an issue where scheduled configuration backups to the SCP server
+ failed with error message
+ No ECDSA host key is known.
+
+ |
+
|
+ PAN-194737
+ |
+
+
+ Fixed an issue where path monitor displayed as deleted when it was
+ disabled, which caused a preview change in the summary for static
+ routes.
+
+ |
+
|
+ PAN-194704
+ |
+
+
+ Fixed an issue with SIP ALG where improper NAT was applied when
+ Destination NAT ran out of IP addresses.
+
+ |
+
|
+ PAN-194615
+ |
+
+
+ Fixed an issue where the packet broker session timeout value did not
+ match the master sessions timeout value after the firewall received a
+ TCP FIN or RST packet. The fix ensures that Broker session times out
+ within 1 second after the master session timed out.
+
+ |
+
|
+ PAN-194441
+ |
+
+
+ Fixed an issue where the dataplane CPU usage was higher than expected
+ due to packet looping in the broker session when the network packet
+ broker was enabled.
+
+ |
+
|
+ PAN-194175
+ |
+
+
+ Fixed an issue on Panorama where a commit push to managed firewalls
+ failed when objects were added as source address exclusions in a
+ Security policy and
+ Share Unused Address and Service Objects with Devices
+ was unchecked.
+
+ |
+
|
+ PAN-194068
+ |
+
+
+ (PA-5200 Series firewalls only) Fixed an issue
+ where the firewall unexpectedly rebooted with the log message
+ Heartbeat failed previously.
+
+ |
+
|
+ PAN-194043
+ |
+
+
+ Fixed an issue where
+ Managed Devices > Summary did not
+ reflect new tag values after an update.
+
+ |
+
|
+ PAN-194031
+ |
+
+
+ (PA-220 Firewalls only) Fixed an issue where
+ system log configurations did not work as expected due to insufficient
+ process timeout after a
+ logrcvr
+ process restart.
+
+ |
+
|
+ PAN-194025
+ |
+
+
+ Fixed an issue where the
+ ikemgr
+ process stopped responding due to a timing issue, which caused VPN
+ tunnels to go down.
+
+ |
+
|
+ PAN-193879
+ |
+
+
+ Fixed an issue on Panorama where the push scope was delayed for commit
+ and push operations.
+
+ |
+
|
+ PAN-193831
+ |
+
+
+ Fixed an issue where internal routes were added to the routing table
+ even after disabling dynamic routing protocols.
+
+ |
+
|
+ PAN-193808
+ |
+
+
+ Fixed a memory leak issue in the
+ mgmtsrvr
+ process that resulted in an OOM condition.
+
+ |
+
|
+ PAN-193733
+ |
+
+
+ (Firewalls in multi-vsys environments only)
+ Fixed an issue where IP tag addresses were not synced to all virtual
+ systems (vsys) when they were pushed to the firewall from Panorama via
+ XML API.
+
+ |
+
|
+ PAN-193619
+ |
+
+
+ Fixed an issue where air gapped firewalls and Panorama appliances
+ performed excessive validity checks to updates.paloaltonetworks.com,
+ which caused software installs to fail.
+
+ |
+
|
+ PAN-193558
+ |
+
+
+ Fixed an issue where log retention settings
+ Multi Disk did not display correct
+ values on the firewall web interface when the settings were configured
+ using a Panorama template or template stack.
+
+ |
+
|
+ PAN-193396
+ |
+
+
+ Fixed an issue where the source user name was displayed in traffic
+ logs even when
+ Show User Names In Logs and Reports
+ was disabled for a custom admin role.
+
+ |
+
|
+ PAN-193323
+ |
+
+
+ Fixed an issue where root partition utilization reached 100% due to
+ mdb old logs not being purged as expected.
+
+ |
+
|
+ PAN-193281
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding after a content update on the firewall.
+
+ |
+
|
+ PAN-193245
+ |
+
+
+ Fixed an issue where, when using
+ syslog-ng forwarding via SSL,
+ with a Base Common Name (CN) and multiple Subject Alternative Names
+ (SANs) were listed in the certificate.
+
+ |
+
|
+ PAN-193175
+ |
+
+
+ Fixed an issue where
+ PBP Drops (8507) threat logs were
+ incorrectly logged as
+ SCTP Init Flood (8506).
+
+ |
+
|
+ PAN-193043
+ |
+
+
+ Fixed an issue with the where firewalls in Google Cloud Platforms
+ (GCP) inserted the hostname as
+ PA-VM in the syslog header
+ instead of the DHCP assigned hostname when logs were being sent to the
+ syslog server.
+
+ |
+
|
+ PAN-193026
+ |
+
+
+ Fixed an issue where warning messages were generated during commits
+ when configuration details of two profiles were identical.
+
+ |
+
|
+ PAN-192681
+ |
+
+
+ Fixed an issue where HIP database storage on the firewall reached full
+ capacity due to the firewall not purging older HIP reports.
+
+ |
+
|
+ PAN-192513
+ |
+
+
+ Fixed an issue where log migration did not work when converting a
+ Legacy mode Panorama appliance to Log Collector mode.
+
+ |
+
|
+ PAN-192456
+ |
+
+
+ Fixed an issue where GlobalProtect SSL VPN processing during a high
+ traffic load caused the dataplane to stop responding.
+
+ |
+
|
+ PAN-192417
+ |
+
+
+ Fixed an issue where botnet reports were not generated on the
+ firewall.
+
+ |
+
|
+ PAN-192296
+ |
+
+
+ Fixed an issue where, when you saved a SaaS application report as a
+ PDF or sent it to print, the size of the report was smaller than
+ expected.
+
+ |
+
|
+ PAN-192244
+ |
+
+
+ Fixed an issue where scheduled log export jobs continued to run even
+ after being deleted.
+
+ |
+
|
+ PAN-192193
+ |
+
+
+ Fixed an issue where exporting a list of managed collectors via the
+ Panorama web interface failed with the following error message:
+ Export Error, Error while exporting
+
+ |
+
|
+ PAN-192188
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the
+ show running resource-monitor ingress-backlogs
+ CLI command failed with the following error message:
+ Server error : Failed to intepret the DP response.
+
+ |
+
|
+ PAN-192092
+ |
+
+
+ Fixed an issue with firewalls in active/passive configurations only
+ where the registered cookie from the satellite firewall to the passive
+ firewall did not sync, which caused authentication between the
+ satellite firewall and the GlobalProtect portal firewall to fail after
+ a failover event.
+
+ |
+
|
+ PAN-192076
+ |
+
+
+ Added debug logs for visibility into an OpenSSL memory initialization
+ issue that caused unexpected failovers.
+
+ |
+
|
+ PAN-191997
+ |
+
+
+ Fixed an issue where log queries did not successfully filter the
+ unknown category.
+
+ |
+
|
+ PAN-191652
+ |
+
+
+ Fixed an issue with Prisma Cloud where a commit push failed due to the
+ error
+ Error: failed to handle TDB_UPDATE_BLOCK.
+
+ |
+
|
+ PAN-191463
+ |
+
+
+ Fixed an issue where the firewall did not handle packets at Fastpath
+ when the interface pointer was null.
+
+ |
+
|
+ PAN-191408
+ |
+
+
+ Fixed an issue where the firewall did not correctly receive dynamic
+ address group information from Panorama after a reboot or initial
+ connection.
+
+ |
+
|
+ PAN-191390
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the management plane CPU was incorrectly calculated as high when
+ logged in the mp-monitor.log.
+
+ |
+
|
+ PAN-191352
+ |
+
+
+ Fixed an intermittent issue where high latency was observed on the web
+ interface and CLI due to high CPU usage related to the
+ sadc
+ process.
+
+ |
+
|
+ PAN-191235
+ |
+
+
+ Fixed an issue with firewalls in HA configurations where the passive
+ firewall attempted to connect to a hardware security module (HSM)
+ client when a service route was configured, which caused dynamic
+ updates and software updates to fail.
+
+ |
+
|
+ PAN-191032
+ |
+
+
+ Fixed an issue on Panorama where
+ Managed Devices displayed
+ Unknown.
+
+ |
+
|
+ PAN-190533
+ |
+
+
+ Fixed an issue where addresses and address groups were not displayed
+ for users in Security admin roles.
+
+ |
+
|
+ PAN-190502
+ |
+
+
+ Fixed an issue where the Policy filter and Policy optimizer filter
+ were required to have the exact same syntax, including nested
+ conditions with rules that contained more than one tag when filtering
+ via the neq operator.
+
+ |
+
|
+ PAN-190454
+ |
+
+
+ Fixed an issue where, while authenticating, the allow list check
+ failed for vsys users when a SAML authentication profile was
+ configured under shared location.
+
+ |
+
|
+ PAN-190409
+ |
+
+
+ (PA-5450 and PA-3200 Series firewalls that use an FE101 processor
+ only) Fixed an issue where packets in the same session were forwarded
+ through a different member of an aggregate ethernet group when the
+ session was offloaded. The fix is that you can use the following CLI
+ command to change the default tag setting to the tuple setting:
+
+
+ admin@firewall> set session lag-flow-key-type ?
