From b36247faf494afe9451853de416a1b89aa2a20e7 Mon Sep 17 00:00:00 2001 From: Aaron Axvig Date: Wed, 29 Jul 2026 12:45:46 -0500 Subject: [PATCH] Added remaining PAN-OS 10.2 reference files --- reference/PAN-OS/addressed/10.2.0-h1.html | 37 + reference/PAN-OS/addressed/10.2.0-h2.html | 147 + reference/PAN-OS/addressed/10.2.0-h3.html | 41 + reference/PAN-OS/addressed/10.2.0-h4.html | 61 + reference/PAN-OS/addressed/10.2.0.html | 96 + reference/PAN-OS/addressed/10.2.1-h1.html | 159 + reference/PAN-OS/addressed/10.2.1-h2.html | 41 + reference/PAN-OS/addressed/10.2.1-h3.html | 61 + reference/PAN-OS/addressed/10.2.1.html | 689 +++ reference/PAN-OS/addressed/10.2.2-h1.html | 61 + reference/PAN-OS/addressed/10.2.2-h2.html | 41 + reference/PAN-OS/addressed/10.2.2-h4.html | 159 + reference/PAN-OS/addressed/10.2.2-h5.html | 41 + reference/PAN-OS/addressed/10.2.2-h6.html | 61 + reference/PAN-OS/addressed/10.2.2.html | 580 ++ reference/PAN-OS/addressed/10.2.3-h11.html | 103 + reference/PAN-OS/addressed/10.2.3-h12.html | 103 + reference/PAN-OS/addressed/10.2.3-h13.html | 41 + reference/PAN-OS/addressed/10.2.3-h14.html | 61 + reference/PAN-OS/addressed/10.2.3-h2.html | 206 + reference/PAN-OS/addressed/10.2.3-h4.html | 244 + reference/PAN-OS/addressed/10.2.3-h9.html | 48 + reference/PAN-OS/addressed/10.2.3.html | 1838 ++++++ reference/PAN-OS/addressed/10.2.4-h10.html | 103 + reference/PAN-OS/addressed/10.2.4-h16.html | 41 + reference/PAN-OS/addressed/10.2.4-h2.html | 138 + reference/PAN-OS/addressed/10.2.4-h3.html | 308 + reference/PAN-OS/addressed/10.2.4-h32.html | 61 + reference/PAN-OS/addressed/10.2.4-h4.html | 221 + reference/PAN-OS/addressed/10.2.4.html | 5901 ++++++++++++++++++++ reference/PAN-OS/addressed/10.2.5-h1.html | 38 + reference/PAN-OS/addressed/10.2.5-h4.html | 103 + reference/PAN-OS/addressed/10.2.5-h6.html | 41 + reference/PAN-OS/addressed/10.2.5-h9.html | 152 + reference/PAN-OS/addressed/10.2.5.html | 3257 +++++++++++ reference/PAN-OS/addressed/10.2.6-h1.html | 103 + reference/PAN-OS/addressed/10.2.6-h3.html | 41 + reference/PAN-OS/addressed/10.2.6-h6.html | 134 + reference/PAN-OS/addressed/10.2.6.html | 260 + 39 files changed, 15821 insertions(+) create mode 100644 reference/PAN-OS/addressed/10.2.0-h1.html create mode 100644 reference/PAN-OS/addressed/10.2.0-h2.html create mode 100644 reference/PAN-OS/addressed/10.2.0-h3.html create mode 100644 reference/PAN-OS/addressed/10.2.0-h4.html create mode 100644 reference/PAN-OS/addressed/10.2.0.html create mode 100644 reference/PAN-OS/addressed/10.2.1-h1.html create mode 100644 reference/PAN-OS/addressed/10.2.1-h2.html create mode 100644 reference/PAN-OS/addressed/10.2.1-h3.html create mode 100644 reference/PAN-OS/addressed/10.2.1.html create mode 100644 reference/PAN-OS/addressed/10.2.2-h1.html create mode 100644 reference/PAN-OS/addressed/10.2.2-h2.html create mode 100644 reference/PAN-OS/addressed/10.2.2-h4.html create mode 100644 reference/PAN-OS/addressed/10.2.2-h5.html create mode 100644 reference/PAN-OS/addressed/10.2.2-h6.html create mode 100644 reference/PAN-OS/addressed/10.2.2.html create mode 100644 reference/PAN-OS/addressed/10.2.3-h11.html create mode 100644 reference/PAN-OS/addressed/10.2.3-h12.html create mode 100644 reference/PAN-OS/addressed/10.2.3-h13.html create mode 100644 reference/PAN-OS/addressed/10.2.3-h14.html create mode 100644 reference/PAN-OS/addressed/10.2.3-h2.html create mode 100644 reference/PAN-OS/addressed/10.2.3-h4.html create mode 100644 reference/PAN-OS/addressed/10.2.3-h9.html create mode 100644 reference/PAN-OS/addressed/10.2.3.html create mode 100644 reference/PAN-OS/addressed/10.2.4-h10.html create mode 100644 reference/PAN-OS/addressed/10.2.4-h16.html create mode 100644 reference/PAN-OS/addressed/10.2.4-h2.html create mode 100644 reference/PAN-OS/addressed/10.2.4-h3.html create mode 100644 reference/PAN-OS/addressed/10.2.4-h32.html create mode 100644 reference/PAN-OS/addressed/10.2.4-h4.html create mode 100644 reference/PAN-OS/addressed/10.2.4.html create mode 100644 reference/PAN-OS/addressed/10.2.5-h1.html create mode 100644 reference/PAN-OS/addressed/10.2.5-h4.html create mode 100644 reference/PAN-OS/addressed/10.2.5-h6.html create mode 100644 reference/PAN-OS/addressed/10.2.5-h9.html create mode 100644 reference/PAN-OS/addressed/10.2.5.html create mode 100644 reference/PAN-OS/addressed/10.2.6-h1.html create mode 100644 reference/PAN-OS/addressed/10.2.6-h3.html create mode 100644 reference/PAN-OS/addressed/10.2.6-h6.html create mode 100644 reference/PAN-OS/addressed/10.2.6.html diff --git a/reference/PAN-OS/addressed/10.2.0-h1.html b/reference/PAN-OS/addressed/10.2.0-h1.html new file mode 100644 index 0000000..ba64293 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.0-h1.html @@ -0,0 +1,37 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-190311
+
+
+ (PA-220 and PA-220R firewalls and PA-800 Series firewalls only) Fixed an issue where management connectivity to the firewall was + lost due to the expiration of the DHCP lease, which caused the IP + configuration on the management port to be purged in PAN-OS 10.2.0. To + upgrade, download PAN-OS 10.2.0 (no installation), then download and + install PAN-OS 10.2.0-h1. +
+
diff --git a/reference/PAN-OS/addressed/10.2.0-h2.html b/reference/PAN-OS/addressed/10.2.0-h2.html new file mode 100644 index 0000000..23e54cc --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.0-h2.html @@ -0,0 +1,147 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-237871
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
+
PAN-202450
+
+
+ Fixed an issue where the + device-client-cert was set to + expire on December 31, 2023. With this fix, the expiration date has + been extended. +
+
+
PAN-198372
+
+
+ Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
diff --git a/reference/PAN-OS/addressed/10.2.0-h3.html b/reference/PAN-OS/addressed/10.2.0-h3.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.0-h3.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/10.2.0-h4.html b/reference/PAN-OS/addressed/10.2.0-h4.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.0-h4.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/10.2.0.html b/reference/PAN-OS/addressed/10.2.0.html new file mode 100644 index 0000000..ba20614 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.0.html @@ -0,0 +1,96 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
+ PAN-231823 +
+
+
+ A fix was made to address + CVE-2024-5916. +
+
+
PAN-186143
+
+
+ Fixed an issue where no local changes could be made on a ZTP-enabled + device after an upgrade to PAN-OS 10.1.x. +
+
+
PAN-182634
+
+
+ (PA-400 series firewalls only) Fixed an issue + where the firewall detected a Power Supply Unit (PSU) failure for the + opposite side when disconnecting a PSU from the device. This issue + occurred when redundant PSUs were connected. +
+
+
PAN-178165
+
+
+ Fixed an issue where the CLI command + set system setting ctd ctd-agent-assigned-cores 0 + to change assigned cores for the ctd-agent failed. +
+
+
PAN-175950
+
+
+ Fixed an issue where IoT Security (without + Strata Logging Service) onboarding failed. +
+
diff --git a/reference/PAN-OS/addressed/10.2.1-h1.html b/reference/PAN-OS/addressed/10.2.1-h1.html new file mode 100644 index 0000000..881800c --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.1-h1.html @@ -0,0 +1,159 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-239241
+
+
+ Extended the root certificate for WildFire appliances to December 31, + 2032. +
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-237871
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
+
PAN-202450
+
+
+ Fixed an issue where the + device-client-cert was set to + expire on December 31, 2023. With this fix, the expiration date has + been extended. +
+
+
PAN-198372
+
+
+ Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
diff --git a/reference/PAN-OS/addressed/10.2.1-h2.html b/reference/PAN-OS/addressed/10.2.1-h2.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.1-h2.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/10.2.1-h3.html b/reference/PAN-OS/addressed/10.2.1-h3.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.1-h3.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/10.2.1.html b/reference/PAN-OS/addressed/10.2.1.html new file mode 100644 index 0000000..f2521a8 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.1.html @@ -0,0 +1,689 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WIF-495
+
+
+ Fixed an issue on Panorama where edits made to an existing data + filtering profile resulted in matching traffic not being detected by + Enterprise DLP. +
+
+
+ PAN-231823 +
+
+
+ A fix was made to address + CVE-2024-5916. +
+
+
PAN-190311
+
+
+ (PA-220 and PA-220R firewalls and PA-800 Series firewalls only) Fixed an issue where management connectivity to the firewall was + lost due to the expiration of the DHCP lease, which caused the IP + configuration on the management port to be purged in PAN-OS 10.2.0. To + upgrade, download PAN-OS 10.2.0 (no installation), then download and + install PAN-OS 10.2.0-h1. +
+
+
PAN-190175 and PAN-190223
+
+
+ A fix was made to address an OpenSSL infinite loop vulnerability in + the PAN-OS software (CVE-2022-0778). +
+
+
PAN-189665
+
+
+ (FIPS-CC enabled firewalls only) Fixed an issue + where the firewall was unable to connect to log collectors after an + upgrade due to missing cipher suites. +
+
+
PAN-189565
+
+
+ Fixed an issue after upgrading to PAN-OS 10.2 where the + tund + process stopped responding on multiple GlobalProtect clients. +
+
+
PAN-189468
+
+
+ Fixed an issue where the firewall onboard packet processor used by the + PAN-OS content-inspection (CTD) engine can generate high dataplane + resource usage when overwhelmed by a session with an unusually high + number of packets. This can result in + resource-unavailable messages due + to the content inspection queue filling up. Factors related to the + likelihood of an occurrence include enablement of content-inspection + based features that are configured in such a way that might process + thousands of packets in rapid succession (such as SMB file transfers). + This can cause poor performance for the affected session and other + sessions using the same packet processor. PA-3000 series and VM-Series + firewalls are not impacted. +
+
+
PAN-189361
+
+
+ Fixed an issue where Panorama was unable to distribute antivirus + signature updates to firewalls with an Advanced Threat Prevention + license only. +
+
+
PAN-189298
+
+
+ Fixed an issue where existing traffic sessions were not synced after + restarting the active dataplane when it became passive. +
+
+
PAN-189230
+
+
+ (VM-Series firewalls only) Fixed an issue that + caused the + pan_task + process to stop responding with floating point exception (FPE) when + there was a module of 0 on the queue number. +
+
+
PAN-189214
+
+
+ Fixed an issue that prevented antivirus signature update packages that + are normally available to install from displaying properly on the + firewall when the Advanced Threat Prevention license is present on a + firewall without a Threat Prevention license. +
+
+
PAN-189206
+
+
+ Fixed an issue where Device Group and Template administrator roles + didn't support a context switch between the Panorama and firewall web + interfaces. +
+
+
PAN-189106
+
+
+ Fixed an issue on Panorama where you were unable to successfully + downgrade to a PAN-OS 10.1 release unless you uninstalled the ZTP + Plugin 2.0. +
+
+
PAN-189094
+
+
+ Fixed an issue where, after upgrading a CN-Series firewall from a + PAN-OS 10.1 release to PAN-OS 10.2.0, show session commands did not + return output. +
+
+
PAN-189032
+
+
+ Fixed an issue where, when Advanced Routing was enabled on the + firewall, an OSPFv3 interface configured with the p2mp link type + caused commits to fail. +
+
+
PAN-188956
+
+
+ Fixed an issue where, after a successful upgrade to PAN-OS 10.2, + logging into the firewall or Panorama web interface from the same + internet browser window or session from which the firewall or Panorama + was upgraded did not work. +
+
+
PAN-188883
+
+
+ Fixed an issue where, when pre-generated license key files were + manually uploaded via the web interface, they weren't properly + recognized by PAN-OS and didn't display a serial number or initiate a + reboot. +
+
+
PAN-188828
+
+
+ Fixed an intermittent issue where web pages and web page contents did + not properly load when cloud inline categorization was enabled. +
+
+
PAN-188009
+
+
+ Fixed an issue where a firewall import to Panorama running a PAN-OS + 10.1 release or a PAN-OS 10.2 release resulted in corrupted private + information when the master key was not used. +
+
+
PAN-187846
+
+
+ Fixed an issue on Panorama where a selective push pushed an incorrect + configuration to the managed firewalls, which caused the firewalls to + display as out of sync. This issue occurred if the Panorama-pushed + version for the + Shared Policy and Template + configuration were 20 or more versions older than the current local + running configuration on Panorama. +
+
+
PAN-187769
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed a Data Plane Development Kit (DPDK) issue where interfaces + remained in a link-down state after an Azure hot plug event. This + issue occurred due to a hot plug of Accelerated Networking interfaces + on the Azure backend caused by host updates, which led to Virtual + Function unregister/Register messages on the VM side. +
+
+
PAN-186886
+
+
+ Fixed an issue where individual configuration objects were not + viewable after committing selective configuration changes on a + multi-vsys firewall. +
+
+
PAN-186785
+
+
+ Fixed an issue where, after logging in, Panorama displayed a 500 error + page after five minutes of logging for dynamic group template admin + types with access to approximately 115 managed devices or 120 dynamic + groups. +
+
+
PAN-186516
+
+
+ Fixed an issue where log queries that included WildFire submission + logs returned more slowly than expected. +
+
+
PAN-186487
+
+
+ Fixed an issue with snmpd.log overflow caused by continuous hourly + repeating errors. +
+
+
PAN-186402
+
+
+ (PA-440 Series firewalls only) Fixed an issue + where the firewall's maximum tunnel limit was incorrect. +
+
+
PAN-186137
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall management interface incorrectly displayed 10G port + speed as an option even though 10G speed is not supported and can't be + configured. +
+
+
PAN-185616
+
+
+ Fixed an issue where the firewall sent fewer logs to the system log + server than expected. With this fix, the firewall accommodates a + larger send queue for syslog forwarding to TCP syslog receivers. +
+
+
PAN-185164
+
+
+ Fixed an issue where processing corrupted IoT messages caused the + wificlient process to restart. +
+
+
PAN-184224
+
+
+ Fixed an issue on Panorama where you were unable to select a template + variable in + Templates > Device > Log Forwarding Card > Log Forwarding + Card Interface > Network > IP address location. +
+
+
PAN-183826
+
+
+ Fixed an issue where, after clicking + WildFire Analysis Report, the web + interface failed to display the report with the following error + message: refused to connect. +
+
+
PAN-183567
+
+
+ Fixed an issue on Panorama where ZTP Plugin 2.0 was not available for + download before upgrading Panorama to PAN-OS 10.2. +
+
+
PAN-182492
+
+
+ Fixed an issue where the WildFire analysis report was not viewable + from the firewall WildFire submission log entry page. +
+
+
PAN-181839
+
+
+ Fixed an issue where Panorama Global Search reported + No Matches found while still + returning results for matching entries on large configurations. +
+
+
PAN-181039
+
+
+ Fixed an issue with DNS cache depletion that caused continuous DNS + retries. +
+
+
PAN-181031
+
+
+ Fixed an issue where the CN-NGFW (DP) folder on the CN-MGMT pod + eventually consumed a large amount of space in the /var/log/pan + because the old registered stale next-generation firewall logs were + not being cleared. +
+
+
PAN-180338
+
+
+ Fixed an issue where the CTD loop count wasn't accurately incremented. +
+
+
PAN-180095
+
+
+ Fixed an issue where Panorama serial-number-based redistribution + agents did not redistribute HIP reports. +
+
+
PAN-179966
+
+
+ Fixed an issue where, after upgrading to a PAN-OS 8.1 release, the + port on the firewall stayed up, but the port on the connected device + reported down. This occurred because, on force mode, autoneg was + disabled by default. With this fix, autoneg is enabled by default on + force mode. +
+
+
PAN-179420
+
+
+ Fixed an issue on Panorama where a selective push to managed firewalls + failed after renaming an existing device group, template, or template + stack that was already pushed to the managed firewalls and you + selectively committed specific configuration objects from the renamed + device group, template, or template stack. +
+
+
PAN-179321
+
+
+ A validation error was added to inform an administrator when a policy + field contained the value any. +
+
+
PAN-178195
+
+
+ Fixed an issue where the URL filtering logs generated by traffic + analyzed by Advanced URL filtering cloud inline categorization didn't + display the URL name. +
+
+
PAN-177072
+
+
+ Fixed an intermittent issue where Panorama did not show new logs from + firewalls. +
+
+
PAN-176889
+
+
+ Fixed an issue where the log collector continuously disconnected from + Panorama due to high latency and a high number of packets in Send-Q. +
+
+
PAN-176693
+
+
+ (M-300 and M-700 appliances only) Fixed an + issue where the Activity (ACT) LEDs on the RJ-45 ports did not blink + when processing network traffic. +
+
+
PAN-174607
+
+
+ Fixed an intermittent issue where, when Security profiles were + attached to a policy, files that were downloaded across TLS sessions + decrypted by the firewall were malformed. +
+
+
PAN-145833
+
+
+ (PA-3200 Series firewalls only) Fixed an issue + where the firewall stopped recording dataplane diagnostic data in + dp-monitor.log after a few hours of uptime. +
+
diff --git a/reference/PAN-OS/addressed/10.2.2-h1.html b/reference/PAN-OS/addressed/10.2.2-h1.html new file mode 100644 index 0000000..ab71e68 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.2-h1.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-195517
+
+
+ Fixed an issue where + CommitAll operations from Panorama + to Prisma Access device groups failed due to missing configuration + files. +
+
+
PAN-194107
+
+
+ Fixed an issue where the expiry date for the Advanced Threat + Protection license was incorrect for BND3 payg VM-Series firewalls on + Amazon Web Services (AWS), Oracle Cloud Infrastructure (OCI), Google + Cloud Platform (GCP), and Microsoft Azure. +
+
+
PAN-186075
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall rebooted after receiving large packets while in DPDK mode + on Azure virtual machines running CX4 (MLx5) drivers. +
+
diff --git a/reference/PAN-OS/addressed/10.2.2-h2.html b/reference/PAN-OS/addressed/10.2.2-h2.html new file mode 100644 index 0000000..8ad4945 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.2-h2.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-192999
+
+
+ A fix was made to address + CVE-2022-0028. +
+
diff --git a/reference/PAN-OS/addressed/10.2.2-h4.html b/reference/PAN-OS/addressed/10.2.2-h4.html new file mode 100644 index 0000000..6571c71 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.2-h4.html @@ -0,0 +1,159 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237935
+
+
+ Extended the offline PAN-DB, Panorama, and WildFire certificates which + were previously set to expire on September 2, 2024. +
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-237871
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
+
PAN-202450
+
+
+ Fixed an issue where the + device-client-cert was set to + expire on December 31, 2023. With this fix, the expiration date has + been extended. +
+
+
PAN-198372
+
+
+ Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
diff --git a/reference/PAN-OS/addressed/10.2.2-h5.html b/reference/PAN-OS/addressed/10.2.2-h5.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.2-h5.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/10.2.2-h6.html b/reference/PAN-OS/addressed/10.2.2-h6.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.2-h6.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/10.2.2.html b/reference/PAN-OS/addressed/10.2.2.html new file mode 100644 index 0000000..a17970b --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.2.html @@ -0,0 +1,580 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
+ PAN-231823 +
+
+
+ A fix was made to address + CVE-2024-5916. +
+
+
PAN-193579
+
+
+ Fixed an issue where new logs viewed from the CLI (show log + <log_type>) and new syslogs forwarded to a syslog server + contained additional, erroneous entries. +
+
+
PAN-192930
+
+
+ Fixed an issue where, when the default port was not TCP/443, + implicitly used SSL applications were blocked by the Security policy + as an SSL application and did not shift to the correct application. +
+
+
PAN-192880
+
+
+ Fixed an issue where, when the firewall was configured for jumbo + frames, an internal interface was not set with the correct MTU, which + caused byte frames larger than 1500 to be dropped when a DF bit was + set. +
+
+
PAN-192725
+
+
+ Fixed an issue where the firewall failed to forward logs to Panorama + when configured with IPv6 addressing only. +
+
+
PAN-192089
+
+
+ Fixed an issue on the web interface where the IPSec tunnel did not + gray out after disabling it. +
+
+
PAN-191629
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the hourly summary log was limited to 100,001 lines when summarized, + which resulted in inconsistent report results when using summary logs. +
+
+
PAN-191513
+
+
+ Fixed an issue on multi-vsys firewalls where the DLP cloud service + continued to exclude an application added to a shared application + group (ObjectsApplication Filters) from non-file traffic inspection. This issue occurred when the + application was removed from the application group or filter that was + added to the + App Exclusion List (ObjectsDLPData Filtering Profiles). +
+
+
PAN-191470
+
+
+ Fixed an issue on Panorama where encrypted passwords were sent to + firewalls on PAN-OS 10.1 releases during a multi-device group push, + which caused client-based External Dynamic Lists (EDL) to fail. +
+
+
PAN-191466
+
+
+ Fixed an issue where you were unable to use the web interface to + override IPsec tunnels pushed from Panorama +
+
+
PAN-191288
+
+
+ Fixed an issue where the firewall restarted due to a + dnsproxy + process crash. +
+
+
PAN-190811
+
+
+ (PA-5450 firewalls only) Fixed an issue where + logs were forwarded through the management interface instead of the + configured log interface to be used for forwarding. +
+
+
PAN-190675
+
+
+ Fixed an IoT cloud connectivity issue with the firewall dataplane when + the Data Services service route was + used and the egress interface had VLAN tagging. +
+
+
PAN-190492
+
+
+ Fixed an issue where the Panorama log collector group level SSH + settings were not migrated to the new format when upgrading from a + PAN-OS 9.1 release to a PAN-OS 10.0 release. +
+
+
PAN-189429
+
+
+ Fixed a memory leak that occurred when enabling XFF (x-forwarded-for) + logging in a Security policy. +
+
+
PAN-189395
+
+
+ (PA-400 Series firewalls only) Fixed an issue + where running a PAN-OS 10.2 release caused dataplane processes to + restart unexpectedly. +
+
+
PAN-189010
+
+
+ Fixed an issue on Panorama where a deadlock in the + configd + process caused both the web interface and the CLI to be inaccessible. +
+
+
PAN-188872
+
+
+ Fixed an OOM condition caused by a memory leak issue on the + useridd + process. +
+
+
PAN-188833
+
+
+ Fixed an issue where shared address objects used as a source or + destination in policies were cloned but not freed back after + configuration commits. +
+
+
PAN-188097
+
+
+ Fixed an issue where the firewall stopped allocating new sessions with + increments in the counter session_alloc_failure. This was caused by + GPRS tunneling protocol (GTP-U) tunnel session aging processing issue. +
+
+
PAN-187558
+
+
+ Fixed an issue where the following error message flooded the system + log: + Incremental update to DP failed. +
+
+
PAN-187429
+
+
+ (PA-3400 Series firewalls and PA-5410, PA-5420, and PA-5430 + firewalls only) Fixed an issue where the CLI and SNMP MIB walk did not display the + model and serial number of the fan tray and PSUs. +
+
+
PAN-187151
+
+
+ Fixed an issue where tunnel-monitoring interface was incorrectly shown + as up instead of down. +
+
+
PAN-186913
+
+
+ Fixed an issue on Panorama where + Validate Device Group (CommitCommit and Push) incorrectly issued a commit all operation instead of a validate all + operation. This issue occurred when multiple device groups were + included in the push. +
+
+
PAN-186750
+
+
+ Fixed an issue where, after upgrading to a PAN-OS 10.1 release, SaaS + reports generated on Panorama did not display + Applications at a glance and most + charts were missing data on the right side of the chart. +
+
+
PAN-185844
+
+
+ Fixed an issue where Decryption Log entries were associated with the + wrong Security policy rule. +
+
+
PAN-185558
+
+
+ Fixed an issue where Panorama log migration failed when old logs + migrated to a newer format. This was due to older indices failing to + close. +
+
+
PAN-184474
+
+
+ Fixed an issue where, when the firewall had Advanced Routing enabled, + a static route remained active after an interface went down. +
+
+
PAN-183579
+
+
+ Fixed an issue where SD-WAN path monitoring failed over the interface + directly connected to the ISP due to an unsupported ICMP probe format. +
+
+
PAN-183319
+
+
+ Fixed an issue on Panorama where commits remained at 99% due to + multiple firewalls sending out CSR singing requests every 10 minutes. +
+
+
PAN-182087
+
+
+ Fixed an issue where commit failures occurred due to validity checks + performed against self-signing certificates not evaluating + Authentication Key Identifier and + Subject Key Identifier fields were + present. +
+
+
PAN-180396
+
+
+ Fixed an issue where Panorama displayed an error when generating a + ticket to disable GlobalProtect for Prisma Access. +
+
+
PAN-180147
+
+
+ Fixed an issue where the + bcm.log and + brdagent_stdout.log-<datestamp> + files filled up the root disk space. +
+
+
PAN-178450
+
+
+ Fixed an issue where icons weren't displayed for clientless VPN + applications. +
+
+
PAN-177671
+
+
+ Fixed an issue where, when SIP traffic traversing the firewall was + sent with a high Quality of Service (QoS) differentiated service code + (DSCP) value, the DSCP value was reset to the default setting (CS0) + for the first data packet. +
+
+
PAN-177455
+
+
+ PA-7000 Series firewalls with HA clustering enabled and using HA4 + communication links only) Fixed an issue where loading PAN-OS 10.2.0 on the firewall caused + the PA-7000 100G NPC (Network Processing Card) to go offline. As a + result, the firewall failed to boot normally and entered maintenance. +
+
+
PAN-176156
+
+
+ Fixed an issue where executing the + show running resource-monitor with + the ingress-backlogs option + enabled displayed the error message `Dataplane is not up or invalid + target-dp(*.dp*)`. +
+
+
PAN-174345
+
+
+ Fixed an issue where a process + all_pktproc + stopped responding after upgrading the firewall. +
+
diff --git a/reference/PAN-OS/addressed/10.2.3-h11.html b/reference/PAN-OS/addressed/10.2.3-h11.html new file mode 100644 index 0000000..1595463 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.3-h11.html @@ -0,0 +1,103 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
diff --git a/reference/PAN-OS/addressed/10.2.3-h12.html b/reference/PAN-OS/addressed/10.2.3-h12.html new file mode 100644 index 0000000..1595463 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.3-h12.html @@ -0,0 +1,103 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
diff --git a/reference/PAN-OS/addressed/10.2.3-h13.html b/reference/PAN-OS/addressed/10.2.3-h13.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.3-h13.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/10.2.3-h14.html b/reference/PAN-OS/addressed/10.2.3-h14.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.3-h14.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/10.2.3-h2.html b/reference/PAN-OS/addressed/10.2.3-h2.html new file mode 100644 index 0000000..e01946a --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.3-h2.html @@ -0,0 +1,206 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-205830
+
+
+ Fixed an issue with multi-vsys firewalls where custom applications and + shared objects pushed from Panorama did not populate in their + respective lists on the firewall. +
+
+
PAN-205805
+
+ Fixed an issue where Generic routing encapsulation (GRE) traffic was + only allowed in one direction when tunnel content inspection (TCI) was + enabled. +
+
PAN-205231
+
+
+ Fixed an issue where a commit operation remained at 55% for longer + than expected if more than 7,500 Security policy rules were + configured. +
+
+
PAN-202795
+
+
+ Fixed an issue where file identification failed for files with minimal + data with large headers. +
+
+
PAN-202535
+
+
+ Fixed an issue where the Device Telemetry configuration for a region + was unable to be set or edited via the web interface. +
+
+
PAN-201872
+
+