+
+ > tag tag
+
+ > tuple tuple
+
+
+ tag is the default behavior (tag
+ based on the CPU, tuple based on the FE).
+
+
+ tuple is the new behavior, where
+ both CPU and FE use the same selection algorithm.
+
+ Use the following command to display the algorithm:
+
+ admin@firewall> show session lag-flow-key-type
+
+
+ dp0: tuple based on fe100
+
+
+ dp1: tuple based on fe100
+
+ |
+
|
+ PAN-190266
+ |
+
+
+ Fixed an issue that stopped the
+ all_task
+ process to stop responding at the
+ pan_sdwan_qualify_if_ini
+ function.
+
+ |
+
|
+ PAN-189960
+ |
+
+
+ Fixed an issue on Panorama where you were unable to view the last
+ address object moved to the shared template list.
+
+ |
+
|
+ PAN-189866
+ |
+
+
+ Fixed an issue with the web interface where group include lists used
+ server profiles instead of LDAP proxy.
+
+ |
+
|
+ PAN-189783
+ |
+
+
+ Fixed an issue where container resource limits were not enforced for
+ all processes when running inside a container.
+
+ |
+
|
+ PAN-189719
+ |
+
+
+ Fixed an issue on Panorama where
+ Test Server Connection failed in an
+ HTTP server profile with the following error message:
+ failed binding local connection end.
+
+ |
+
|
+ PAN-189718
+ |
+
+
+ Fixed an issue where the number of sessions did not reach the expected
+ maximum value with Security profiles.
+
+ |
+
|
+ PAN-189666
+ |
+
+
+ Fixed an issue where GlobalProtect portal connections failed after
+ random commits when multiple agent configurations were provisioned and
+ configuration selection criteria using certificate profile was used.
+
+ |
+
|
+ PAN-189643
+ |
+
+
+ Fixed an issue where, when QoS was enabled on an IPSec tunnel, traffic
+ failed due to applying the wrong tunnel QoS ID.
+
+ |
+
|
+ PAN-189518
+ |
+
+
+ Fixed an issue where incoming DNS packets with looped compression
+ pointers caused the
+ dnsproxyd
+ process to stop responding.
+
+ |
+
|
+ PAN-189425
+ |
+
+
+ Fixed an issue on Panorama where
+ Export Panorama and devices config bundle
+ (Panorama > Setup > Operations) failed with the following error message:
+ Failed to redirect error to /var/log/pan/appweb3-panmodule.log
+ (Permission denied).
+
+ |
+
|
+ PAN-189379
+ |
+
+
+ Fixed an issue where FQDN based Security policy rules did not match
+ correctly.
+
+ |
+
|
+ PAN-189375
+ |
+
+
+ Fixed an issue where, when migrating the firewall, the firewall
+ dropped packets when trying to re-use the TCP session.
+
+ |
+
|
+ PAN-189335
+ |
+
+
+ Fixed an issue where the
+ varrcvr
+ process restarted repeatedly, which caused the firewall to restart.
+
+ |
+
|
+ PAN-189300
+ |
+
+
+ Fixed an issue where Panorama appliances in active/passive HA
+ configurations reported the false positive system log
+ Failed to sync vm-auth-key when a
+ VM authentication key was generated on the active appliance.
+
+ |
+
|
+ PAN-189200
+ |
+
+
+ Fixed an issue where sinkholes did not occur for AWS Gateway Load
+ Balancer dig queries.
+
+ |
+
|
+ PAN-189027
+ |
+
+
+ Fixed an issue where the dataplane CPU utilization provided from the
+ web interface or via SNMP was incorrect.
+
+ |
+
|
+ PAN-188933
+ |
+
+
+ Fixed an issue where the UDP checksum wasn't correctly calculated for
+ VXLAN traffic after applying NAT.
+
+ |
+
|
+ PAN-188912
+ |
+
+
+ Fixed an issue where authentication failed due to a process
+ responsible for handling authentication requests going into an
+ irrecoverable state.
+
+ |
+
|
+ PAN-188519
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue
+ where, when manually deactivating the license, the admin user did not
+ receive the option to download the token file and upload it to the
+ Customer Support Portal (CSP) to deactivate the license.
+
+ |
+
|
+ PAN-188904
+ |
+
+
+ Fixed an issue where web pages and web page contents were not properly
+ loaded when cloud inline categorization was enabled.
+
+ |
+
|
+ PAN-188506
+ |
+
+
+ Fixed an issue where the
+ ctd_dns_malicious_fwd counter
+ incorrectly increased incrementally.
+
+ |
+
|
+ PAN-188403
+ |
+
+
+ Fixed an issue on the web interface where the interzone-default rule
+ hit count was not displayed.
+
+ |
+
|
+ PAN-188348
+ |
+
+
+ Fixed an issue where encapsulating Security payload packets
+ originating from the firewall were dropped when strict IP address
+ check was enabled in a zone protection profile.
+
+ |
+
|
+ PAN-188291
+ |
+
+
+ Fixed an issue where, when using Global Find on the web interface to
+ search for a given
+ Hostname Configuration (Device > Setup > Management), clicking the search result directed you to the appropriate Hostname
+ configuration, but did not change the respective
+ Template field automatically.
+
+ |
+
|
+ PAN-188272
+ |
+
+
+ (PA-5200 Series and PA-7000 Series firewalls only) Fixed an issue where
+ Support UTF-8 For Log Output wasn't
+ visible on the web interface.
+
+ |
+
|
+ PAN-188118
+ |
+
+
+ Fixed an issue with firewalls in FIPS mode that prevented device
+ telemetry from connecting.
+
+ |
+
|
+ PAN-187763
+ |
+
+
+ Fixed an issue where DNS Security logs did not display a threat
+ category, threat name, or threat ID when domain names contained 64 or
+ more characters.
+
+ |
+
|
+ PAN-187438
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where HSCI interfaces didn’t come up when using BiDi transceivers.
+
+ |
+
|
+ PAN-187279
+ |
+
+
+ Fixed an issue where not all quarantined devices were displayed as
+ expected.
+
+ |
+
|
+ PAN-186530
+ |
+
+
+ Fixed an issue where the current date was incorrectly printed as the
+ last license check date.
+
+ |
+
|
+ PAN-186471
+ |
+
+
+ Fixed an issue where, when exporting to CSV in Global Find, the
+ firewall truncated names of rules that contained over 40 characters.
+
+ |
+
|
+ PAN-186412
+ |
+
+
+ Fixed an issue where invalid
+ packet-ptr was seen in work
+ entries.
+
+ |
+
|
+ PAN-186294
+ |
+
+
+ Fixed an issue where commits from Panorama failed on the firewall due
+ to the virtual router name character limit.
+
+ |
+
|
+ PAN-186270
+ |
+
+
+ Fixed an issue where, when HA was enabled and a dynamic update
+ schedule was configured, the
+ configd
+ process unexpectedly stopped responding during configuration commits.
+
+ |
+
|
+ PAN-185770
+ |
+
+
+ Fixed an issue where the firewall displayed the error message
+ Malformed Request when an email
+ address included an ampersand ( & ) when configuring an email
+ server profile.
+
+ |
+
|
+ PAN-185466
+ |
+
+
+ Fixed an issue where WildFire submission did not work as expected.
+
+ |
+
|
+ PAN-185394
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where not all changes to the template were reflected on the firewall.
+
+ |
+
|
+ PAN-185360
+ |
+
+
+ Fixed an issue where, when Captive Portal Authentication was
+ configured,
+ l3svc_ngx_error.log and
+ l3svc_access.log did not roll
+ over after exceeding 10 megabytes, which caused the root partition to
+ reach full utilization.
+
+ |
+
|
+ PAN-185287
+ |
+
+
+ (PA-7050 firewalls with Network Processing Cards (NPCs) only) Debug commands were added to address an issue where the firewall's
+ NPC Slot2 failed and multiple dataplane processes stopped responding.
+
+ |
+
|
+ PAN-185234
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the packet buffer utilization was displayed as high even when no
+ traffic was traversing the firewall.
+
+ |
+
|
+ PAN-184744
+ |
+
+
+ Fixed an issue where the firewall did not decrypt SSL traffic due to a
+ lack of internal resources allocated for decryption.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Fixed an issue where scheduled report emails (Monitor>PDF Reports>Email Scheduler) were not emailed as expected if they included a SaaS Application
+ Usage report.
+
+ |
+
|
+ PAN-183524
+ |
+
+
+ Fixed an issue where GTPv2-c and GTP-U traffic was identified with
+ insufficient-data in the traffic
+ logs.
+
+ |
+
|
+ PAN-183375
+ |
+
+
+ Fixed an issue where traffic arriving on a tunnel with a bad IP
+ address header checksum was not dropped.
+
+ |
+
|
+ PAN-183126
+ |
+
+
+ Fixed an issue on Panorama where you were able to attempt to push a
+ number of active schedules to the firewall that was greater than the
+ firewall's maximum capacity.
+
+ |
+
|
+ PAN-182875
+ |
+
+
+ Fixed an issue where certificate generation using SCEP did not take
+ more than one organizational unit (OU).