+ Fixed an issue where SMB performance caused overall network latency + after an upgrade. +
+
+
PAN-201714
+
+
+ Fixed an issue with GlobalProtect where attempting to authenticate + with the GlobalProtect gateway returned a 502 error code. +
+
+
PAN-201357
+
+
+ The CLI command + debug dataplane set pow no-desched yes + was added to address an issue where the + all_pktproc + process stopped responding and caused traffic issues. +
+
+
PAN-200946
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where GRE tunnels went down due to recursive routing when the passive + firewall was booting up. When the passive firewall became active and + no recursive routing was configured, the GRE tunnel remained down. +
+
+
PAN-198718
+
+
+ (PA-5280 firewalls only) Fixed an issue where + memory allocation failures caused increased decryption failures. +
+
+
PAN-196583
+
+
+ Fixed an issue where the Cisco TrustSEc plugin triggered a flood of + redundant register/unregister messages due to a failed IP address tag + database search. +
+
+
PAN-195756
+
+
+ Fixed an issue that caused an API request timeout when parsing + requests using large header buffers. +
+
+
PAN-195713
+
+
+ Fixed an issue where clientless VPN applications were not displayed in + the GlobalProtect portal page. +
+
+
PAN-182732
+
+
+ Fixed an issue where the GlobalProtect gateway inactivity timer wasn't + refreshed even though traffic was passing through the tunnel. +
+
diff --git a/reference/PAN-OS/addressed/10.2.3-h4.html b/reference/PAN-OS/addressed/10.2.3-h4.html new file mode 100644 index 0000000..2047e9a --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.3-h4.html @@ -0,0 +1,244 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-210513
+
+
+ Fixed an issue where Captive Portal authentication via SAML did not + work. +
+
+
PAN-208737
+
+
+ Fixed an issue where domain information wasn't populated in IP + address-to-username matching after a successful GlobalProtect + authentication using an authentication override cookie. +
+
+
PAN-208079
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the PAN-DB engine did not start when using a + VM-Series firewall Flex based CPU. +
+
PAN-207562
+
+
+ Fixed an issue where the shard count displayed by the + show log-collector-es-cluster health + CLI command was higher than the recommended limit. The recommended + limit can be calculated with the formula + 20*heap-memory*no-of-data-nodes. +
+
+
PAN-206963
+
+
+ (M-700 Appliances only) A CLI command was added + to check the status of each physical port of a bond1 interface. +
+
+
PAN-206921
+
+
+ Fixed an issue where the GlobalProtect client pre-login was + successful, but the certificate authentication failed. +
+
+
PAN-206466
+
+
+ Fixed an issue where the push scope was displaying duplicate shared + objects for each device group that were listed under the + shared-object group. +
+
+
PAN-206069
+
+
+ Fixed an issue where the firewall was unable to boot up on older Intel + CPUs. +
+
+
PAN-205698
+
+
+ Fixed an issue where GlobalProtect authentication did not work on + Apple MacOS devices when the authentication method used was CIE with + SAML Authentication. +
+
+
PAN-204892
+
+
+ Fixed an issue on Panorama where the web interface was not accessible + and displayed the error + 504 Gateway Not Reachable due to the + mgmtsrvr + process not responding. +
+
+
PAN-204838
+
+
+ Fixed an issue where the + dot1q VLAN tag in ARP reply + packets were not displayed. +
+
+
PAN-204572
+
+
+ Fixed an issue where python scripts were not working as expected. +
+
+
PAN-197339
+
+
+ Fixed an issue where template configuration for the User-ID agent was + not reflected on the template stack on Panorama appliances on PAN-OS + 10.2.1. +
+
+
PAN-196954
+
+
+ Fixed a memory leak issue related to the + distributord process. +
+
+
PAN-195149
+
+
+ Fixed an issue where firewall administrators were unable to log in to + the web interface when RADIUS two-factor authentication was used. +
+
+
PAN-186270
+
+
+ Fixed an issue where, when high availability (HA) was enabled and a + dynamic update schedule was configured, the + configd + process unexpectedly stopped responding during configuration commits. +
+
diff --git a/reference/PAN-OS/addressed/10.2.3-h9.html b/reference/PAN-OS/addressed/10.2.3-h9.html new file mode 100644 index 0000000..13f93dd --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.3-h9.html @@ -0,0 +1,48 @@ + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-202450
+
+
+ Fixed an issue where the + device-client-cert was set to + expire on December 31, 2023. With this fix, the expiration date has + been extended. +
+
+
PAN-198372
+
+
+ Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
diff --git a/reference/PAN-OS/addressed/10.2.3.html b/reference/PAN-OS/addressed/10.2.3.html new file mode 100644 index 0000000..8e1e923 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.3.html @@ -0,0 +1,1838 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
+ PAN-231823 +
+
+
+ A fix was made to address + CVE-2024-5916. +
+
+
PAN-209275
+
+
+ Fixed an issue where Override cookie authentication into the + GlobalProtect gateway failed when an allow list was configured under + the authentication profile. +
+
+
PAN-201627
+
+
+ Fixed an issue in next-generation firewall deployments where, when + SD-WAN was configured, the dataplane restarted if all SD-WAN member + links were down due to an out-of-memory (OOM) condition or during a + reboot when all SD-WAN tunnels were down. +
+
+
PAN-200771
+
+
+ Fixed an issue where + syslog-ng + was unable to start due to a design change in the syslog configuration + file. +
+
+
PAN-199654
+
+
+ Fixed an issue where ACC reports did not work for custom RBAC users + when more than 12 access domains were associated with the username. +
+
+
PAN-199311
+
+
+ Fixed an issue where the Log Forwarding Card (LFC) failed to forward + logs to the syslog server. +
+
+
PAN-199099
+
+
+ Fixed an issue where, when decryption was enabled, Safari and Google + Chrome browsers on Apple Mac computers rejected the server certificate + created by the firewall because the Authority Key Identifier was + copied from the original server certificate and did not match the + Subject Key Identifier on the forward trust certificate. +
+
+
PAN-198733
+
+
+ (PA-5450 firewalls only) Fixed an issue where + dmin tcpdump was hardcoded to + eth0 instead of bond0. +
+
+
PAN-198332
+
+
+ (PA-5400 Series only) Fixed an issue where + swapping Network Processing Cards (NPCs) caused high root partition + use. +
+
+
PAN-198266
+
+
+ Fixed an issue where, when predicts for UDP packets were created, a + configuration change occurred that triggered a new policy lookup, + which caused the dataplane stopped responding when converting the + predict. This resulted in a dataplane restart. +
+
+
PAN-198244
+
+
+ Fixed an issue where using the + load config partial CLI command + to x-paths removed address object entries from address groups. +
+
+
PAN-197576
+
+
+ Fixed an issue where commits pushed from Panorama caused a memory leak + related to the + mgmtsrvr + process. +
+
+
PAN-197484
+
+
+ (PA-5400 Series firewalls) Fixed an issue where + the firewall forwarded packets to the incorrect aggregate ethernet + interface when Policy Based Forwarding (PBF) was used. +
+
+
PAN-197383
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2 release, the + firewall ran a RAID rebuild for the log disk after ever every reboot. +
+
+
PAN-197244
+
+
+ Fixed an issue on firewalls with Forward Proxy enabled where the + all_pktproc + process stopped responding due to missed heartbeats. +
+
+
PAN-196993
+
+
+ Fixed an issue where an incorrect regex key was generated to + invalidate the completions cache, which caused the + configd + process to stop responding. +
+
+
PAN-196953
+
+
+ (PA-5450 firewalls only) Fixed an issue where + jumbo frames were dropped. +
+
+
PAN-196445
+
+
+ Fixed an issue where restarting the Network Processing Card (NPC) or + the Data Processing Card (DPC) did not bring up all the network + interfaces. +
+
+
PAN-196398
+
+
+ (PA-7000 Series SMC-B firewalls only) Fixed an + issue where the firewall did not capture data when the active + management interface was MGT-B. +
+
+
PAN-196227
+
+
+ Fixed an issue where the + logd + process stopped responding, which caused Panorama to reboot into + maintenance mode. +
+
+
PAN-196005
+
+
+ (PA-3200 Series, PA-5200 Series, and PA-5400 Series firewalls + only) Fixed an issue where GlobalProtect IPSec tunnels disconnected at + half the inactivity logout timer value. +
+
+
PAN-195707
+
+
+ Fixed an issue on Panorama appliances configured as log collectors + where Panorama repeatedly rebooted into maintenance mode. +
+
+
PAN-195689
+
+
+ Fixed an issue where WildFire submission logs did not load on the + firewall web interface. +
+
+
PAN-195628
+
+
+ Fixed an issue that caused the + pan_task + process to miss heartbeats and stop responding. +
+
+
PAN-195625
+
+
+ Fixed an issue where + authd + frequently created SSL sessions, which resulted in an OOM condition. +
+
+
PAN-195360
+
+
+ Fixed an issue with firewalls in Microsoft Azure environments where + BGP flapping occurred due to the firewall incorrectly treating + capability from BGP peering as unsupported. +
+
+
PAN-195223
+
+
+ Fixed an issue where the + all_pktproc + process restarted when receiving a GTPv2 Modify Bearer Request packet + if the Serving GPRS Support Node (SGSN) used the same key as the + Serving Gateway (SGW). +
+
+
PAN-195181
+
+
+ Added enhancements to improve the load on the + pan_comm + process during SNMP polling. +
+
+
+ PAN-194993 +
+
+
+ Fixed an issue that occurred when authenticating into GlobalProtect + with authentication override cookies and SAML where, if the cookie was + invalid, authentication did not fall back to SAML. +
+
+
PAN-194826
+
+
+ (WF-500 and WF-500-B appliances only) Fixed an + issue where log system forwarding did not work over a TLS connection. +
+
+
PAN-194782
+
+
+ Fixed an issue on Panorama where, if you added a new local or + non-local administrator account or an admin user to a template, + authentication profiles were incorrectly referenced. +
+
+
PAN-194708
+
+
+ Fixed an issue where URL filtering logs (MonitorLogsURL Filtering) incorrectly truncated a 16KB Header value and did not display the + Header values that followed the truncated 16KB header. +
+
+
PAN-194694
+
+
+ Fixed an issue where multiple SNMP requests being made to the firewall + caused in the + pan_comm + process to stop responding. +
+
+
PAN-194601
+
+
+ Fixed an issue that caused the + all_task + process to stop responding. +
+
+
PAN-194588
+
+
+ (PA-7000 Series firewalls with LFCs (Log Forwarding Cards), PA-7050 + firewalls with SMC-B (Switch Management Cards), and PA-7080 + firewalls only) Fixed an issue where the + logrcvr_statistics output was not + recorded in mp-monitor.log. +
+
+
PAN-194481
+
+
+ Fixed an issue in ESXi where the bootstrapped VM-Series firewalls with + the Software Licensing Plugin had + :xxx appended to their hostnames. +
+
+
PAN-194408
+
+
+ Fixed an issue where, when policy rules had the apps that implicitly + depended on web browsing configured with the service + application default, traffic did not match the rule correctly. +
+
+
PAN-194406
+
+
+ Fixed an issue where the MTU from SD-WAN interfaces was recalculated + after a configuration push from Panorama or a local commit, which + caused traffic disruption. +
+
+
PAN-194262
+
+
+ Fixed an issue where the GlobalProtect application failed to connect + when a user or group was configured under the portal + Config Selection Criteria. +
+
+
PAN-194152
+
+
+ (PA-5410, PA-5420, PA-5430, and PA-5440 firewalls in HA + configurations only) Fixed an issue where HA1-A and HA1-B port information didn't match + to front panel mappings and, when one firewall was on PAN-OS 10.2.3 or + a later release and the other was on PAN-OS 10.2.2 or an earlier + release, a split-brain situation occurred. +
+
+
PAN-194129
+
+
+ (PA-5450 firewalls only) Fixed an issue where + slot 2 did not use all features correctly if a DPC was used instead of + an NPC. +
+
+
PAN-194097
+
+
+ Fixed an issue on firewalls in high availability (HA) active/passive + configurations where + _ha_d_session_msgbuf overflowed + on the passive firewall during an upgrade, which caused the firewall + to enter a non-functional state. +
+
+
PAN-193981
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall stopped monitoring HA failure and + floating IP addresses did not get moved to the newly active firewall. +
+
+
PAN-193899
+
+
+ Fixed an issue where advanced mode factory reset (Maintenance ModeFactory ResetAdvancedselect a specific image) was only compatible with PAN-OS 10.1.3 or later version images. +
+
+
PAN-193818
+
+
+ Fixed an issue where the firewall device server failed to resolve URL + cloud FQDNs, which interrupted URL category lookup. +
+
+
PAN-193766
+
+
+ (VM-Series firewalls only) Fixed an issue where + the GlobalProtect portal was not accessible. +
+
+
PAN-193765
+
+
+ Fixed an issue where commits failed the following error displayed in + the + configd + log: + Unable to populate ids into candidate config: Error: Error + populating id for 'sg2+DMZ to FirstAM Scanner-1. +
+
+
PAN-193763
+
+
+ Fixed an issue on the firewall where the dataplane CPU spiked, which + caused traffic to be affected during commits or content updates. +
+
+
PAN-193744
+
+
+ (PA-3200 Series firewalls only) Fixed an issue + where, when the HA2 HSCI connection was down, the system log displayed + Port HA1-b: down instead of + Port HSCI: Down. +
+
+
PAN-193732
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where the firewall incorrectly handled internal transactions. +
+
+
PAN-193707
+
+
+ Fixed an issue where SAML authentication failed during commits with + the following error message: + revocation status could not be verified (reason: ). +
+
+
PAN-193483
+
+
+ (VM-Series firewalls only) Fixed an issue + where, during Layer-7 packet inspection where traffic was being + inspected for threat signature and data patterns, multiple processes + stopped responding. +
+
+
PAN-193392
+
+
+ Fixed an issue where RTP packets dropped due to conflicting duplicate + flows. +
+
+
PAN-193251
+
+
+ Fixed an issue where, when SAML was configured as the authentication + method for GlobalProtect, the SAML page did not load when using a + browser. +
+
+
PAN-193235
+
+
+ Fixed an issue where duplicate log entries were displayed on Panorama. +
+
+
PAN-193201
+
+
+ Fixed an issue where auto-commits failed after an upgrade if an + imported certificate size was greater than the size of a buffer. +
+
+
PAN-193132
+
+
+ (PA-220 firewalls only) Fixed an issue where a + commit and push from Panorama caused high dataplane CPU utilization. +
+
+
PAN-192944
+
+
+ Fixed an issue where the + logrcvr + process caused an OOM condition. +
+
+
PAN-192739
+
+
+ Fixed an issue where the error message + Machine Learning found virus was + displayed in threat CSV logs as + Threat ID/Name when WildFire Inline + ML detected malware. +
+
+
PAN-192726
+
+
+ Fixed an issue where the firewall dropped TCP traffic inside IPSec + tunnels. +
+
+
PAN-192673
+
+
+ (PA-7050-SMC-B firewalls only) Fixed an issue + where the LFC syslog-ng service failed to start after an upgrade. +
+
+
PAN-192666
+
+
+ (VM-Series firewalls only) Fixed an issue where + uploading certificates via API failed within the first 30 minutes of a + bootstrap. +
+
+
PAN-192551
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where the firewall incorrectly processed path monitoring packets. +
+
+
PAN-192404
+
+
+ Fixed an issue where ARP broadcasts occurring in the same time + interval and network segment as HA path monitoring pings triggered an + ARP cache request, which prevented the firewall from sending ICMP echo + requests to the monitored destination IP address and caused an HA path + monitoring failover. +
+
+
PAN-192330
+
+
+ (Bootstrapped VM-Series firewalls in Microsoft Azure environments + only) Fixed an issue where the firewall did not automatically receive the + Strata Logging Service license. +
+
+
PAN-192052
+
+
+ Fixed an issue where, when next hop MAC address entries weren't found + on the offload processor for active traffic, update messages flooded + the firewall, which caused resource contention and traffic disruption. +
+
+
PAN-191874
+
+
+ Fixed an issue where monthly scheduled reports did not display + information after upgrading to PAN-OS 10.2.0. +
+
+
PAN-191847
+
+
+ Fixed an issue where the Panorama appliance was unable to generate + scheduled custom reports due to the large number of files stored in + the + opt/pancfg/mgmt/custom-reports + directory. +
+
+
PAN-191726
+
+
+ Fixed an issue where an SCP export of the device state from the + firewall added single quotes ( ' ) to the filename. +
+
+
PAN-191558
+
+
+ Fixed an issue where, after an upgrade to PAN-OS 10.1.5, Global Find + did not display all results related to a searched item. +
+
+
PAN-191269
+
+
+ Fixed an issue where the NAT pool leaked for passive mode FTP predict + sessions. +
+
+
PAN-191222
+
+
+ Fixed an issue where Panorama became inaccessible when after a push to + the collector group. +
+
+
PAN-191218
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where the session log storage quota could not be changed via the web + interface. +
+
+
PAN-191216
+
+
+ Fixed an issue where, on Apple iOS devices, SAML authentication did + not connect to the GlobalProtect portal. +
+
+
PAN-191214
+
+
+ Fixed an issue where the Elasticsearch process stopped responding, + which caused an OOM condition. +
+
+
PAN-190657
+
+
+ Fixed an issue where IPSec tunnels did not rekey due to the security + association being deleted too early. +
+
+
PAN-190448
+
+
+ Fixed an issue in ACC reports where IPv6 addresses were displayed + instead of IPv4 addresses. +
+
+
PAN-189894
+
+
+ Fixed an issue with the web interface where the template stack didn't + show inherited values of + Template > Authentication Portal Settings. +
+
+
PAN-189861
+
+
+ Fixed an issue on firewalls in HA configurations where intermittent + system alerts on the active firewall caused the + pan_comm + process to restart continuously. +
+
+
PAN-189859
+
+
+ Fixed an issue on the firewall where an administrator was unable to + Import Custom URL Category Content. +
+
+
PAN-189762
+
+
+ Fixed an issue where a predict session didn't match with the traffic + when both source NAT and destination NAT were enabled. +
+
+
PAN-189723
+
+
+ Fixed an issue where you were unable to configure dynamic address + groups to use more than 64,000 IP addresses in a Security policy. +
+
+
PAN-189414
+
+
+ Fixed an issue where TCP packets were dropped during the first zone + transfer when DNS security was enabled. +
+
+
PAN-189304
+
+
+ Fixed an issue where the Panorama appliance didn't display logs or + generate reports for a device group containing MIPs platform that + forwarded logs to Strata Logging Service. +
+
+
PAN-189270
+
+
+ Fixed an issue that caused a memory leak on the + reportd + process. +
+
+
PAN-189225
+
+
+ Fixed an issue where BGP routes were lost or uninstalled after + disabling jumbo frames on the firewall. +
+
+
PAN-189114
+
+
+ Fixed an issue where the dataplane went down, which caused an HA + failover. +
+
+
PAN-188867
+
+
+ Fixed an issue where the firewall dropped packets when the session + payload was too large. +
+
+
PAN-188489
+
+
+ (VM-Series firewalls only) Fixed an issue where + dynamic content updates weren't automatically pushed to the firewall + licensed using the Panorama Software Firewall License plugin when + Automatically push content when software device registers to + Panorama + (PanoramaTemplatesAdd Stack) was enabled. +
+
+
PAN-188338
+
+
+ Fixed an issue where canceling a commit caused the commit process to + remain at 70% and the firewall had to be rebooted. +
+
+
PAN-188303
+
+
+ Fixed an issue where the serial number displayed as + unknown after running the + show system state CLI command. +
+
+
PAN-188096
+
+
+ (VM-Series firewalls only) Fixed an issue + where, on firewalls licensed with Software NGFW Credit (VM-FLEX-4 and + higher), HA clustering was unable to be established. +
+
+
PAN-187985
+
+
+ Fixed an issue where you were unable to configure a QoS Profile as + percentage for Clear Text Traffic. +
+
+
PAN-187890
+
+
+ Fixed an issue where the + Strata Logging Service connection incorrectly + displayed as disconnected when a service route was in use. +
+
+
PAN-187805
+
+
+ Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted during certificate + construction or destruction. +
+
+
PAN-187476
+
+
+ Fixed an issue where, when hip-redistribution is enabled, Panorama + doesn't display a part of HIP information. +
+
+
PAN-187234
+
+
+ Fixed an intermittent issue where web pages submitted for analysis by + Advanced URL Filtering cloud inline categorization experienced high + latency. +
+
+
PAN-186891
+
+
+ Fixed an issue where NetFlow packets contained incorrect octet counts. +
+
+
PAN-186418
+
+
+ Fixed an issue where Panorama displayed a discrepancy in RAM + configured on the VMware host. +
+
+
PAN-186134
+
+
+ Fixed an issue on Panorama where performing a commit and push + intermittently failed to push the committed configuration to managed + firewalls. +
+
+
PAN-186075
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall rebooted after receiving large packets while in DPDK mode + on Azure virtual machines running CX4 (MLx5) drivers. +
+
+
PAN-185787
+
+
+ Fixed an issue where logging in to the Panorama web interface did not + work and the following error message displayed: + Timed out while getting config lock. Please try again. +
+
+
PAN-185283
+
+
+ Fixed an issue on Panorama where using the + name-of-threatid contains log4j + filter didn't produce expected results. +
+
+
PAN-184702
+
+
+ (M-700 appliances in Log Collector mode only) + Fixed an issue on the Panorama management server where the Panorama + appliance failed to connect to Panorama when added as a managed log + collector. +
+
+
PAN-184068
+
+
+ (PA-5200 Series firewalls only) Fixed an issue + where the firewall generated pause frames, which caused network + latency. +
+
+
PAN-183788
+
+
+ Fixed an issue with SCEP certificate enrollment where the incorrect + Registration Authority (RA) certificate was chosen to encrypt the + enrollment request. +
+
+
PAN-185750
+
+
+ Updated an issue to eliminate failed + pan_comm + software issues that caused the dataplane to restart unexpectedly +
+
+
PAN-183270
+
+
+ Fixed an issue where a bootstrapped firewall connected only to the + first log collector in a log collector group. +
+
+
PAN-183184
+
+
+ Fixed an issue where enabling SSL decryption with a Hardware Security + Model (HSM) caused a dataplane restart. +
+
+
PAN-183166
+
+
+ Fixed an issue where system, configuration, and alarm logs were queued + up on the + logrcvr + process and were not forwarded out or written to disk until an + autocommit was passed. +
+
+
PAN-182689
+
+
+ Fixed an issue where a signature from a previous WildFire package + triggered virus detection even though the signature was no longer + present in the current WildFire package. +
+
+
PAN-182539
+
+
+ Fixed an issue with Panorama appliances in HA configurations where + dedicated log collectors did not send local system or configuration + logs to both Panorama appliances. +
+
+
PAN-182212
+
+
+ Fixed an issue where SNMP reported the + panVsysActiveTcpCps and + panVsysActiveUdpCps value to be + 0. +
+
+
PAN-181277
+
+
+ Fixed an issue where VPN tunnels in SD-WAN flapped due to duplicate + tunnel IDs. +
+
+
PAN-179543
+
+
+ Fixed an issue where the + flow_mgmt + process stopped responding when attempting to clear the session table, + which caused the dataplane to restart. +
+
+
PAN-179258
+
+
Fixed an issue where system disk migration failed.
+
+
PAN-178243
+
+
+ Fixed an issue where + Shared Gateway was not visible in + the Virtual System drop down when + configuring a Layer3 aggregate subinterface. +
+
+
PAN-178194
+
+
+ Fixed an issue with the web interface where, when only the Advanced + URL Filtering license was activated, the message + License required for URL filtering to function + was incorrectly displayed and the + URL Filtering Profile > Inline ML + section was disabled. +
+
+
PAN-177482
+
+
+ Fixed an issue where + ACC > App Scope > Threat Monitor + showed NO DATA TO DISPLAY. +
+
+
PAN-172501
+
+
+ Fixed an issue where you were unable to revert HA mode settings to the + default values from the web interface. +
+
+
PAN-171714
+
+
+ Fixed an issue where, when NetBIOS format (domain\user) was used for + the IP address-to-username mapping and the firewall received the group + mapping information from the Cloud Identity Engine, the firewall did + not match the user to the correct group. +
+
+
PAN-157215
+
+
+ Fixed an issue that occurred when two FQDNs were resolved to the same + IP address and were configured as the same src/dst of the same rule. + If one FQDN was later resolved to a different IP address, the IP + address resolved for the second FQDN was also changed, which caused + traffic with the original IP address to hit the incorrect rule. +
+
+
PAN-151469
+
+
+ Fixed an issue where packets were dropped unexpectedly due to errors + parsing the IP version field. +
+
diff --git a/reference/PAN-OS/addressed/10.2.4-h10.html b/reference/PAN-OS/addressed/10.2.4-h10.html new file mode 100644 index 0000000..1595463 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.4-h10.html @@ -0,0 +1,103 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
diff --git a/reference/PAN-OS/addressed/10.2.4-h16.html b/reference/PAN-OS/addressed/10.2.4-h16.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.4-h16.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/10.2.4-h2.html b/reference/PAN-OS/addressed/10.2.4-h2.html new file mode 100644 index 0000000..ff4fa06 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.4-h2.html @@ -0,0 +1,138 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
PAN-218285 + Fixed an issue where after switching the SPN by suspending the active + SPN, the forwarding rule was not correctly pointing to the new active + node when moved from 3 rules (TCP/UDP/ICMP) to 1 Layer 3 default rule in + GCP. +
+
PAN-217484
+
+
+ Fixed an issue where the + rasmgr + process used 100% CPU due to a maximum duration timer not being set, + which caused the GlobalProtect gateway to be unavailable. +
+
PAN-217431 + Fixed an issue with slot 2 DPCs where URL Filtering did not work as + expected after upgrading to PAN-OS 10.1.9. +
PAN-216710 + Fixed an issue with firewalls in active/active HA configurations where + GlobalProtect disconnected when the original suspected active-primary + firewall became active-secondary. +
PAN-216036 + Fixed an issue where the + all_pktproc process stopped responding, + which caused the firewall to enter a nonfunctional state. +
PAN-215823 + Fixed an issue on log collectors where the + reportd process stopped responding. +
PAN-215496 + Fixed an issue where 100G ports did not come up with BIDI QSFP modules. +
PAN-214406 + Fixed an issue with Elasticsearch where ES tunnels weren’t started and + were forked incorrectly, which caused them to fail. +
PAN-213079 + Fixed an issue with Captive Portal SAML authentication by increasing the + number of retries in the Nginx configuration. +
+ PAN-212726 +
PAN-211519
+
+ Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP + ALG when the source NAT translation type was persistent + Dynamic IP And Port. +
PAN-211870 + Fixed an issue where path monitoring failure occurred, which caused high + availability failover. +
PAN-195912 + Fixed an issue where connections from the firewall to + Strata Logging Service failed. +
diff --git a/reference/PAN-OS/addressed/10.2.4-h3.html b/reference/PAN-OS/addressed/10.2.4-h3.html new file mode 100644 index 0000000..3a34fda --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.4-h3.html @@ -0,0 +1,308 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-222035
+
+
+ Fixed an issue where when multiple portals were configured in Prisma + Access deployments, CIE SAML authentication failed on the secondary + portal. +
+
+
PAN-221068
+
+
+ Fixed an issue where the firewall restarted after a failed push from + Panorama, which resulted in autocommit failures. +
+
+
PAN-219355
+
+
+ Fixed an issue where disk space became full due to a GPSVC FD leak. +
+
+
PAN-219333
+
+
+ Fixed an issue where a secondary Prisma Access Portal address with + port 8443 did not work. +
+
+
PAN-218620
+
+
+ Fixed an issue where scheduled configuration exports and SCP server + connection testing failed. +
+
+
PAN-218368
+
+
+ Fixed an issue with incorrect VLAN tagging on Intel based platforms + that occurred when opening a response page from a virtual-wire + subinterface. +
+
+
PAN-218340
+
+
+ Fixed a memory leak issue related to the + configd + process that affected selective pushes on Panorama. +
+
+
PAN-218267
+
+
+ Fixed an issue where a partial commit and push operation from Panorama + to managed firewalls did not work as expected. +
+
+
PAN-218046
+
+
+ Fixed an issue where the + Virtual Routers (NetworkVirtual Routers) setting was not available when configuring a custom admin role + DeviceAdmin Roles. +
+
+
PAN-217053
+
+
+ Fixed an issue where the + configd + process stopped responding after a selective push to multiple device + groups failed. +