+
+ |
+
|
+ PAN-182732
+ |
+
+
+ Fixed an issue where the GlobalProtect gateway inactivity timer wasn't
+ refreshed even though traffic was passing through the tunnel.
+
+ |
+
|
+ PAN-182167
+ |
+
+
+ Removed a duplicate save filter Icon in the Audit Comment Archive for
+ Security Rule Audit Comments tab.
+
+ |
+
|
+ PAN-181968
+ |
+
+
+ (PA-400 Series firewalls in active/passive HA configurations
+ only) Fixed an issue where, when HA failover occurred, link up on all
+ ports took longer than expected, which caused traffic outages.
+
+ |
+
|
+ PAN-181334
+ |
+
+
+ Fixed an issue where users with custom admin roles and access domains
+ were unable to view address objects or edit Security rules.
+
+ |
+
|
+ PAN-181129
+ |
+
+
+ Improved protection against unexpected packets and error handling for
+ traffic identified as SIP.
+
+ |
+
|
+ PAN-180948
+ |
+
+
+ Fixed an issue where an external dynamic list fetch failed with the
+ error message
+ Unable to fetch external dynamic list. Couldn't resolve host name.
+ Using old copy for refresh.
+
+ |
+
|
+ PAN-180690
+ |
+
+
+ Fixed an issue where the firewall dropped IPv6 Bi-Directional
+ Forwarding (BFD) packets when IP Spoofing was enabled in a Zone
+ Protection Profile.
+
+ |
+
|
+ PAN-179174
+ |
+
+
+ Fixed an issue where exported PDF report of the ACC was the incorrect
+ color after upgrading from a PAN-OS 10.1 or later release.
+
+ |
+
|
+ PAN-178951
+ |
+
+
+ Fixed an issue on the firewall where Agentless User-ID lost parent
+ Security group information after the Security group name of the nested
+ groups on Active Directory was changed.
+
+ |
+
|
+ PAN-178728
+ |
+
+
+ Fixed an issue where the
+ dcsd
+ process stopped responding when attempting to read the config to
+ update its redis database.
+
+ |
+
|
+ PAN-177942
+ |
+
+
+ Fixed an issue where, when grouping HA peers, access domains that were
+ configured using multi-vsys firewalls deselected devices or virtual
+ systems that were in other configured access domains.
+
+ |
+
|
+ PAN-177562
+ |
+
+
+ Fixed an issue where PDF reports were not translated to the configured
+ local language.
+
+ |
+
|
+ PAN-177201
+ |
+
+
+ Fixed an issue where, when a Panorama appliance on a PAN-OS 9.0 or
+ later release pushed built-in external dynamic lists to a firewall on
+ a PAN-OS 8.1 release, the external dynamic list was removed, but the
+ rule was still pushed to the firewall. With this fix, Panorama will
+ show a validation error when attempting to push a pre-defined external
+ dynamic list to a firewall on a PAN-OS 8.1 release.
+
+ |
+
|
+ PAN-176989
+ |
+
+
+ Fixed an issue where the CLI command to show SD-WAN tunnel members
+ caused the firewall to stop responding.
+
+ |
+
|
+ PAN-176379
+ |
+
+
+ Fixed an issue where, when multiple routers were configured under a
+ Panorama template, you were only able to select its own virtual router
+ for next hop.
+
+ |
+
|
+ PAN-175244
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when adding, deleting or listing an
+ authentication key.
+
+ |
+
|
+ PAN-175142
+ |
+
+
+ Fixed an issue on Panorama where executing a debug command caused the
+ logrcvr
+ process to stop responding.
+
+ |
+
|
+ PAN-175061
+ |
+
+
+ Fixed an issue where filtering threat logs using any value under
+ THREAT ID/NAME displayed the error
+ Invalid term.
+
+ |
+
|
+ PAN-174953
+ |
+
+
+ Fixed an issue where the firewall didn't update URL categories from
+ the management plane to the dataplane cache.
+
+ |
+
|
+ PAN-174781
+ |
+
+
+ Fixed an issue where the firewall did not send an SMTP 541 error
+ message to the email client after detecting a malicious file
+ attachment.
+
+ |
+
|
+ PAN-174680
+ |
+
+
+ Fixed an issue where, when adding new configurations, Panorama didn't
+ display a list of suggested template variables when typing in a
+ relevant field.
+
+ |
+
|
+ PAN-174027
+ |
+
+
+ Fixed an issue on Panorama where attempting to rename mapping for
+ address options caused a push to fail with the following error
+ message:
+ Error: Duplicate address name..
+
+ |
+
|
+ PAN-171927
+ |
+
+
+ Fixed an issue where incorrect results were displayed when filtering
+ logs in the Monitor tab.
+
+ |
+
|
+ PAN-171300
+ |
+
+
+ Fixed an issue on Panorama where a password change in a template did
+ not reset an expired password flag on the firewall, which caused the
+ user to change their password when logging in to a firewall.
+
+ |
+
|
+ PAN-170414
+ |
+
+
+ Fixed an issue related to an OOM condition in the dataplane, which was
+ caused by multiple panio commands
+ using extra memory.
+
+ |
+
|
+ PAN-157199
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ the GlobalProtect portal was not reachable with IPv6 addresses.
+
+ |
+
|
+ PAN-142701
+ |
+
+
+ Fixed an issue where the firewall did not delete Stateless SCTP
+ sessions after receiving an SCTP Abort packet.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-229705
+ |
+
+
+ Fixed an issue where running the
+ show rule-hit-count CLI command on
+ Panorama displayed the error message
+ Server error : Timed out while getting config lock. Please try
+ again.
+ when attempting to log in or run CLI commands.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ PAN-248427
+ |
+
+
+ Fixed an issue where push operations took longer than expected to
+ complete.
+
+ |
+
|
+ PAN-247403
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where the push scope CLI command took longer than expected,
+ which caused the web interface to be slow.
+
+ |
+
|
+ PAN-245850
+ |
+
+
+ Fixed an issue on Panorama appliances in active/passive HA
+ configurations where the firewalls entered an HA out-of-sync status
+ and jobs failed on the passive appliance with the error message
+ Could not merged running config from file.
+
+ |
+
|
+ PAN-244746
+ |
+
+
+ Fixed an issue where changes committed on Panorama were not reflected
+ on the firewall after a successful push.
+
+ |
+
|
+ PAN-235840
+ |
+
+
+ Fixed an issue where, after a configuration push from Panorama to
+ managed firewalls, the status displayed as
+ None and the push took longer than
+ expected.
+
+ |
+
|
+ PAN-228515
+ |
+
+
+ Fixed an issue where the Elasticsearch cluster health status displayed
+ as yellow or red due to Elasticsearch SSH tunnel flaps.
+
+ |
+
|
+ PAN-216941
+ |
+
+
+ (M-700 Appliances in Log Collector mode only)
+ Fixed an issue where Panorama stopped processing and saving logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+
+ PAN-231823
+
+ |
+
+
+ A fix was made to address
+ CVE-2024-5916.
+
+ |
+
|
+ PAN-227179
+ |
+
+
+ Fixed an issue where routes were not updated in the forwarding table.
+
+ |
+
|
+ PAN-225340
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to connect after
+ upgrading to PAN-OS 10.2.4 due to an incorrect client authentication
+ configuration being selected.
+
+ |
+
|
+ PAN-225183
+ |
+
+
+ Fixed an issue where SSH tunnels were unstable due to ciphers used as
+ part of the high availability SSH configuration.
+
+ |
+
|
+ PAN-224273
+ |
+
+
+ Fixed an issue where the
+ debug dataplane pow status CLI
+ command did not display extended NIC statistics.
+
+ |
+
|
+ PAN-223501
+ |
+
+
+ (PA-5200 Series and PA-7000 Series firewalls only) Fixed an issue where diagnostic information for the dataplane in
+ the dp-monitor.log file was not complete.
+
+ |
+
|
+ PAN-223317
+ |
+
+
+ Fixed an issue where SSL traffic failed with the error message:
+ Error: General TLS protocol error.
+
+ |
+
|
+ PAN-223185
+ |
+
+
+ Fixed an issue where the
+ distributord
+ process stopped responding.
+
+ |
+
|
+ PAN-222712
+ |
+
+
+ (PA-5450 firewalls only) Fixed a low frequency
+ DPC restart issue.
+
+ |
+
|
+ PAN-221984
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where an interface went down after a hotplug event
+ and was only recoverable by restarting the firewall.
+
+ |
+
|
+ PAN-221881
+ |
+
+
+ Fixed an issue where log ingestion to Panorama failed, which resulted
+ in missing logs under the
+ Monitor tab.
+
+ |
+
|
+ PAN-221836
+ |
+
+
+ Fixed an issue where improper SNI detection caused incorrect URL
+ categorization.
+
+ |
+
|
+ PAN-221708
+ |
+
+
+ Fixed an issue where temporary files remained under
+ /opt/pancfg/tmp/sw-images/ even
+ after manually uploading the content or AV file to the firewall.
+
+ |
+
|
+ PAN-221647
+ |
+
+
+ Fixed an issue where the
+ Apps seen value was not reflected on
+ Panorama.
+
+ |
+
|
+ PAN-220910
+ |
+
+
+ Fixed an issue where an internal management plane NIC caused a kernel
+ panic when doing a transmit due to the driver reinitializing under
+ certain failure or change conditions on the same interface during
+ transmit.
+
+ |
+
|
+ PAN-220899
+ |
+
+
+ Fixed an issue where you were unable to choose the manual
+ GlobalProtect gateway.
+
+ |
+
|
+ PAN-220747
+ |
+
+
+ Fixed an issue where logs were not visible after restarting the log
+ collector.
+
+ |
+
|
+ PAN-220626
+ |
+
+
+ Fixed an issue where system warning logs were written every 24 hours.
+
+ |
+
|
+ PAN-220448
+ |
+
+
+ Fixed an issue where the GlobalProtect client connection remained at
+ the prelogin stage when Kerberos SSO failed and was unable to fall
+ back to the realm authentication.
+
+ |
+
|
+ PAN-220401
+ |
+
+
+ Fixed an issue where, during a reboot, an unexpected error message was
+ displayed that the syslog configuration file format was too old.
+
+ |
+
|
+ PAN-220281
+ |
+
+
+ (PA-7080 firewalls only) Fixed an issue where
+ auto-committing changes after rebooting the Log Forwarding Card (LFC)
+ caused the
+ logrcvr
+ process to fail to read the configuration file.
+
+ |
+
|
+ PAN-219690
+ |
+
+
+ Fixed an issue where GlobalProtect authentication failed when
+ authentication was SAML with CAS and the portal was resolved with
+ IPv6.
+
+ |
+
|
+ PAN-219686
+ |
+
+
+ Fixed an issue where a device group push operation from Panorama
+ failed with the following error on managed firewalls:
+ vsys <vsys1> plugins unexpected here vsys is invalid Commit
+ failed.
+
+ |
+
|
+ PAN-219659
+ |
+
+
+ Fixed an issue where root partition frequently filled up and the
+ following error message was displayed:
+ Disk usage for / exceeds limit, xx percent in use, cleaning
+ filesystem.
+
+ |
+
|
+ PAN-219640
+ |
+
+
+ Fixed an issue where a transformation migration script error caused a
+ commit failure with the error message
+ user-id-agent unexpected here.
+ This occurred after upgrading the firewall from a PAN-OS 9.1 release
+ to a PAN-OS 10.0 release.
+
+ |
+
|
+ PAN-219573
+ |
+
+
+ Fixed an issue where tag names did not correctly display special
+ characters.
+
+ |
+
|
+ PAN-219508
+ |
+
+
+ (VM-Series, PA-400 Series, PA-1400, PA-3400, and PA-5400 Series
+ firewalls only) Fixed an issue where Bidirectional Forwarding Detection (BFD)
+ packets experienced a delay in processing, which caused the BFD
+ connection to flap.
+
+ |
+
|
+ PAN-219498
+ |
+
+
+ Fixed an issue where the
+ Threat ID/Name detail in Threat logs
+ was not included in syslog messages sent to Splunk.
+
+ |
+
|
+ PAN-219351
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding during Layer 7 processing.
+
+ |
+
|
+ PAN-219253
+ |
+
+
+ Fixed an issue where, after making changes in a template, the
+ Commit and Push option was grayed
+ out.
+
+ |
+
|
+ PAN-218947
+ |
+
+
+ Fixed an issue where logs were not displayed in Elasticsearch under
+ ingestion load.
+
+ |
+
|
+ PAN-218697
+ |
+
+
+ Fixed an issue where the ElasticSearch status frequently changed to
+ red or yellow after a PAN-OS upgrade.
+
+ |
+
|
+ PAN-218644
+ |
+
+
+ Fixed an issue where the firewall generated incorrect VSA attribute
+ codes when radius was configured with EAP-based authentication
+ protocols.
+
+ |
+
|
+ PAN-218620
+ |
+
+
+ Fixed an issue where scheduled configuration exports and SCP server
+ connection testing failed.
+
+ |
+
|
+ PAN-218404
+ |
+
+
+ Fixed an issue where
+ ikemgr
+ stopped responding due to receiving
+ CREATE_CHILD messages with a
+ malformed SA payload.
+
+ |
+
|
+ PAN-218335
+ |
+
+
+ Fixed an issue with hardware destination MAC filtering on the Log
+ Processing Card (LPC) that caused the logging card interface to be
+ susceptible to unicast flooding.
+
+ |
+
|
+ PAN-218318
+ |
+
+
+ Fixed an issue where the firewall changed the time zone automatically
+ instead of retrieving the correct time zone from the NTP server.
+
+ |
+
|
+ PAN-218264
+ |
+
+
+ (PA-3400 and PA-1400 Series firewalls only)
+ Fixed an issue where packet drops occurred due to slow servicing of
+ internal hardware queries.
+
+ |
+
|
+ PAN-218151
+ |
+
+
+ Fixed an issue where a configuration push to a new firewall did not
+ work and displayed validation errors.
+
+ |
+
|
+ PAN-218107
+ |
+
+
+ Fixed an issue with ciphers used for SSH tunnels where packet lengths
+ were too large, which made the SSH tunnel unstable.
+
+ |
+
|
+ PAN-218001
+ |
+
+
+ (PA-400 Series firewalls only) Fixed an issue
+ where shut down commands rebooted the system instead of correctly
+ triggering a shutdown.
+
+ |
+
|
+ PAN-217681
+ |
+
+
+ Fixed an issue caused by out of order TCP segments where the TCP
+ retransmission failed when the TCP segment had the FIN flag and the
+ TCP data was truncated.
+
+ |
+
|
+ PAN-217582
+ |
+
+
+ (VM-Series firewalls on Google Cloud Platform environments only) Fixed an issue where firewalls failed to load the virtual machine
+ information source configuration.
+
+ |
+
|
+ PAN-217581
+ |
+
+
+ Fixed an issue where the firewall did not initiate scheduled log
+ uploads to the FTP server.
+
+ |
+
|
+ PAN-217489
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where the passive firewall MAC flapping occurred when the passive
+ firewall was rebooted.
+
+ |
+
|
+ PAN-217465
+ |
+
+
+ Fixed an issue where the Panorama web interface became unresponsive
+ and displayed the error message
+ 504 Gateway Not Reachable.
+
+ |
+
|
+ PAN-217431
+ |
+
+
+ (PA-5400 Series firewalls with DPC (Data Processing Cards) only) Fixed an issue with slot 2 DPCs where URL Filtering did not work as
+ expected after upgrading to PAN-OS 10.1.9.
+
+ |
+
|
+ PAN-217284
+ |
+
+
+ Fixed an intermittent issue where an LACP flap occurred when the LACP
+ transmission rate was set to Fast.
+
+ |
+
|
+ PAN-217169
+ |
+
+
+ Fixed an issue where the logrcvr stopped forwarding logs to the syslog
+ server after a restart or crash.
+
+ |
+
|
+ PAN-216996
+ |
+
+
+ Fixed an issue where multiple User-ID alerts were generated every 10
+ minutes.
+
+ |
+
|
+ PAN-216957
+ |
+
+
+ Fixed an issue where allow list checks in an authentication profile
+ did not work if the group Distinguished Name contains the ampersand (
+ & ) character.
+
+ |
+
|
+ PAN-216913
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the
+ brdagent
+ process stopped responding due to missed heartbeats, which caused the
+ firewall to reboot. This occurred when the
+ brdagent
+ process and DPDK-managed ports became out of sync after the Azure
+ infrastructure triggered a hotplug event.
+
+ |
+
|
+ PAN-216821
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding after upgrading an M-200 appliance to
+ PAN-OS 10.2.4.
+
+ |
+
|
+ PAN-216662
+ |
+
+
+ Fixed an issue where a custom Antispyware profile did not open and
+ displayed the following error message:
+ The server is not responding. Please wait and try your operation
+ again later.
+
+ |
+
|
+ PAN-216366
+ |
+
+
+ Fixed an issue where, when custom signatures used a certain syntax,
+ false positives were generated on devices on a PAN-OS 10.0 release.
+
+ |
+
|
+ PAN-216360
+ |
+
+
+ Fixed an issue on Panorama where
+ No Default Selections under
+ Push to Devices was intermittently
+ deselected after performing a commit operation.
+
+ |
+
|
+ PAN-216170
+ |
+
+
+ (PA-400 Series firewalls in HA configurations only) Fixed an issue where an HA switchover took longer than expected to
+ bring up ports on the newly active firewall.
+
+ |
+
|
+ PAN-216054
+ |
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while
+ it was idle.
+
+ |
+
|
+ PAN-216048
+ |
+
+
+ Fixed an issue where, when upgrading from a PAN-OS 9.1 release to a
+ PAN-OS 10.0 release, commits failed with the error message:
+ hip profiles unexpected here.
+
+ |
+
|
+ PAN-216043
+ |
+
+
+ Fixed an issue where wifclient stopped responding due to shared memory
+ corruption.