+
+
PAN-215899
+
+
+ Fixed an issue with Panorama appliances in high availability (HA) + configurations where configuration synchronization between the HA + peers failed. +
+
+
PAN-215767
+
+
+ Fixed an issue where, after a high availability failover, IKE SA + negotiation failed with the error message + INVALID_SPI, which resulted in + temporary loss of traffic over some proxy IDs. +
+
+
PAN-215324
+
+ (PA-5400 Series firewalls with Jumbo Frames enabled only) Fixed an issue with CPU throttling and buffer depletion. +
+
PAN-215315
+
+
+ Fixed an issue where the dataplane stopped responding due to ager and + inline packet processing occurring concurrently on different cores for + the same session. +
+
+
PAN-214463
+
+
+ Fixed an issue where IKE rekey negotiation failed with a third-party + vendor and the firewall acting as the initiator received a response + with the VENDOR_ID payload and the error message + unexpected critical payload (type 43). +
+
+
PAN-213973
+
+
+ Fixed an issue where the + authd + process stopped responding during a cleanup of authentication server + context. +
+
+
PAN-212978
+
+
+ Fixed an issue where the firewall stopped responding when executing an + SD-WAN configuration or operational CLI command. +
+
+
PAN-210366
+
+
+ Fixed an issue where deleting a device group when a selective + configuration push was in progress caused the + configd + process to stop responding. +
+
+
PAN-208240
+
+
+ Fixed an issue where, when attempting to replace an existing + certificate, importing a new certificate with the same name as the + existing certificate failed due to mismatched public and private keys. +
+
diff --git a/reference/PAN-OS/addressed/10.2.4-h32.html b/reference/PAN-OS/addressed/10.2.4-h32.html new file mode 100644 index 0000000..d32ffbb --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.4-h32.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/10.2.4-h4.html b/reference/PAN-OS/addressed/10.2.4-h4.html new file mode 100644 index 0000000..39e2cde --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.4-h4.html @@ -0,0 +1,221 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-223501
+
+
+ Fixed an issue where diagnostic information for the dataplane in the + dp-monitor.log file was not complete. +
+
+
PAN-222712
+
+
+ (PA-5450 firewalls only) Fixed a low frequency + DPC restart issue. +
+
+
PAN-221984
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where an interface went down after a hotplug event + and was only recoverable by restarting the firewall. +
+
+
PAN-221836
+
+
+ Fixed an issue where improper SNI detection caused incorrect URL + categorization. +
+
+
PAN-219508
+
+
+ (VM-Series, PA-400 Series, PA-1400, PA-3400, and PA-5400 Series + firewalls only) Fixed an issue where Bidirectional Forwarding Detection (BFD) + packets experienced a delay in processing, which caused the BFD + connection to flap. +
+
+
PAN-217489
+
+ Fixed an issue with firewalls in active/passive high availability (HA) + configurations where the passive firewall MAC flapping occurred when the + passive firewall was rebooted. +
+
PAN-216043
+
+
+ Fixed an issue where wifclient stopped responding due to shared memory + corruption. +
+
+
PAN-215655
+
+
+ Fixed an issue where, after a multi-dynamic group push, Security + policies with the target device tag was added to a firewall that did + not have the tag. +
+
+
PAN-215066
+
+
+ Fixed an issue on Panorama where push scope rendering caused the + commit and push or push operation window to hang for several minutes. +
+
+
PAN-214187
+
+
+ Fixed an issue where superreaders were able to execute the + request restart system CLI command. +
+
+
PAN-211191
+
+
+ Fixed an issue where the firewall restarted after initiating a + mgmtsrvr + process restart. +
+
+
PAN-210661
+
+
+ Fixed an issue where firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
+
+
PAN-210429
+
+
+ (VM-Series firewalls only) Fixed an issue where + the HTTP service failed to come up on DHCP dataplane interfaces after + rebooting the firewall, which resulted in health-check failure on + HTTP/80 with a 503 error code on the public load balancer. +
+
+
PAN-195439
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the dataplane interface status went down after + a hotplug event triggered by Azure infrastructure. +
+
+
PAN-169586
+
+
+ Fixed an issue where scheduled log view reports in emails didn't match + the monitor page query result for the same time interval. +
+
diff --git a/reference/PAN-OS/addressed/10.2.4.html b/reference/PAN-OS/addressed/10.2.4.html new file mode 100644 index 0000000..60daf0f --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.4.html @@ -0,0 +1,5901 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
WF500-5976
+
+
+ (WF-500 appliances only) Fixed an issue where + files were incorrectly detected as malicious. +
+
+
WF500-5953
+
+
+ Fixed an issue where testing the same file sample using a PowerShell + script returned different verdicts in Private Cloud and Public Cloud. +
+
+
WF500-5920
+
+
Fixed an issue where an elink parser did not work.
+
+
+ PAN-231823 +
+
+
+ A fix was made to address + CVE-2024-5916. +
+
+
PAN-220741
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where, when redistribution agent connections to the + passive firewall failed, excessive system alerts for the failed + connection were generated. With this fix, system alerts are logged + every 5 hours instead of 10 minutes. +
+
+
PAN-219686
+
+
+ Fixed an issue where a device group push operation from Panorama + failed with the following error on managed firewalls. +
+
+ vsys -> vsys1 -> plugins unexpected here +
+
+ vsys is invalid +
+
Commit failed
+
+
PAN-216656
+
+
+ Fixed an issue where the firewall was unable to fully process the user + list from a child group when the child group contained more than 1,500 + users. +
+
+
PAN-216314
+
+
+ (PA-3200 Series firewalls only) Fixed an issue + where, after upgrading to or from PAN-OS 10.1.9 or PAN-OS 10.1.9-h1, + offloaded application traffic sessions disconnected even when a + session was active. This occurred due to the application default + session timeout value being exceeded. +
+
+
PAN-215911
+
+
+ Fixed an issue that resulted in a race condition, which caused the + configd + process to stop responding. +
+
+
PAN-215488
+
+
+ Fixed an issue where an expired Trusted Root CA was used to sign the + forward proxy leaf certificate during SSL Decryption. +
+
+
PAN-215461
+
+
+ Fixed an issue where the packet descriptor leaked over time with GRE + tunnels and keepalives. +
+
+
PAN-215125
+
+
+ Fixed an issue where false negatives occurred for some script samples. +
+
+
PAN-214634
+
+
Fixed an issue where an elink parser did not work.
+
+
PAN-214624
+
+
+ Fixed an issue where the + logrcvr + process stopped responding. +
+
+
PAN-214337
+
+
+ Fixed an issue on the firewall related to the + gp_broker configuration transform + that led to longer commit times. +
+
+
PAN-214037
+
+
+ (PA-5440, PA-5430, PA-5420, and PA-5410 firewalls only) Fixed an issue where firewalls in active/active HA configurations + experienced packet drop when running asymmetric traffic. +
+
+
PAN-213973
+
+
+ Fixed an issue where the + authd + process stopped responding during a cleanup of authentication server + context. +
+
+
PAN-213661
+
+
+ Fixed an issue where memory allocation failure caused dataplane + processes to restart. This issue occurred when decryption was enabled + and the device was under heavy L7 usage. +
+
+
PAN-213011
+
+
+ Fixed an issue where, when using multi-factor authentication (MFA) + with RADIUS OTP, the challenge message + Enter Your Microsoft verification code + did not appear when accessing the GlobalProtect portal via browser. +
+
+
PAN-212982
+
+
+ Fixed an issue where the + logrcvr + process stopped responding with MICA HTTP2 traffic. +
+
+
PAN-212409
+
+
+ Fixed an issue where there were duplicate IPSec Security Associations + (SAs) for the same tunnel, gateway, or proxy ID. +
+
+
PAN-211242
+
+
+ Fixed an issue where missed heartbeats caused the Data Processing Card + (DPC) and its corresponding Network Processing Card (NPC) to restart + due to internal packet path monitoring failure. +
+
+
PAN-210919
+
+
+ Fixed an issue where the Data Processing Card remained in a + Starting state after a restart. +
+
+
PAN-210892
+
+
+ (M-600 and M-700 appliances only) Fixed an + issue where the Elasticsearch shard count grew continuously without + limit. +
+
+
PAN-210875
+
+
+ Fixed an issue where the + pan_task + process stopped responding due to software packet buffer 3 trailer + corruption, which caused the firewall to restart. +
+
+
PAN-210561
+
+
+ Fixed an issue where the + all_task + process repeatedly restarted due to missed heartbeats. +
+
+
PAN-210481
+
+
+ Fixed an issue where botnet reports were not generated on the + firewall. +
+
+
PAN-210449
+
+
+ Fixed an issue where the value for shared objects used in policy rules + were not displayed on multi-vsys firewalls when pushed from Panorama. +
+
+
PAN-210331
+
+
+ Fixed an issue where the firewall did not send device telemetry files + to Strata Logging Service with the error + message + Send File to Strata Logging Service Receiver Failed. +
+
+
PAN-210327
+
+
+ (PA-5200 Series firewalls only) Fixed an issue + where upgrading to PAN-OS 10.1.7, an internal loop caused an increase + in the packets received per second. +
+
+
PAN-210237
+
+
+ Fixed an issue where system logs generated by Panorama for commit + operations showed the severity as + High instead of + Informational. +
+
+
PAN-210080
+
+
+ Fixed an issue where the + useridd + process stopped responding when add and delete member parameters in an + incremental sync query were empty. +
+
+
PAN-209660
+
+
+ Fixed an issue where a selective push from Panorama to multiple + firewalls failed due to a missing configuration file, which caused a + communication error. +
+
+
PAN-209346
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.3, HA peers + received conflicting ARP messages that indicated a duplicate IP + address. +
+
+
PAN-209305
+
+
+ Fixed a memory space issue where the content and threat detection + (CTD) process flow cleanup during inline cloud analysis did not work. +
+
+
PAN-209226
+
+
+ Fixed an issue where the feature bits function reused shared memory, + which resulted in a memory allocation error and caused the dataplane + to go down. +
+
+
PAN-209069
+
+
+ Fixed an issue where IP addresses in the + X-Forwarded-For (XFF) field were not + logged when the IP address contained an associated port number. +
+
+
PAN-209021
+
+
+ Fixed an issue where packets were fragmented when SD-WAN VPN tunnel + was configured on aggregate ethernet interfaces and sub-interfaces. +
+
+
PAN-208987
+
+
+ (PA-5400 Series only) Fixed an issue where + packets were not transmitted from the firewall if its fragments were + received on different slots. This occurred when aggregate ethernet + (AE) members in an AE interface were placed on a different slot. +
+
+
+ PAN-208922 +
+
+
+ A fix was made to address an issue where an authenticated + administrator was able to commit a specifically created configuration + to read local files and resources from the system (CVE-2023-38046). +
+
+
PAN-208930
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where auto-tagging in log forwarding did not work. +
+
+
PAN-208877
+
+
+ Fixed an issue where the + all_task + process stopped responding when freeing the HTTP2 stream, which caused + the dataplane to go down. +
+
+
PAN-208737
+
+
+ Fixed an issue where domain information wasn't populated in IP + address-to-username matching after a successful GlobalProtect + authentication using an authentication override cookie. +
+
+
PAN-208724
+
+
+ Fixed an issue where port pause frame settings did not work as + expected and incorrect pause frames occurred. +
+
+
PAN-208718
+
+
+ Additional debug information was added to capture internal details + during traffic congestion. +
+
+
PAN-208711
+
+
+ (PA-5200 Series firewalls only) The CLI command + debug dataplane set pow no-desched yes/no + was added to address an issue where the + all_pktproc + process stopped responding and caused traffic issues. +
+
+
PAN-208537
+
+
+ Fixed an issue where the + licensed-device-capacity was + reduced when multiple device management license key files were + present. +
+
+
PAN-208485
+
+
+ Fixed an issue where NAT policies were not visible on the CLI if they + contained more than 32 characters. +
+
+
PAN-208189
+
+
+ Fixed an issue when traffic failed to match and reach all destinations + if a Security policy rule includes FQDN objects that resolve to two or + more IP addresses. +
+
+
PAN-208157
+
+
+ Fixed an issue where malformed hints sent from the firewall caused the + logd + process to stop responding on Panorama, which caused a system reboot + into maintenance mode. +
+
+
PAN-208079
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the PAN-DB engine did not start when using a + VM-Series firewall Flex based CPU. +
+
+
PAN-207983
+
+
+ Fixed an issue on Panorama in Management Only mode where the logdb + database incorrectly collected traffic, threat, GTP, decryption, and + corresponding summary logs. +
+
+
PAN-207940
+
+
+ Fixed an issue where platforms with RAID disk checks were performed + weekly, which caused logs to incorrectly state that RAID was + rebuilding. +
+
+
PAN-207891
+
+
+ Fixed an issue on Panorama where log migration did not complete after + an upgrade. +
+
+
PAN-207740
+
+
+ Fixed an issue that resulted in a race condition, which caused the + configd + process to stop responding. +
+
+
PAN-207738
+
+
+ Fixed an issue where the + ocsp-next-update-time CLI command + did not execute for leaf certificates with certificate chains that did + not specify OCSP or CRL URLs. As a result, the next update time was 60 + minutes even if a different time was set. +
+
+
PAN-207663
+
+
+ Fixed a Clientless VPN issue where JSON stringify caused issues with + the application rewrite. +
+
+
PAN-207629
+
+
+ Fixed an issue where a selective push to firewalls failed if the + firewalls were enabled with multiple vsys and the push scope contained + shared objects in device groups. +
+
+
PAN-207623
+
+
+ Fixed an issue on Panorama where log migration did not complete as + expected. +
+
+
PAN-207610
+
+
+ (PA-5200 Series and PA-7000 Series firewalls only) Fixed an issue where + Log Admin Activity was not visible + on the web interface. +
+
+
PAN-207602
+
+
+ Fixed an issue where file streams were opened or closed twice due to a + race condition which caused Linux to stop responding. +
+
+
PAN-207601
+
+