+
+ |
+
|
+ PAN-215911
+ |
+
+
+ Fixed an issue that resulted in a race condition, which caused the
+ configd
+ process to stop responding.
+
+ |
+
|
+ PAN-215808
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.1, the log
+ forwarding rate toward the syslog server was reduced. With this fix,
+ the overall log forwarding rate has also been improved.
+
+ |
+
|
+ PAN-215780
+ |
+
+
+ Fixed an issue where changes to Zone Protection profiles made via XML
+ API were not reflected in the zone protection configuration.
+
+ |
+
|
+ PAN-215778
+ |
+
+
+ Fixed an issue where API Get requests for
+ /config timed out due to
+ insufficient buffer size.
+
+ |
+
|
+ PAN-215655
+ |
+
+
+ Fixed an issue where, after a multidynamic group push, Security policy
+ rules with the target device tag were added to a firewall that did not
+ have the tag.
+
+ |
+
|
+ PAN-215503
+ |
+
+
+ Fixed a memory-related issue where the
+ MEMORY_POOL address was mapped
+ incorrectly.
+
+ |
+
|
+ PAN-215496
+ |
+
+
+ Fixed an issue where 100G ports did not come up with BIDI QSFP
+ modules.
+
+ |
+
|
+ PAN-215338
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where the inner VLAN tag for Q-in-Q traffic was stripped when
+ forwarding.
+
+ |
+
|
+ PAN-215317
+ |
+
+
+ Fixed an issue where the dataplane stopped responding unexpectedly
+ with the error message
+ comm exited with signal of 10.
+
+ |
+
|
+ PAN-215066
+ |
+
+
+ Fixed an issue on Panorama where push scope rendering caused the
+ Commit and Push or
+ Push to Devices operation window to
+ hang for several minutes.
+
+ |
+
|
+ PAN-215058
+ |
+
+
+ Fixed a memory leak related to the
+ logdb
+ process.
+
+ |
+
|
+ PAN-214990
+ |
+
+
+ Fixed an issue where firewall copper ports flapped intermittently when
+ device telemetry was enabled.
+
+ |
+
|
+ PAN-214815
+ |
+
+
+ Fixed an issue where SNMP queries were not replied to due to an
+ internal process timeout.
+
+ |
+
|
+ PAN-214753
+ |
+
+
+ Fixed an issue where retrieving WildFire Analysis reports when
+ choosing WildFire log entries under
+ Detailed Log View displayed the
+ error
+ Fetching WildFire server xxx report failed!
+
+ |
+
|
+ PAN-214727
+ |
+
+
+ Fixed an issue where a memory leak related to the
+ useridd
+ process resulted in an OOM condition, which caused the process to stop
+ responding.
+
+ |
+
|
+ PAN-214669
+ |
+
+
+ Fixed an issue where FIN and RESET packets were sent in reverse order.
+
+ |
+
|
+ PAN-214201
+ |
+
+
+ Fixed an issue where, after exporting custom reports to CSV format,
+ the letter b appeared at the
+ beginning of each column.
+
+ |
+
|
+ PAN-214187
+ |
+
+
+ Fixed an issue where superreaders were able to execute the
+ request restart system CLI
+ command.
+
+ |
+
|
+ PAN-214026
+ |
+
+
+ Fixed an issue where, when using an ECMP
+ weighted-round-robin algorithm,
+ traffic was not redistributed among the links proportionally as
+ expected from the configuration.
+
+ |
+
|
+ PAN-213949
+ |
+
+
+ Fixed an issue where the VPN responder stopped responding when it
+ received a CREATE_CHILD message with no security association (SA)
+ payload.
+
+ |
+
|
+ PAN-213942
+ |
+
+
+ (PA-400 Series firewalls) Fixed an issue where
+ the firewall required an explicit allow rule to forward broadcast
+ traffic.
+
+ |
+
|
+ PAN-213932
+ |
+
+
+ Fixed an issue where, when an incorrect log filter was configured, the
+ commit did not fail.
+
+ |
+
|
+ PAN-213931
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process cache was not in sync with the mapping on the firewall.
+
+ |
+
|
+ PAN-213746
+ |
+
+
+ Fixed an issue on Panorama where the Hostkey displayed as
+ undefined if an SSH Service Profile
+ Hostkey configured in a template from the template stack was
+ overridden.
+
+ |
+
|
+ PAN-213463
+ |
+
+
+ (PA-5200 Series firewalls only) Fixed an issue
+ where unplugging a PAN-SFP-CG transceiver from an interface with its
+ link speed setting set to 1000 caused the firewall to incorrectly read
+ that interface as up.
+
+ |
+
|
+ PAN-213296
+ |
+
+
+ Fixed an issue where Single Log-out (SLO) was not correctly triggered
+ from the firewall toward the client, which caused the client to not
+ initiate the SLO request toward the identity provider (IdP). This
+ resulted in the IdP not making the SLO callback to the firewall to
+ remove the user.
+
+ |
+
|
+ PAN-213162
+ |
+
+
+ Fixed an issue where an SD-WAN object was not displayed under a child
+ device group.
+
+ |
+
|
+ PAN-213077
+ |
+
+
+ Fixed an issue where the
+ sysdagent
+ process stopped responding, which caused interfaces and the subsequent
+ connections behind them to fail.
+
+ |
+
|
+ PAN-213060
+ |
+
+
+ Fixed an issue where Panorama did not show the target under the
+ Entities column.
+
+ |
+
|
+ PAN-212978
+ |
+
+
+ Fixed an issue where the firewall stopped responding when executing an
+ SD-WAN debug CLI command.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ Fixed an issue on Panorama where different threat names were used when
+ querying a threat under
+ Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after
+ clicking a threat name in
+ Threat Monitor and filtering it in
+ the global filters.
+
+ |
+
|
+ PAN-212859
+ |
+
+
+ Fixed an issue where the
+ pan_task stopped responding
+ briefly during a commit due to a contention with
+ brdagent updating the
+ configuration.
+
+ |
+
|
+ PAN-212848
+ |
+
+
+ Fixed an issue where attempting to change the disk-usage cleanup
+ threshold to 90 resulted in the error message
+ Server error : op command for client dagger timed out as client is
+ not available.
+
+ |
+
|
+ PAN-212726
+ |
+
+
+ Fixed an issue where RTP/RTCP packets were dropped for SIP calls by
+ SIP ALG when the source NAT translation type was persistent
+ Dynamic IP And Port.
+
+ |
+
|
+ PAN-212577
+ |
+
+
+ (PA-5200 Series and PA-7080 firewalls only)
+ Fixed an issue where commits took longer than expected when more than
+ 45,000 Security policy rules were configured.
+
+ |
+
|
+ PAN-212576
+ |
+
+
+ Fixed an issue where firewall HA clusters in active/active
+ configurations with Advanced Routing enabled did not relay to ping
+ requests sent to a virtual IP address.
+
+ |
+
|
+ PAN-212530
+ |
+
+
+ Fixed an issue on log collectors where root partition reached 100%
+ utilization.
+
+ |
+
|
+ PAN-212057
+ |
+
+
+ Fixed an issue where Advanced Threat Prevention caused SSL delays when
+ no URL licenses were present.
+
+ |
+
|
+ PAN-211997
+ |
+
+
+ Fixed an issue where large OSPF control packets were fragmented, which
+ caused the neighborship to fail.
+
+ |
+
|
+ PAN-211887
+ |
+
+
+ Fixed an issue on Panorama that caused recently committed changes to
+ not be displayed when previewing the changes to push to device groups.
+
+ |
+
|
+ PAN-211843
+ |
+
+
+ Fixed an issue where renaming a Zone Protection profile failed with
+ the error message
+ Obj does not exist.
+
+ |
+
|
+ PAN-211602
+ |
+
+
+ Fixed an issue where, when viewing a WildFire Analysis report via the
+ web interface, the
+ detailed log view was not accessible
+ if the browser window was resized.
+
+ |
+
|
+ PAN-211575
+ |
+
+
+ Fixed an issue where a local commit on Panorama remained at 99% for
+ longer than expected before completing.
+
+ |
+
|
+ PAN-211519
+ |
+
+
+ Fixed an issue where RTP/RTCP packets were dropped for SIP calls by
+ SIP ALG when the source NAT translation type was persistent
+ Dynamic IP And Port.
+
+ |
+
|
+ PAN-211441
+ |
+
+
+ Fixed a memory leak issue related to SSL crypto operations that
+ resulted in failed commits.
+
+ |
+
|
+ PAN-211422
+ |
+
+
+ Fixed an issue where the
+ show session packet-buffer-protection buffer-latency
+ CLI command randomly displayed incorrect values.
+
+ |
+
|
+ PAN-211398
+ |
+
+
+ Fixed an issue where dataplane processes stopped responding when
+ handling HTTP/2 streams.
+
+ |
+
|
+ PAN-211191
+ |
+
+
+ Fixed an issue where the firewall restarted after initiating a
+ mgmtsrvr
+ process restart.
+
+ |
+
|
+ PAN-211041
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where DHCP assigned interfaces did not send
+ ICMP unreachable - Fragmentation needed
+ messages when the received packets were higher than the maximum
+ transmission unit (MTU).
+
+ |
+
|
+ PAN-210921
+ |
+
+
+ (Panorama appliances in Legacy Mode only) Fixed
+ an issue where
+ Blocked Browsing Summary by Website
+ in the user activity report contained scrambled characters.
+
+ |
+
|
+ PAN-210883
+ |
+
+
+ Fixed an issue where SSL proxy traffic was dropped when DoS zone
+ protection was enabled.
+
+ |
+
|
+ PAN-210740
+ |
+
+
+ Fixed a memory leak issue related to the
+ slotd
+ process.
+
+ |
+
|
+ PAN-210738
+ |
+
+
+ Fixed an issue where fragmented UDP packets were dropped.
+
+ |
+
|
+ PAN-210736
+ |
+
+
+ Fixed an issue where configuration changes related to the SSH service
+ profile were not reflected when pushed from Panorama. With this fix,
+ the deletion of ciphers, MAC, and kex fields of SSH server profiles
+ and HA profiles won't clear the values under template stacks and will
+ retain the values configured from templates.
+
+ |
+
|
+ PAN-210661
+ |
+
+
+ Fixed an issue where firewalls disconnected from
+ Strata Logging Service after renewing the
+ device certificate.
+
+ |
+
|
+ PAN-210640
+ |
+
+
+ Fixed an issue where applications were not displayed after
+ authenticating into the clientless VPN.
+
+ |
+
|
+ PAN-210563
+ |
+
+
+ Fixed an issue on Panorama where Security policy rules with a
+ Tag target did not appear in the
+ pre-rule list of a Dynamic Address Group that was part of the tag.
+
+ |
+
|
+ PAN-210511
+ |
+
+
+ Fixed an issue where Panorama commits failed due to an invalid
+ community value error.
+
+ |
+
|
+ PAN-210502
+ |
+
+
+ Fixed an issue where Panorama was unable to convert to PAN-OS 9.1
+ syntax for WF-500 appliances.
+
+ |
+
|
+ PAN-210456
+ |
+
+
+ Fixed an issue where high latency occurred on PA-850-ZTP when SSL
+ decryption was enabled.
+
+ |
+
|
+ PAN-210452
+ |
+
+
+ Fixed an issue where application PCAP was not generated when Security
+ policy rules were used as a filter.
+
+ |
+
|
+ PAN-210451
+ |
+
+
+ Fixed an issue where the firewall did not send the source IP address
+ of the user to the RADIUS server with the
+ set authentication radius-vsa-on client-source-ip
+ CLI command.
+
+ |
+
|
+ PAN-210429
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the HTTP service failed to come up on DHCP dataplane interfaces after
+ rebooting the firewall, which resulted in health-check failure on
+ HTTP/80 with a 503 error code on the public load balancer.
+
+ |
+
|
+ PAN-210397
+ |
+
+
+ Fixed an issue on Panorama where VM-Series firewalls in HA
+ configurations hosted on Amazon Web Services (AWS) were not displayed
+ under Deploy Master Key.
+
+ |
+
|
+ PAN-210364
+ |
+
+
+ Fixed an issue where high latency was observed when accessing internal
+ web applications, which interrupted development activities related to
+ the web server.
+
+ |
+
|
+ PAN-210325
+ |
+
+
+ Fixed an issue on the firewall where the configuration log always
+ displayed commit-all operations as successful even when the commit
+ failed.
+
+ |
+
|
+ PAN-210216
+ |
+
+
+ A debug command was added to address an issue with firewalls in high
+ availability configurations.
+
+ |
+
|
+ PAN-210158
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the dataplane stopped responding after a container restart.
+
+ |
+
|
+ PAN-210000
+ |
+
+
+ Fixed an issue where, when traffic and Threat logs exceeded the
+ threshold of 90% total allowed size, alarms were not generated for
+ other log types.
+
+ |
+
|
+ PAN-209937
+ |
+
+
+ Fixed an issue where certificate-based authentication for
+ administrators were unable to log in to the Panorama or firewall web
+ interface and received the following error message:
+ Bad Request - Your browser sent a request that this server could
+ not understand.
+
+ |
+
|
+ PAN-209930
+ |
+
+
+ Fixed an issue where cloned rules pushed from Panorama were not shown
+ on the managed firewall.
+
+ |
+
|
+ PAN-209872
+ |
+
+
+ Fixed an issue where dataplane ports responded to ICMP requests fewer
+ than 64 bytes with nonzero padding bytes in the ICMP response.
+
+ |
+
|
+ PAN-209696
+ |
+
+
+ Fixed an issue where link-local address communication for IPv6, BFD,
+ and OSPFv3 neighbors was dropped when IP address spoofing check was
+ enabled in a Zone Protection profile.
+
+ |
+
|
+ PAN-209683
+ |
+
+
+ Fixed an issue where Panorama was unable to retrieve IP
+ address-to-username mapping from a firewall on a PAN-OS 8.1 release.
+
+ |
+
|
+ PAN-209617
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where the passive firewall created an incorrect SCTP association due
+ to the HA sync messages from the active firewall having an incorrect
+ value.
+
+ |
+
|
+ PAN-209585
+ |
+
+
+ The Palo Alto Networks QoS implementation now supports a new QoS mode
+ called lockless QoS for PA-3400, PA-5410, PA-5420, PA-5430, and
+ PA-5440 firewalls. For firewalls with higher bandwidth QoS
+ requirements, the lockless QoS dedicates cores to the QoS function
+ that improves QoS performance, resulting in improved throughput and
+ latency.
+
+ |
+
|
+ PAN-209501
+ |
+
+
+ Fixed an issue where the GlobalProtect
+ logdb quota was not displayed in
+ the
+ show system logdb quota output.
+
+ |
+
|
+ PAN-209375
+ |
+
+
+ Fixed an issue on the firewall where log filtering did not work as
+ expected.
+
+ |
+
|
+ PAN-209172
+ |
+
+
+ Fixed an issue where the firewall was unable to handle GRE packets for
+ Point-to-Point Tunneling Protocol (PPTP) connections.
+
+ |
+
|
+ PAN-209108
+ |
+
+
+ Fixed an issue where a Panorama in Management Only mode was unable to
+ display logs from log collectors due to missing schema files.
+
+ |
+
|
+ PAN-208902
+ |
+
+
+ Fixed an issue where, when a client sent a TCP/FIN packet, the
+ firewall displayed the end reason as
+ aged-out instead of
+ tcp-fin.
+
+ |
+
|
+ PAN-208792
+ |
+
+
+ Fixed an issue where authentication failed when the service route for
+ RADIUS traffic was configured as
+ use default for IPv4 addresses and
+ included the dataplane interface as the destination route.
+
+ |
+
|
+ PAN-208567
+ |
+
+
+ Fixed an issue with email formatting where, when a scheduled email
+ contained two or more attachments, only one attachment was visible.
+
+ |
+
|
+ PAN-208343
+ |
+
+
+ Fixed an issue where telemetry regions were not visible on Panorama.
+
+ |
+
|
+ PAN-208325
+ |
+
+
+ (PA-5400 Series, PA-3400 Series, and PA-400 Series only) Fixed an issue where the firewall was unable to automatically renew
+ the device certificate.
+
+ |
+
|
+ PAN-208316
+ |
+
+
+ Fixed an issue where user-group names were unable to be configured as
+ the source user via the
+ test security-policy-match
+ command.
+
+ |
+
|
+ PAN-208201
+ |
+
+
+ Fixed an issue on the firewall where the modified date and time was
+ incorrectly updated after a commit operation, PAN-OS upgrade, or
+ reboot.
+
+ |
+
|
+ PAN-208198
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where, after rebooting the passive firewall, interfaces were briefly
+ shown as powered up, and then shown as down or shutdown.
+
+ |
+
|
+ PAN-208187
+ |
+
+
+ Fixed an issue where REST API requests did not work for GlobalProtect
+ gateway tunnels.
+
+ |
+
|
+ PAN-208090
+ |
+
+
+ Fixed an issue where the ACC report did not display data when querying
+ the filter for the fields Source and
+ Destination IP.
+
+ |
+
|
+ PAN-208039
+ |
+
+
+ (PA-7000 Series firewalls with SMC-B only)
+ Fixed an issue where the details of configuration changes were not
+ included in configuration logs on the syslog server.
+
+ |
+
|
+ PAN-207842
+ |
+
+
+ Fixed an issue where WildFire Analysis reports were not visible when
+ the WF-500 appliance was on private cloud.
+
+ |
+
|
+ PAN-207741
+ |
+
+
+ Fixed an issue where Large Scale VPN (LSVPN) Portal authentication
+ failed with the error
+ invalid http response. return error(Authentication failed; Retry
+ authentication
+ when the satellite connected to more than one portal.
+
+ |
+
|
+ PAN-207700
+ |
+
+
+ Fixed an issue where the
+ show system info and
+ show system ztp status CLI
+ commands displayed a different Zero Touch Provisioning (ZTP) status if
+ a firewall upgrade was initiated from Panorama before the initial
+ commit push succeeded.