+ Fixed an issue where URL cloud connections were unable to resolve the + proxy server hostname. +
+
+
PAN-207533
+
+
+ Fixed an issue with firewalls in HA configurations where ARP and IPv6 + multicast packets were transmitted from the passive firewall. +
+
+
PAN-207455
+
+
+ Fixed an issue where the + pan_task + process stopped responding when processing client certificate requests + from the server in TLS1.3. +
+
+
PAN-207426
+
+
+ Fixed an issue where a selective push did not include the + Share Unused Address and Service Objects with Devices + option on Panorama, which caused the firewall to not receive the + objects during the configuration push. +
+
+
PAN-207400
+
+
+ Fixed an issue on Octeon based platforms where fragmented VLAN tagged + packets dropped on an aggregate interface. +
+
+
PAN-207390
+
+
+ Fixed an issue where, even after disabling Telemetry, Telemetry system + logs were still generated. +
+
+
PAN-207260
+
+
+ A commit option was enabled for Device Group and Template + administrators after a password change. +
+
+
PAN-207045
+
+
+ (PA-800 Series firewalls only) Fixed an issue + where PAN-SFP-SX transceivers used on ports 5 to 8 did not renegotiate + with peer ports after a reload. +
+
+
PAN-207043
+
+
+ Fixed an issue on PAN-OS 10.2.3 where ports 41-44 remained down when + the PAN-QSFP28-DAC-5M cable was connected. +
+
+
PAN-206963
+
+
+ (M-700 Appliances only) A CLI command was added + to check the status of each physical port of a bond1 interface. +
+
+
PAN-206921
+
+
+ Fixed an issue where GlobalProtect client certificate authentication + failed on a gateway when the gateway was placed behind a NAT. +
+
+
PAN-206858
+
+
+ Fixed an issue where a segmentation fault occurred due to the + useridd + process being restarted. +
+
+
PAN-206796
+
+
+ Fixed an issue where + cfg.lcaas-region was not reset + when it was empty, which caused + Strata Logging Service onboarding to fail. +
+
+
PAN-206755
+
+
+ Fixed an issue when a scheduled multi-device group push occurred, the + configd + process stopped responding, which caused the push to fail. +
+
+
PAN-206658
+
+
+ Fixed a timeout issue in the Intel + ixgbe driver that resulted in + internal path monitoring failure. +
+
+
PAN-206629
+
+
+ (VM-Series firewalls in AWS environments only) + Fixed an issue where a newly bootstrapped firewalls did not forward + logs to Panorama. +
+
+
PAN-206393
+
+
+ (PA-5280 firewalls only) Fixed an issue where + memory allocation errors caused decryption failures that disrupted + traffic with SSL forward proxy enabled. +
+
+
PAN-206382
+
+
+ Fixed an issue where authentication sequences were not populated in + the drop down when selecting authentication profiles during + administrator creation in a template. +
+
+
PAN-206253
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the default log rate value was too low, and the maximum + configurable log rate was capped incorrectly, which caused the + firewall to not generate more than 6826 logs per second. +
+
+
PAN-206251
+
+
+ (PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only) Fixed an issue where the + logrcvr + process did not send the + system-start SNMP trap during + startup. +
+
+
PAN-206233
+
+
+ Fixed an issue where the + pan_comm + process stopped responding when a content update and a cloud + application update occurred at the same time. +
+
+
PAN-206128
+
+
+ (PA-7000 Series firewalls with NPCs (Network Processing Cards) + only) Improved debugging capability for an issue where the firewall + restarted due to heartbeat failures and then failed with the following + error message: Power not OK. +
+
+
PAN-206077
+
+
+ Fixed an issue on firewalls in active/active HA configurations where, + after upgrading to PAN-OS 10.1.6-h6, the active primary firewall did + not send HIP reports to the active secondary firewall. +
+
+
PAN-206069
+
+
+ Fixed an issue where the firewall was unable to boot up on older Intel + CPUs. +
+
+
PAN-206017
+
+
+ Fixed an issue where the + show dos-protection rule command + displayed a character limit error. +
+
+
PAN-206005
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the l7_misc memory pool was + undersized and caused connectivity loss when the limit was reached. +
+
+
PAN-205995
+
+
+ Fixed an issue where logs from unaffected log collector groups were + not displayed when a log collector was down. +
+
+
PAN-205955
+
+
+ Fixed an issue where RAID rebuilds occurred even with healthy disks + and a clean shutdown. +
+
+
PAN-205877
+
+
+ (PA-5450 firewalls only) Added debug commands + for an issue where a MAC address flap occurred on a neighbor firewall + when connecting both MGT-A and MGT-B interfaces. +
+
+
PAN-205829
+
+
+ Fixed an issue where logs did not display + Host-ID details for GlobalProtect + users despite having a quarantine Security policy rule. This occurred + due to a missed local cache lookup. +
+
+
PAN-205804
+
+
+ Fixed an issue on Panorama where a WildFire scheduled update for + managed devices triggered multiple + UploadInstall jobs per minute. +
+
+
PAN-205729
+
+
+ (PA-3200 Series and PA-7000 Series firewalls only) Fixed an issue where the CPLD watchdog timeout caused the firewall + to reboot unexpectedly. +
+
+
PAN-205699
+
+
+ Fixed an issue where the cloud plugin configuration was automatically + deleted from Panorama after a reboot or a + configd + process restart. +
+
+
PAN-205590
+
+
+ Fixed an issue where the fan tray fault LED light was on even though + no alarm was reported in the system environment. +
+
+
PAN-205473
+
+
+ (VM-Series firewalls on Microsoft Hyper-V only) + Fixed an issue where the firewall did not receive any traffic on Layer + 3 sub-interfaces from the trunk port. +
+
+
PAN-205453
+
+
+ Fixed an issue where running reports or queries under a user group + caused the + reportd + process to stop responding. +
+
+
PAN-205451
+
+
+ Fixed an issue where the + pan_com + process stopped responding due to aggressive commits. +
+
+
PAN-205428
+
+
+ Fixed an issue where WildFire submissions failed if the file name + contained special characters. +
+
+
PAN-205396
+
+
+ Fixed an issue where SD-WAN adaptive SaaS path monitoring did not work + correctly during a next hop link down failure. +
+
+
PAN-205337
+
+
+ Fixed an issue in the + Run Now section of custom reports + where Threat/Content Name displayed + in hypertext, and hovering over the text with the mouse displayed the + message + undefined. +
+
+
PAN-205260
+
+
+ Fixed an issue where there was an IP address conflict after a reboot + due to a transaction ID collision. +
+
+
PAN-205255
+
+
+ Fixed a rare issue that caused the dataplane to restart unexpectedly. +
+
+
PAN-205231
+
+
+ Fixed an issue where a commit operation remained at 55% for longer + than expected if more than 7,500 Security policy rules were + configured. +
+
+
PAN-205222
+
+
+ Fixed an issue where you were unable to add a new application in a + selected policy rule. +
+
+
PAN-205211
+
+
+ Fixed an issue where the + reportd + process stopped responding while querying logs (Monitor > Logs > <logtype>). +
+
+
PAN-205187
+
+
+ Fixed an issue where Elasticsearch did not start properly when a newly + installed Panorama virtual appliance powered on for the first time, + which caused the Panorama virtual appliance to not query logs + forwarded from the managed firewall to a Log Collector. +
+
+
PAN-205096
+
+
+ Fixed an issue where promoted sessions were not synced with all + cluster members in an HA cluster. +
+
+
PAN-205030
+
+
+ Fixed an issue where, when a session hit policy based forwarding with + symmetric return enabled was not offloaded, the firewall received + excessive return-mac update messages, which resulted in resource + contention and traffic disruption. +
+
+
PAN-204892
+
+
+ Fixed an issue on Panorama where the web interface was not accessible + and displayed the error + 504 Gateway Not Reachable due to + the + mgmtsrvr + process not responding. +
+
+
PAN-204851
+
+
+ Fixed an issue where, when performing an advanced factory reset from + maintenance mode on a firewall running PAN-OS 10.2.2 or an earlier + release and downgrading to PAN-OS 10.1.0 or an earlier release, the + firewall entered into maintenance mode after the reboot. +
+
+
PAN-204838
+
+
+ Fixed an issue where the + dot1q VLAN tag was missing in ARP + reply packets. +
+
+
PAN-204830
+
+
+ Fixed an issue where logging in via the web interface or CLI did not + work until an auto-commit was complete. +
+
+
PAN-204749
+
+
+ Fixed an issue where sudden, large bursts of traffic destined for an + interface that was down caused packet buffers to fill, which stalled + path monitor heartbeat packets. +
+
+
PAN-204690
+
+
+ Fixed an issue where selective configuration pushes failed due to + schema validation when both the device group and template stack had + the same name. +
+
+
PAN-204663
+
+
+ Fixed an issue on Panorama where you were unable to context switch + from one managed firewall to another. +
+
+
PAN-204582
+
+
+ Fixed an issue where, when a firewall acting as a DHCP client received + a new DHCP IP address, the firewall did not release old DHCP IP + addresses from the IP address stack. +
+
+
PAN-204581
+
+
+ Fixed an issue where, when accessing a web application via the + GlobalProtect Clientless VPN, the web application landing page + continuously reloaded. +
+
+
PAN-204575
+
+
+ (PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only) Fixed an issue where the firewall did not forward logs to the log + collector. +
+
+
PAN-204482
+
+
+ Fixed an issue where searching threat logs (Monitor > Logs > Threat) using the + partial hash parameter did not + work, which resulted in an invalid operator error. +
+
+
PAN-204456
+
+
+ Fixed an issue related to the + logd + process that caused high memory consumption. +
+
+
PAN-204335
+
+
+ Fixed an issue where Panorama became unresponsive, and when refreshed, + the error + 504 Gateway not Reachable was + displayed. +
+
+
PAN-204307
+
+
+ (PA-5440, PA-5430, PA-5420 and PA-5410 firewalls only) Fixed an issue where, when moving interfaces from one aggregate + group to another while the interface's link state was down, traffic + was not properly routed through the aggregate group until after a + second commit. +
+
+
PAN-204271
+
+
+ Fixed an issue where the quarantine device list did not display due to + the maximum memory being reached. +
+
+
PAN-204238
+
+
+ Fixed an issue where, when + View Rulebase as Groups was enabled, + the Tags field did not display a + scroll down arrow for navigation. +
+
+
PAN-204216
+
+
+ Fixed an issue where URL categorization failed and the firewall + displayed the URL category as + not-resolved for all traffic and + the following error message was displayed in the device server logs + Error(43): A libcurl function was given a bad argument. +
+
+
PAN-204118
+
+
+ Fixed an issue where browser sessions stopped responding for device + group template admin users with access domains that had many device + groups or templates. +
+
+
PAN-204068
+
+
+ Fixed an issue where a newly created vsys (virtual system) in a + template was not able to be pushed from Panorama to the firewall. +
+
+
PAN-203964
+
+
+ (Firewalls in FIPS-CC mode only) Fixed an issue + where the firewall went into maintenance mode due to downloading a + corrupted software image, which resulted in the error message + FIPS-CC failure. Image File Authentication Error. +
+
+
PAN-203851
+
+
+ Fixed an issue with firewalls in HA configurations where host + information profile (HIP) sync did not work between peer firewalls. +
+
+
PAN-203796
+
+
+ Fixed an issue where legitimate syn+ack packets were dropped after an + invalid syn+ack packet was ingressed. +
+
+
PAN-203681
+
+
+ (Panorama appliances in FIPS-CC mode only) + Fixed an issue where a leaf certificate was unable to be imported into + a template stack. +
+
+
PAN-203663
+
+
+ Fixed an issue where administrators were unable to change the password + of a local database for users configured as a local admin user via an + authentication profile. +
+
+
PAN-203653
+
+
+ Fixed an issue where dynamic updates were completed even when + configuration commits failed, which caused the + all_task + process to stop responding. +
+
+
PAN-203618
+
+
+ Fixed an issue where, when SSL/TLS Handshake Inspection was enabled, + SSL/TLS sessions were incorrectly reset if a Security policy rule with + no Security profiles configured was matched. +
+
+
PAN-203604
+
+
+ Fixed an issue where GlobalProtect authentication failed for SAML + username with a special character. +
+
+
PAN-203563
+
+
+ Fixed an issue with Content and Threat Detection allocation storage + space where performing a commit failed with a + CUSTOM_UPDATE_BLOCK error + message. +
+
+
PAN-203430
+
+
+ Fixed an issue where, when the User-ID agent had + collector name/secret configured, + the configuration was mandatory on clients on PAN-OS 10.0 and later + releases. +
+
+
PAN-203402
+
+
+ Fixed an intermittent issue where forward session installs were + delayed, which resulted in latencies. +
+
+
PAN-203362
+
+
+ Fixed an issue where the + rasmgr + process restarted due to a null reference. +
+
+
PAN-203339
+
+
+ Fixed an issue where services failed due to the RAID rebuild not being + completed on time. +
+
+
PAN-203330
+
+
+ Fixed an issue where the certificate for an External Dynamic List + (EDL) incorrectly changed from invalid to valid, which caused the EDL + file to be removed. +
+
+
PAN-203320
+
+
+ Fixed an issue where configuring the firewall to connect with Panorama + using an auth key and creating the auth key without adding the managed + firewall to Panorama first, the auth key was incorrectly decreased + incrementally. +
+
+
PAN-203147
+
+
+ (Firewalls in FIPS-CC mode only) Fixed an issue + where the firewall unexpectedly rebooted when downloading a new PAN-OS + software image. +
+
+
PAN-203137
+
+
+ (PA-5450 firewalls only) Fixed an issue where + HSCI ports did not come up when QSFP DAC cables were used. +
+
+
PAN-202946
+
+
+ Fixed an issue where the + request high-availability session-reestablish + command was not available for API. +
+
+
PAN-202918
+
+
+ Fixed an issue where processing route-table entries did not work as + expected. +
+
+
PAN-202872
+
+
+ Fixed an issue where an incorrect URL list limit displayed during a + commit. +
+
+
PAN-202783
+
+
+ (PA-7000 Series firewalls with 100G NPC (Network Processing Cards) + only) Fixed an issue where sudden, large bursts of traffic destined for + an interface that was down caused packet buffers to fill, which + stalled path monitor heartbeat packets. +
+
+
PAN-202722
+
+
+ Fixed an issue where the factor completion time for login events + learned through XML API displayed as + 1969/12/31 19:00:00. +