+
+ |
+
|
+ PAN-207661
+ |
+
+
+ Fixed an issue with firewalls in active/active HA configurations where
+ the virtual floating IP address configuration under a Panorama
+ template was overridden and displayed
+ From Template Override: undefined
+ as a source.
+
+ |
+
|
+ PAN-207604
+ |
+
+
+ Fixed an issue where system logs continuously generated the log
+ message
+ Not enough space to load content to SHM.
+
+ |
+
|
+ PAN-207457
+ |
+
+
+ Fixed an issue where the MLAV allow list did not work for some types
+ of traffic.
+
+ |
+
|
+ PAN-207240
+ |
+
+
+ Fixed an issue where
+ mprelay
+ repeatedly restarted, which caused commits to remain at 70% before
+ failing with the error message
+ A communication error happened during the configuration commit to
+ the data plane, please try again.
+
+ |
+
|
+ PAN-206765
+ |
+
+
+ Fixed an issue where log forwarding filters involving negation did not
+ work.
+
+ |
+
|
+ PAN-206640
+ |
+
+
+ Fixed an issue where the
+ ikemgr process stopped
+ responding, which caused IPSec tunnels to go down.
+
+ |
+
|
+ PAN-206396
+ |
+
+
+ Fixed an issue where HIP report flip and HIP check failed when a user
+ was part of multiple user groups with different domains.
+
+ |
+
|
+ PAN-206391
+ |
+
+
+ Fixed an issue where shared objects were seen under the push scope
+ with every configuration push.
+
+ |
+
|
+ PAN-206333
+ |
+
+
+ Fixed an issue where the
+ Include/Exclude IP filter under
+ Data Distribution did not work
+ correctly.
+
+ |
+
|
+ PAN-206278
+ |
+
+
+ Fixed an issue where a critical system log was generated when the boot
+ drive for PA-7000 Series firewall Switch Management Cards (SMCs)
+ failed.
+
+ |
+
|
+ PAN-206221
+ |
+
+
+ Fixed an issue where scheduled configuration pushes with
+ Include Device and Network Templates
+ selected did not work.
+
+ |
+
|
+ PAN-205513
+ |
+
+
+ Fixed an issue where the stats dump file generated by Panorama for a
+ device firewall differed from the stats dump file generated by the
+ managed device.
+
+ |
+
|
+ PAN-205369
+ |
+
+
+ Fixed an issue where connections to
+ Strata Logging Service were initialized from
+ the firewall even when
+ Strata Logging Service forwarding was
+ disabled.
+
+ |
+
|
+ PAN-205086
+ |
+
+
+ Fixed an issue where DNS Security categories were able to be deleted
+ from spyware profiles.
+
+ |
+
|
+ PAN-204718
+ |
+
+
+ (PA-5200 Series firewalls only) Fixed an issue
+ where, after upgrading to PAN-OS 10.1.6-h3, a TACACS user login
+ displayed the following error message during the first login attempt:
+ Could not chdir to home directory /opt/pancfg/home/user: Permission
+ denied.
+
+ |
+
|
+ PAN-204683
+ |
+
+
+ Fixed an issue where logs were unable to be generated due to old logs
+ not getting purged and
+ /opt/panlogs reaching over 100%
+ usage.
+
+ |
+
|
+ PAN-204530
+ |
+
+
+ Fixed an issue where giving up FTP or SCP sessions for log export took
+ longer than expected after a failure to export the log when one of the
+ destination hosts designated in the scheduled log export was
+ unresponsive.
+
+ |
+
|
+ PAN-204420
+ |
+
+
+ (WF-500 appliances only) Fixed an issue where,
+ after an upgrade to a PAN-OS 10.1 release, SNMP traps were not sent to
+ the SNMP server. This occurred due to SNMP trap server settings not
+ being enabled.
+
+ |
+
|
+ PAN-204233
+ |
+
+
+ Fixed an issue where, when the firewall received a 513 error from the
+ WildFire cloud, the firewall attempted to repeatedly send the same
+ file.
+
+ |
+
|
+ PAN-204215
+ |
+
+
+ (PA-7000 Series firewalls with Log Processing Cards (LPCs) only) Fixed an issue where performing a commit operation resulted in the
+ following error messages:
+ log forwarding is setup for data but log-card interface is not
+ setup
+ or
+ log forwarding is setup for traffic but log-card interface is not
+ setup.
+
+ |
+
|
+ PAN-203791
+ |
+
+
+ (PA-3400 and PA-5400 Series firewalls only)
+ Fixed an issue where the log type correlation was not configurable and
+ displayed as
+ $.Format.Correlation (Device > Server Profile > syslog ><Profile-name>
+ > Customer log format > log type).
+
+ |
+
|
+ PAN-203655
+ |
+
+
+ Fixed an issue where enabling
+ event-specific traps (Device > Setup > Operations > Miscellaneous > SNMP
+ Setup), the new deviating device system logs included incorrect
+ information.
+
+ |
+
|
+ PAN-203611
+ |
+
+
+ Fixed an issue where URL categorization was not recognized for URLs
+ that contained more than 100 characters.
+
+ |
+
|
+ PAN-203222
+ |
+
+
+ Fixed an issue where commit-all operations took longer than expected
+ due to cURL failures and timeouts related to external dynamic list
+ retrieval.
+
+ |
+
|
+ PAN-203168
+ |
+
+
+ Fixed an issue where the WIF state was not cleaned up promptly after
+ usage, which caused allocation failure. This fix increased the
+ wif_state quota.
+
+ |
+
|
+ PAN-202981
+ |
+
+
+ Fixed an issue on Panorama where global find did not return results
+ for existing universally unique identifiers (UUID).
+
+ |
+
|
+ PAN-202963
+ |
+
+
+ Fixed an issue where the system log message
+ dsc HA state is changed from 1 to 0
+ was generated with the severity
+ High. With this fix, the severity
+ was changed to Info.
+
+ |
+
|
+ PAN-202524
+ |
+
+
+ Fixed an issue where the session ID was missing in the session details
+ section of the
+ ingress-backlogs XML API output.
+
+ |
+
|
+ PAN-202516
+ |
+
+
+ Fixed an issue where the firewall stopped responding if it received an
+ illegal packet with SRC port = 0 encapsulated within a VXLAN packet.
+
+ |
+
|
+ PAN-201855
+ |
+
+
+ Fixed an issue where, after cloning a template, a certificate with the
+ block private key option enabled was corrupted.
+
+ |
+
|
+ PAN-201721
+ |
+
+
+ Fixed an issue with firewalls in HA configurations where HA setup
+ generated the error
+ mismatch due to device update
+ during a content update even though the version was the same.
+
+ |
+
|
+ PAN-201515
+ |
+
+
+ Fixed an issue with the web interface where the cursor disappeared
+ under the Policies and
+ Objects tabs on the search bar if
+ the cursor was moved quickly.
+
+ |
+
|
+ PAN-201466
+ |
+
+
+ Fixed an issue where the system log generated on GlobalProtect
+ satellite did not provide the reason for failures to connect to the
+ GlobalProtect portal or gateway.
+
+ |
+
|
+ PAN-200757
+ |
+
+
+ Fixed an issue with client certificate generation on Panorama, which
+ resulted in a firewall being unable to connect to a log collector.
+
+ |
+
|
+ PAN-200394
+ |
+
+
+ Fixed an issue where, after a push from Panorama to one or more device
+ groups in a multi-vsys environment, vulnerability profile exceptions
+ were not seen on all firewalls.
+
+ |
+
|
+ PAN-199819
+ |
+
+
+ Fixed an issue where, if a decryption profile allowed TLS1.3, but the
+ server only supported TLS1.2, and the cipher used by the first
+ connection to the server was a CBC SHA2 cipher suite, the connection
+ failed.
+
+ |
+
|
+ PAN-199687
+ |
+
+
+ Fixed an issue where content updates failed when using prelicensed
+ keys during the bootstrap process.
+
+ |
+
|
+ PAN-199557
+ |
+
+
+ Fixed an issue on Panorama where virtual memory usage exceeded the set
+ limit, which caused the
+ configd
+ process to restart.
+
+ |
+
|
+ PAN-198453
+ |
+
+
+ Fixed an issue where you were unable to resize the
+ Description pop-up window (Policies > Security > Prerules).
+
+ |
+
|
+ PAN-198050
+ |
+
+
+ Fixed an issue where
+ Connection to update server is successful
+ messages displayed even when connections failed.
+
+ |
+
|
+ PAN-197493
+ |
+
+
+ Fixed an issue where having multiple terminal service agents with the
+ same hostname caused the firewall to reboot.
+
+ |
+
|
+ PAN-197467
+ |
+
+
+ Fixed an issue on Panorama where the WildFire
+ Test-Configuration feature did not
+ work as expected.
+
+ |
+
|
+ PAN-197388
+ |
+
+
+ Fixed an issue where, when the firewall forwarded Threat logs via
+ email, the email client truncated the sender and recipient email
+ addresses when they were put between angle brackets (<, >).
+
+ |
+
|
+ PAN-196956
+ |
+
+
+ Fixed an issue where URL Filtering logs did not display matching
+ entries when filtered by device name.
+
+ |
+
|
+ PAN-196923
+ |
+
+
+ Fixed an issue where the interface option did not have a source
+ address in the cURL command, which caused a DNS lookup error and
+ resulted in DNS lookup failing for device Telemetry.
+
+ |
+
|
+ PAN-196597
+ |
+
+
+ Fixed an issue where the
+ dnsproxyd
+ process stopped responding due to corruption.
+
+ |
+
|
+ PAN-196417
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where firewalls experienced slow SNMP responses, which caused the SNMP
+ server to time out before polling completion.
+
+ |
+
|
+ PAN-196345
+ |
+
+
+ Fixed an issue where scheduled dynamic content updates failed to be
+ retrieved by managed firewalls from Panorama when connectivity was
+ slow.
+
+ |
+
|
+ PAN-195788
+ |
+
+
+ Fixed an issue where zip files did not download when applying Security
+ inspection and the following error message displayed:
+ resources-unavailable.
+
+ |
+
|
+ PAN-195439
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the dataplane interface status went down after
+ a hotplug event triggered by Azure infrastructure.
+
+ |
+
|
+ PAN-195251
+ |
+
+
+ Fixed an issue where IPSec tunnel re-key generated the critical log
+ message tunnel-status-up.
+
+ |
+
|
+ PAN-193521
+ |
+
+
+ Fixed an issue where
+ Panorama > Device > Deployment > Software
+ did not display software after running
+ check now for managed devices.
+
+ |
+
|
+ PAN-190903
+ |
+
+
+ Fixed an issue where MAC addresses in threat capture were swapped
+ between the source MAC and destination MAC addresses.
+
+ |
+
|
+ PAN-190435
+ |
+
+
+ Fixed an issue where, after committing a configuration change, the
+ Task Manager commit
+ Status went directly from 0% to
+ Completed instead of reflecting the
+ accurate commit job process.
+
+ |
+
|
+ PAN-190055
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall did not follow the set Jumbo MTU value.
+
+ |
+
|
+ PAN-189442
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-189423
+ |
+
+
+ Fixed an issue where exporting correlation logs generated an empty
+ file.
+
+ |
+
|
+ PAN-189328
+ |
+
+
+ Fixed an issue where traffic belonging to the same session was sent
+ out from different ECMP enabled interfaces.
+
+ |
+
|
+ PAN-187989
+ |
+
+
+ Fixed an issue where a user who did not have permissions of other
+ access domains were able to view the commit and configuration lock.
+
+ |
+
|
+ PAN-186956
+ |
+
+
+ Fixed an issue where SD-WAN DIA VIF did not become active if default
+ gateways for member interfaces did not respond to pings.
+
+ |
+
|
+ PAN-186182
+ |
+
+
+ Fixed an issue where software buffer 3 was depleted when URL proxy was
+ enabled and SSL sessions were decrypted to inject the block page. This
+ issue occurred when an HTTP/2 block page was displayed for a large
+ POST request.
+
+ |
+
|
+ PAN-185249
+ |
+
+
+ Fixed an issue where
+ Template Stack overrides (Dynamic Updates > App & Threats > Schedule) were not able to be reverted via the web interface.
+
+ |
+
|
+ PAN-185135
+ |
+
+
+ (VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the physical port counters (including SNMP) on
+ the dataplane interfaces increased when DPDK was enabled.
+
+ |
+
|
+ PAN-184630
+ |
+
+
+ Fixed an issue where TLS clients, such as those using OpenSSL 3.0,
+ enforced the TLS renegotiation extension (RFC 5746).
+
+ |
+
|
+ PAN-183297
+ |
+
+
+ Fixed an issue where, when the firewall received a large amount of
+ user information, the firewall was unable to output IP
+ address-to-username mapping information via XML API.
+
+ |
+
|
+ PAN-182960
+ |
+
+
+ Additional error logs were added for an issue where, when multiple
+ Panorama web interface sessions were opened, active lock did not show
+ up on the web interface for any session.
+
+ |
+
|
+ PAN-182734
+ |
+
+
+ Fixed an issue where, on an Advanced Routing Engine, BGP peering
+ flapped after a commit.
+
+ |
+
|
+ PAN-180082
+ |
+
+
+ Fixed an issue where errors in
+ brdagent
+ logs caused dataplane path monitoring failure.
+
+ |
+
|
+ PAN-177227
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services environments only) Fixed an issue where traffic sent from a GENEVE tunnel to the
+ firewall was dropped if the firewall attempted to encapsulate traffic
+ into an IPSec tunnel.
+
+ |
+
|
+ PAN-176412
+ |
+
+
+ Fixed an issue where changing the password of a local database user
+ did not work.
+
+ |
+
|
+ PAN-172977
+ |
+
+
+ Fixed an issue where session offloading did not occur on a tap
+ interface under a high packet load.
+
+ |
+
|
+ PAN-172600
+ |
+
+
+ Fixed an issue where the CLI command
+ show rule-hit-count did not
+ provide all details of the rule from the device group.
+
+ |
+
|
+ PAN-169586
+ |
+
+
+ Fixed an issue where scheduled log view reports in emails didn't match
+ the monitor page query result for the same time interval.
+
+ |
+
|
+ PAN-168102
+ |
+
+
+ Fixed an issue where the API format to check heap usage of a node
+ showed a JSON error.
+
+ |
+
|
+ PAN-160633
+ |
+
+
+ (PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls
+ only) Fixed an issue where the dataplane restarted repeatedly due to an
+ internal path monitoring failure until a power cycle.
+
+ |
+
|
+ PAN-151692
+ |
+
+
+ Fixed a permission issue where a Panorama administrator was unable to
+ download or install Dynamic Updates (Panorama > Device Deployment).
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ PAN-249581
+ |
+
+
+ Fixed an issue where stale BGP routes were advertised to peers even
+ when they were not present in the local RIB table.
+
+ |
+
|
+ PAN-228877
+ |
+
+
+ (PA-5200 Series, PA-5400 Series, and PA-7000 Series firewalls
+ only) Fixed an issue with out-of-memory (OOM) conditions that caused slot
+ restarts due to
+ pan_cmd
+ consuming more than 300MB.
+
+ |
+
|
+ PAN-223852
+ |
+
+
+ Fixed an issue where
+ all_pktproc
+ stopped responding when network packet broker or decryption broker
+ chains failed.
+
+ |
+
|
+ PAN-223652
+ |
+
+
+ Fixed an issue where data was not thread safe and led to concurrent
+ read/write issues that caused GPSVC to stop working unexpectedly.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+
+ PAN-231823
+
+ |
+
+
+ A fix was made to address
+ CVE-2024-5916.
+
+ |
+
|
+ PAN-229865
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ upgrading to PAN-OS 10.2.5 failed if the firewall was on a PAN-OS 10.1
+ release.
+
+ |
+
|
+ PAN-229705
+ |
+
+
+ Fixed an issue where running the
+ show rule-hit-count CLI command
+ on Panorama displayed the error message
+ Server error : Timed out while getting config lock. Please try
+ again.
+ when attempting to log in or run CLI commands.
+
+ |
+
|
+ PAN-227639
+ |
+
+
+ Fixed an issue where the
+ ACC displayed an incorrect DNS-base
+ application traffic byte count.
+
+ |
+
|
+ PAN-227523
+ |
+
+
+ A fix was made to address customer and internal bugs (CVE-2023-38802).
+
+ |
+
|
+
+ PAN-227376
+
+ |
+
+
+ Fixed an issue where a memory overrun caused the
+ all_task
+ process to stop responding.
+
+ |
+
|
+ PAN-225240
+ |
+
+
+ Fixed an issue where the OSPF neighbor state remained in
+ exstart when the OSPF network had
+ more than 40 routes.
+
+ |
+
|
+ PAN-223787
+ |
+
+
+ (PA-400 Series and PA-1400 Series firewalls only) Fixed an issue where commits failed with the error message
+ Error unserializing profile objects failed to handle
+ CONFIG_UPDATE_START.
+
+ |
+
|
+ PAN-221728
+ |
+
+
+ Fixed an issue where selective pushes did not work after upgrading to
+ PAN-OS 10.2.4.
+
+ |
+
|
+ PAN-216775
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process stopped responding at
+ pan_cloud_agent_get_curl_connection()
+ and the URL cloud could not be connected.
+
+ |
+
|
+ PAN-214273
+ |
+
+
+ Fixed an issue where Elasticsearch logs were not cleared, which caused
+ the root partition to fill up.
+
+ |
+
|
+ PAN-205015
+ |
+
+
+ Fixed an issue where not all users were included in the user group
+ after an incremental sync between the firewall and the Cloud Identity
+ Engine.
+
+ |
+
|
+ PAN-204868
+ |
+
+
+ Fixed an issue where disk utilization was continuously high due to the
+ log purger not sufficiently reducing the utilization level.
+
+ |
+
|
+ PAN-198509
+ |
+
+
+ Fixed an issue where commits failed due to insufficient CFG memory.
+
+ |
+
|
+ PAN-198043
+ |
+
+
+ Fixed a rare issue where aBuildXmlCache
+ job failed on the firewall.
+
+ |
+