+
+
PAN-202593
+
+
+ Fixed an issue where expanding Global Find results displayed only the + top level and second level of a searched item. +
+
+
PAN-202544
+
+
+ An enhancement was made to collect CPLD register data after a path + monitor failure. +
+
+
PAN-202543
+
+
+ An enhancement was made to improve path monitor data collection by + verifying the status of the control network. +
+
+
PAN-202535
+
+
+ Fixed an issue where the Device Telemetry configuration for a region + was unable to be set or edited via the web interface. +
+
+
PAN-202451
+
+
+ Fixed an issue where + Retrieve Framed-IP-Address attribute + from the authentication server fails generating GlobalProtect + connection failure with the error + Assign private IP address failed. +
+
+
PAN-202450
+
+
+ Fixed an issue where the + device-client-cert was set to + expire on December 31, 2023. With this fix, the expiration date has + been extended. +
+
+
PAN-202295
+
+
+ Fixed an issue where read-only superusers were unable to see the + Commit All job status, warnings, or errors for Panorama device groups. +
+
+
PAN-202282
+
+
+ Fixed an issue where stats dump files did not display all necessary + reports. +
+
+
PAN-202264
+
+
+ (VM-Series firewalls only) Fixed an issue where + an automatic site license activation for a PAYG license did not + register in the Customer Support Portal. +
+
+
PAN-202248
+
+
+ Fixed an issue where, due to a tunnel content inspection (TCI) policy + match, IPSec traffic did not pass through the firewall when NAT was + performed on the traffic. +
+
+
PAN-202194
+
+
+ Fixed an SD-WAN link issue that occurred when Aggregate Ethernet + without a member interface was configured as an SD-WAN interface. +
+
+
PAN-202140
+
+
+ Fixed an issue where the + comm + process stopped responding due to an OOM condition. +
+
+
PAN-202101
+
+
+ Fixed an issue where firewalls stopped responding after an upgrade due + to configuration corruption. +
+
+
PAN-202095
+
+
+ Fixed an issue on the web interface where the language setting is not + retained. +
+
+
PAN-202040
+
+
+ (PA-220 firewalls only) Fixed an issue where + ECDSA fingerprints were not displayed. +
+
+
PAN-202012
+
+
+ A debug command was introduced to control Gzip encoding for the + GlobalProtect Clientless VPN application. +
+
+
PAN-201973
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the management interface could not be assigned as an HA port. +
+
+
PAN-201954
+
+
+ Fixed an issue where NAT policy rules were deleted on managed devices + after a successful push from Panorama to multiple device groups. This + occurred when NAT policy rules had + device_tags selected in the target + section. +
+
+
PAN-201910
+
+
+ Fixed an issue where some Security profiles consumed a large amount of + memory, which reduced the number of supported Security profiles below + the stated maximum for a platform. +
+
+
PAN-201900
+
+
+ Fixed an internal path monitoring failure issue that caused the + dataplane to go down. +
+
+
PAN-201860
+
+
+ Fixed an issue where the + Device Quarantine list was not + redistributed or updated on Panorama and Prisma Access in a full mesh + topology. +
+
+
PAN-201858
+
+
+ Fixed an issue where the SD-WAN interface Maximum Transmission Unit + (MTU) led to incorrect fragmentation of IPSec traffic. +
+
+
PAN-201839
+
+
+ Fixed an issue where GlobalProtect HIP match failed for Mac users due + to invalid characters being present in the subject alternative + attributes in the certificate on the HIP report. +
+
+
PAN-201818
+
+
+ Fixed an issue where INIT SCTP packets were dropped after being + processed by the CTD, and silent drops occurred even with SCTP no-drop + function enabled. +
+
+
PAN-201714
+
+
+ Fixed an issue with GlobalProtect where attempting to authenticate + with the GlobalProtect gateway returned a 502 error code. +
+
+
PAN-201701
+
+
+ Fixed an issue where the firewall generated system log alerts if the + raid for a system or log disk was corrupted. +
+
+
PAN-201639
+
+
+ Fixed an issue with Saas Application Usage reports where + Applications with Risky Characteristics + displayed only two applications per section. +
+
+
PAN-201632
+
+
+ Fixed an issue where the + all_task + stopped responding with a segmentation fault due to an invalid + interface port. +
+
+
PAN-201601
+
+
+ Fixed an issue where the + all_task + process stopped responding after adding customer hyperscan signatures. +
+
+
PAN-201587
+
+
+ Fixed an issue where the + App Pcaps directory size was + incorrectly detected which caused commit errors. +
+
+
PAN-201580
+
+
+ Fixed an issue where the + useridd + process stopped responding due to an invalid vsys_id request. +
+
+
PAN-201561
+
+
+ Fixed an issue where LSVPN satellite authentication cookies were not + synced across high availability LSVPN portals. +
+
+
PAN-201360
+
+
+ Fixed an issue with Panorama managed log collector statistics where + the oldest logs displayed on the primary Panorama appliance and the + secondary Panorama appliance did not match. +
+
+
PAN-201357
+
+
+ The CLI command + debug dataplane set pow no-desched yes + was added to address an issue where the + all_pktproc + process stopped responding and caused traffic issues. +
+
+
PAN-201136
+
+
+ Fixed an issue where IGMP packets were offloaded with frequent IGMP + Join and Leave messages from the client. +
+
+
PAN-201085
+
+
+ (PA-5450 firewalls only) Fixed an issue where + inserting the NPC and DPC on slot2 created excessive logs in the + bcm.log file. +
+
+
PAN-200946
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where GRE tunnels went down due to recursive routing when the passive + firewall was booting up. When the passive firewall became active and + no recursive routing was configured, the GRE tunnel remained down. +
+
+
PAN-200914
+
+
+ (PA-3440 firewalls only) Fixed an issue where + the default NAT DIPP pool oversubscription was set to 2 instead of 4. +
+
+
PAN-200845
+
+
+ (M-600 Appliances in Management-only mode only) + Fixed an issue where XML API queries failed due to the configuration + size being larger than expected. +
+
+
PAN-200774
+
+
+ Fixed an issue where SCEP certificate import did not work on the + firewall when the certificate name contained a period ( . ). +
+
+
PAN-200676
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where the user counts in the management plane were not synchronized + between the active and the passive firewall. +
+
+
PAN-200463
+
+
+ Fixed an issue where disabling + strict-username-check did not + apply to admin users authenticating with SAML. +
+
+
PAN-200356
+
+
+ Fixed an issue where the + Elapsed seconds field incorrectly + displayed as 0 for DHCP packets coming from the firewall. +
+
+
PAN-200354
+
+
+ Fixed an issue where the firewall did not initiate scheduled log + reports. +
+
+
PAN-200160
+
+
+ Fixed a memory leak issue on Panorama related to the + logd + process that caused an out-of-memory (OOM) condition. +
+
+
PAN-200116
+
+
+ Fixed an issue where Elasticsearch displayed red due to frequent + tunnel check failures between HA clusters. +
+
+
PAN-200103
+
+
+ Fixed an issue where decryption logs were not displayed under + Manage Custom Reports for custom + Panorama admin users. +
+
+
PAN-200102
+
+
+ Fixed an issue on the firewall web interface that prevented + applications from loading under any policy or in any location where + application IDs were able to be refreshed. +
+
+
PAN-200035
+
+
+ Fixed an issue where the firewall reported + General TLS Protocol Error for + TLSv1.3 when the firewall closed a TCP connection to the server via a + FIN packet without waiting for the handshake to complete. +
+
+
PAN-200019
+
+
+ Fixed an issue on Panorama where + Virtual Routers (Network > Virtual Routers) was not available when configuring a custom Panorama admin role + (Panorama > Admin Roles). +
+
+
PAN-199965
+
+
+ Fixed an issue where the + reportd + process stopped responding on log collectors during query and report + operations due to a race condition between request handling threads. +
+
+
PAN-199821
+
+
+ Fixed an issue where the + Include/Exclude IPs filter under + Data Redistribution did not + consistently filter IP addresses correctly. +
+
+
PAN-199807
+
+
+ Fixed an issue where the dataplane frequently restarted due to high + memory usage on wifclient. +
+
+
PAN-199726
+
+
+ Fixed an issue with firewalls in HA configurations where both + firewalls responded with gARP messages after a switchover. +
+
+
PAN-199661
+
+
+ (VM-Series firewalls in ESXI environments only) + Fixed an issue where the number of used packet buffers was not + calculated properly, and packet buffers displayed as a higher value + than the correct value, which triggered PBP Alerts. This occurred when + the driver name was not compatible with new DPDK versions. +
+
+
PAN-199612
+
+
+ Fixed a sync issue with firewalls in active/active HA configurations. +
+
+
PAN-199570
+
+
+ Fixed an issue where uploading certificates using a custom admin role + did not work as expected after a context switch. +
+
+
PAN-199543
+
+
+ Resolved failed authentication for Radius and TLS where shared secret + was striped for FIPS mode +
+
+
PAN-199500
+
+
+ Fixed an issue where, when many NAT policy rules were configured, the + pan_comm + process stopped responding after a configuration commit due to a high + number of debug messages. +
+
+
PAN-199410
+
+
+ Fixed an issue where system logs for + syslog + activities were categorized as + general under + Type and + EVENT columns. +
+
+
PAN-199214
+
+
+ Fixed an intermittent issue where downloading + threat pcap via XML API failed + with the following error message: + /opt/pancfg/session/pan/user_tmp/XXXXX/YYYYY.pcap does not + exist. +
+
+
PAN-199141
+
+
+ Fixed an issue where renaming a device group and then performing a + partial commit led to the device group hierarchy being incorrectly + changed. +
+
+
PAN-198920
+
+
+ Fixed an issue where configuration changes caused a previously valid + interface ID to become invalid due to HA switchovers delaying the + configuration push. +
+
+
PAN-198889
+
+
+ Fixed an issue where the + logd + process stopped responding if some devices in a collector group were + on a PAN-OS 10.1 device and others were on a PAN-OS 10.0 release. This + issue affected the devices on a PAN-OS 10.0 release. +
+
+
PAN-198871
+
+
+ Fixed an issue when both URL and Advanced URL licenses were installed, + the expiry date was not correctly checked. +
+
+
PAN-198718
+
+
+ (PA-5280 firewalls only) Fixed an issue where + memory allocation failures caused increased decryption failures. +
+
+
PAN-198693
+
+
+ Fixed an issue where decrypted SSH sessions were interrupted with a + decryption error. +
+
+
PAN-198691
+
+
+ Added an alternate health endpoint to direct health probes on the + firewall (https://firewall/unauth/php/health.php) to address an issue + where /php/login.php performance + was slow when large amounts of traffic were being processed. +
+
+
PAN-198575
+
+
+ Fixed an issue where data did not load when filtering by + Threat Name (ACC > Threat Activity). +
+
+
PAN-198333
+
+
+ Fixed an issue where the SaaS PDF report incorrectly displayed the + sanctioned application tag count as 1. +
+
+
PAN-198306
+
+
+ Fixed an issue where the + useridd + process stopped responding when booting up the firewall. +
+
+
PAN-198174
+
+
+ Fixed an issue where, when viewing traffic or threat logs from the + Application Command Center (ACC) or + Monitor tabs, performing a reverse + DNS lookup caused the + dnsproxy + process to restart if DNS server settings were not configured. +
+
+
PAN-198078
+
+
+ Fixed an issue where VXLAN keepalive packets were dropped randomly. +
+
+
PAN-198038
+
+
+ A CLI command was added to address an issue where long-lived sessions + were aging out even when there was ongoing traffic. +
+
+
PAN-197953
+
+
+ Fixed an issue where the + logd + process stopped responding due to forwarded threat logs, which caused + Panorama to reboot into maintenance mode. +
+
+
PAN-197935
+
+
+ Fixed an intermittent issue where XML API IP address tag registration + failed on firewalls in a multi-vsys environment. +
+
+
PAN-197919
+
+
+ Fixed an issue where, when path monitoring for a static route was + configured with a new Ping Interval value, the value was not used as + intended. +
+
+
PAN-197908
+
+
+ Fixed an issue where + Strata Logging Service flaps occurred for long + durations which caused a memory leak related to the + mgmtsrvr process. +
+
+
PAN-197877
+
+
+ Fixed an intermittent issue on Panorama where the + distributord + process stopped responding. +
+
+
PAN-197872
+
+
+ Fixed an issue where the + useridd + process generated false positive critical errors. +
+
+
PAN-197847
+
+
+ Fixed an issue where disabling the + enc-algo-aes-128-gcm cipher did + not work when using an SSL/TLS profile. +
+
+
PAN-197737
+
+
+ Fixed an issue where the connection to the PAN-DB server failed with + following error message: + Failed to send req type[3], curl error: Couldn't resolve host + name. +
+
+
PAN-197729
+
+
+ Fixed an issue where repeated configuration pushes from Panorama + resulted in a management server memory leak. +
+
+
PAN-197678
+
+
+ Fixed an issue where the dataplane stopped responding, which caused + internal path monitoring failure. +
+
+
PAN-197582
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.1.6, the firewall + reset SSL connections that used policy-based forwarding. +
+
+
PAN-197563
+
+
+ Fixed an issue in the User Activity Report where output fields started + with the letter + b. +
+
+
PAN-197549
+
+
+ Fixed an issue where making GlobalProtect gateway configuration + changes resulted in a HIP notification error. +
+
+
PAN-197426
+
+
+ Fixed an issue on Panorama where, when attempting to view the + Monitor page, the error + invalid term was displayed. +
+
+
PAN-197386
+
+
+ Fixed an issue where traffic that was subject to network packet broker + inspection entered a looping state due to incorrect session offload. +
+
+
PAN-197339
+
+
+ Fixed an issue where template configuration for the User-ID agent was + not reflected on the template stack on Panorama appliances on PAN-OS + 10.2.1. +
+
+
PAN-197298
+
+
+ Fixed an issue where the audit comment archive for Security rule + changes output had overlapping formats. +
+
+
PAN-197203
+
+
+ Fixed an intermittent issue where, if SSL/TLS Handshake Inspection was + enabled, multiple processes stopped responding when the firewall was + processing packets. +
+
+
PAN-197121
+
+
+ Fixed an issue where incorrect user details were displayed under the + USER DETAIL drop-down (ACC > Network activity > User activity). +
+
+
PAN-197115
+
+
+ Fixed an issue where, when the total number of in-used HIP profiles + was greater than 32, traffic from the GlobalProtect Agent did not hit + the expected Security policy rule configured with the HIP profile even + though a HIP match log was generated. +
+
+
PAN-197097
+
+
+ Fixed an issue where LSVPN did not support IPv6 addresses on the + satellite firewall. +
+
+
PAN-196954
+
+
+ Fixed a memory leak issue related to the + distributord + process. +
+
+
PAN-196874
+
+
+ Fixed an issue where, when the firewall accepted ICMP redirect + messages on the management interface, the firewall did not clear the + route from the cache. +
+
+
PAN-196840
+
+
+ Fixed an issue where exporting a Security policy rule that contained + Korean language characters to CSV format resulted in the policy + description being in a non-readable format. +
+
+
PAN-196811
+
+
+ Fixed an issue where logout events without a username caused high CPU + usage. +
+
+
PAN-196715
+
+
+ Fixed an issue where you could not directly edit + Services and + Address objects from the + Policies tab. +
+
+
PAN-196704
+
+
+ Fixed an issue where + Preview Changes on Panorama Push to Devices + incorrectly displayed changes to encrypted entries. +
+
+
PAN-196701
+
+
+ Fixed an issue where the firewall did not properly measure the + Panorama connection keepalive timer, which caused a Panorama HA + failover to take longer than expected. +
+
+
PAN-196671
+
+
+ (PA-3400 Series firewalls and PA-5410, PA-5420, and PA-5430 + firewalls only) Addressed an issue to improve network latency, +
+
+
PAN-196583
+
+
+ Fixed an issue where the Cisco TrustSEc plugin triggered a flood of + redundant register/unregister messages due to a failed IP address tag + database search. +
+
+
PAN-196566
+
+
+ Fixed an issue where the + useridd + process restarted repeatedly which let to an OOM condition. +
+
+
PAN-196558
+
+
+ Fixed an issue where IP address tag policy updates were delayed. +
+
+
PAN-196474
+
+
+ Fixed an issue where, when a decryption profile was configured with + TLSv1.2 or later, web pages utilizing TLS1.0 were blocked with an + incorrect ERR_TIME_OUT message + instead of an + ERR_CONNECTION_RESET message. +
+
+
PAN-196467
+
+
+ Fixed an issue where enabling strict IP address checks in a Zone + Protection profile caused GRE tunnel packets to be dropped. +
+
+
PAN-196457
+
+
+ Fixed an issue where extraneous logs displayed in the Traffic log when + Security policy settings were changed. +
+
+
PAN-196452
+
+
+ Fixed an issue where DNS queries failed from source port 4789 with a + NAT configuration. +
+
+
PAN-196450
+
+
+ Fixed an issue where certificates with whitespaces in the name or + common name (CN) were not able to be imported. +
+
+
PAN-196410
+
+
+ Fixed an issue where you were unable to customize the risk value in + Risk-of-app. +
+
+
PAN-196309
+
+
+ (PA-5450 firewalls only) Fixed an issue where a + firewall configured with a Policy-Based Forwarding policy flapped when + a commit was performed, even when the next hop was reachable. +
+
+
PAN-196131
+
+
+ Fixed an issue where the + comm + process stopped responding when a show command was executed in two + sessions. +
+
+
PAN-196105
+
+
+ Fixed an issue on the firewall where using special characters in a + password caused authentication to fail when connecting to the + GlobalProtect portal with GlobalProtect satellite configured. +
+
+
PAN-196050
+
+
+ Fixed an issue on Panorama where logs did not populate when one log + collector in a log collector group was down. +
+
+
PAN-196003
+
+
+ Fixed an issue where the + Adjust Columns options for Panorama + traffic logs did not correctly auto-adjust the columns. +
+
+
PAN-195988
+
+
+ Fixed an issue where commits failed when an AS path regular expression + that included the ( _ ) character was specified in the virtual router + BGP configuration export rule. +
+
+
PAN-195893
+
+
+ Fixed an issue where daily PDF summary reports were not generated when + the Application Report was selected. +
+
+
PAN-195869
+
+
+ Fixed an issue where scheduled custom reports based on firewall data + did not display any information. +
+
+
PAN-195828
+
+
+ Fixed an issue where SNMP reported the + panVsysActiveTcpCps and + panVsysActiveUdpCps value to be + 0. +
+
+
PAN-195792
+
+
+ Fixed an issue where, when generating a stats dump file for a managed + device from Panorama (Panorama > Support > Stats Dump File), the file did not display any data. +
+
+
PAN-195790
+
+
+ Fixed an issue where syslog traffic that was sent from the management + interface to the syslog server even when a destination IP address + service route was configured. +
+
+
PAN-195713
+
+
+ Fixed an issue where clientless VPN applications were not displayed in + the GlobalProtect portal page. +
+
+
PAN-195695
+
+
+ Fixed an issue where the AppScope Summary report and PDF report export + function did not work as expected. +
+
+
PAN-195669
+
+
+ Fixed an issue with Panorama appliances in HA configurations where a + passive Panorama appliance generated + CMS Redistribution Client is connected to global collector + messages. +
+
+
PAN-195659
+
+
+ Fixed an issue with firewalls in HA configurations where ping + responses from the target IP addresses were much delayed after a + configuration push. +
+
+
PAN-195583
+
+
+ Fixed an issue where, after renaming an object, configuration pushes + from Panorama failed with the commit error + object name is not an allowed keyword. +
+
+
PAN-195526
+
+
+ Fixed an issue where the firewall system log received a large amount + of error messages when attempting a connection between the firewall + and Panorama. +
+
+
PAN-195374
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where, when redistribution agent connections to the + passive firewall failed, excessive system alerts for the failed + connection were generated. With this fix, system alerts are logged + every 5 hours instead of 10 minutes. +
+
+
PAN-195201
+
+
+ Fixed an issue where high volume DNS Security traffic caused the + firewall to reboot. +
+
+
PAN-195200
+
+
+ Fixed an issue where Panorama did not attach and email scheduled + reports (Monitor > PDF > Reports > Email Scheduler) when the size of the email attachments was large. +
+
+
PAN-195114
+
+
+ Fixed an issue where proxy ARP responded on the wrong interface when + the same subnet was in two virtual routers. +
+
+
PAN-195107
+
+
+ (PA-7000s Series firewalls with LFCs only) + Fixed an issue where the IP address of the LFC displayed as + unknown. +
+
+
PAN-195064
+
+
+ Fixed an issue where the log collector did not forward correlation + logs to the syslog server. +
+
+
PAN-194912
+
+
+ Fixed an issue where the CLI command + show applications list did not + return any outputs. +
+
+
PAN-194812
+
+
+ Fixed an issue where generating reports via XML API failed when the + serial number was set as + target in the query. +
+
+
PAN-194805
+
+
+ Fixed an issue where scheduled configuration backups to the SCP server + failed with error message + No ECDSA host key is known. +
+
+
PAN-194737
+
+
+ Fixed an issue where path monitor displayed as deleted when it was + disabled, which caused a preview change in the summary for static + routes. +
+
+
PAN-194704
+
+
+ Fixed an issue with SIP ALG where improper NAT was applied when + Destination NAT ran out of IP addresses. +
+
+
PAN-194615
+
+
+ Fixed an issue where the packet broker session timeout value did not + match the master sessions timeout value after the firewall received a + TCP FIN or RST packet. The fix ensures that Broker session times out + within 1 second after the master session timed out. +
+
+
PAN-194441
+
+
+ Fixed an issue where the dataplane CPU usage was higher than expected + due to packet looping in the broker session when the network packet + broker was enabled. +
+
+
PAN-194175
+
+
+ Fixed an issue on Panorama where a commit push to managed firewalls + failed when objects were added as source address exclusions in a + Security policy and + Share Unused Address and Service Objects with Devices + was unchecked. +
+
+
PAN-194068
+
+
+ (PA-5200 Series firewalls only) Fixed an issue + where the firewall unexpectedly rebooted with the log message + Heartbeat failed previously. +
+
+
PAN-194043
+
+
+ Fixed an issue where + Managed Devices > Summary did not + reflect new tag values after an update. +
+
+
PAN-194031
+
+
+ (PA-220 Firewalls only) Fixed an issue where + system log configurations did not work as expected due to insufficient + process timeout after a + logrcvr + process restart. +
+
+
PAN-194025
+
+
+ Fixed an issue where the + ikemgr + process stopped responding due to a timing issue, which caused VPN + tunnels to go down. +
+
+
PAN-193879
+
+
+ Fixed an issue on Panorama where the push scope was delayed for commit + and push operations. +
+
+
PAN-193831
+
+
+ Fixed an issue where internal routes were added to the routing table + even after disabling dynamic routing protocols. +
+
+
PAN-193808
+
+
+ Fixed a memory leak issue in the + mgmtsrvr + process that resulted in an OOM condition. +
+
+
PAN-193733
+
+
+ (Firewalls in multi-vsys environments only) + Fixed an issue where IP tag addresses were not synced to all virtual + systems (vsys) when they were pushed to the firewall from Panorama via + XML API. +
+
+
PAN-193619
+
+
+ Fixed an issue where air gapped firewalls and Panorama appliances + performed excessive validity checks to updates.paloaltonetworks.com, + which caused software installs to fail. +
+
+
PAN-193558
+
+
+ Fixed an issue where log retention settings + Multi Disk did not display correct + values on the firewall web interface when the settings were configured + using a Panorama template or template stack. +
+
+
PAN-193396
+
+
+ Fixed an issue where the source user name was displayed in traffic + logs even when + Show User Names In Logs and Reports + was disabled for a custom admin role. +
+
+
PAN-193323
+
+
+ Fixed an issue where root partition utilization reached 100% due to + mdb old logs not being purged as expected. +
+
+
PAN-193281
+
+
+ Fixed an issue where the + logrcvr + process stopped responding after a content update on the firewall. +
+
+
PAN-193245
+
+
+ Fixed an issue where, when using + syslog-ng forwarding via SSL, + with a Base Common Name (CN) and multiple Subject Alternative Names + (SANs) were listed in the certificate. +
+
+
PAN-193175
+
+
+ Fixed an issue where + PBP Drops (8507) threat logs were + incorrectly logged as + SCTP Init Flood (8506). +
+
+
PAN-193043
+
+
+ Fixed an issue with the where firewalls in Google Cloud Platforms + (GCP) inserted the hostname as + PA-VM in the syslog header + instead of the DHCP assigned hostname when logs were being sent to the + syslog server. +
+
+
PAN-193026
+
+
+ Fixed an issue where warning messages were generated during commits + when configuration details of two profiles were identical. +
+
+
PAN-192681
+
+
+ Fixed an issue where HIP database storage on the firewall reached full + capacity due to the firewall not purging older HIP reports. +
+
+
PAN-192513
+
+
+ Fixed an issue where log migration did not work when converting a + Legacy mode Panorama appliance to Log Collector mode. +
+
+
PAN-192456
+
+
+ Fixed an issue where GlobalProtect SSL VPN processing during a high + traffic load caused the dataplane to stop responding. +
+
+
PAN-192417
+
+
+ Fixed an issue where botnet reports were not generated on the + firewall. +
+
+
PAN-192296
+
+
+ Fixed an issue where, when you saved a SaaS application report as a + PDF or sent it to print, the size of the report was smaller than + expected. +
+
+
PAN-192244
+
+
+ Fixed an issue where scheduled log export jobs continued to run even + after being deleted. +
+
+
PAN-192193
+
+
+ Fixed an issue where exporting a list of managed collectors via the + Panorama web interface failed with the following error message: + Export Error, Error while exporting +
+
+
PAN-192188
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the + show running resource-monitor ingress-backlogs + CLI command failed with the following error message: + Server error : Failed to intepret the DP response. +
+
+
PAN-192092
+
+
+ Fixed an issue with firewalls in active/passive configurations only + where the registered cookie from the satellite firewall to the passive + firewall did not sync, which caused authentication between the + satellite firewall and the GlobalProtect portal firewall to fail after + a failover event. +
+
+
PAN-192076
+
+
+ Added debug logs for visibility into an OpenSSL memory initialization + issue that caused unexpected failovers. +
+
+
PAN-191997
+
+
+ Fixed an issue where log queries did not successfully filter the + unknown category. +
+
+
PAN-191652
+
+
+ Fixed an issue with Prisma Cloud where a commit push failed due to the + error + Error: failed to handle TDB_UPDATE_BLOCK. +
+
+
PAN-191463
+
+
+ Fixed an issue where the firewall did not handle packets at Fastpath + when the interface pointer was null. +
+
+
PAN-191408
+
+
+ Fixed an issue where the firewall did not correctly receive dynamic + address group information from Panorama after a reboot or initial + connection. +
+
+
PAN-191390
+
+
+ (VM-Series firewalls only) Fixed an issue where + the management plane CPU was incorrectly calculated as high when + logged in the mp-monitor.log. +
+
+
PAN-191352
+
+
+ Fixed an intermittent issue where high latency was observed on the web + interface and CLI due to high CPU usage related to the + sadc + process. +
+
+
PAN-191235
+
+
+ Fixed an issue with firewalls in HA configurations where the passive + firewall attempted to connect to a hardware security module (HSM) + client when a service route was configured, which caused dynamic + updates and software updates to fail. +
+
+
PAN-191032
+
+
+ Fixed an issue on Panorama where + Managed Devices displayed + Unknown. +
+
+
PAN-190533
+
+
+ Fixed an issue where addresses and address groups were not displayed + for users in Security admin roles. +
+
+
PAN-190502
+
+
+ Fixed an issue where the Policy filter and Policy optimizer filter + were required to have the exact same syntax, including nested + conditions with rules that contained more than one tag when filtering + via the neq operator. +
+
+
PAN-190454
+
+
+ Fixed an issue where, while authenticating, the allow list check + failed for vsys users when a SAML authentication profile was + configured under shared location. +
+
+
PAN-190409
+
+
+ (PA-5450 and PA-3200 Series firewalls that use an FE101 processor + only) Fixed an issue where packets in the same session were forwarded + through a different member of an aggregate ethernet group when the + session was offloaded. The fix is that you can use the following CLI + command to change the default tag setting to the tuple setting: +
+
+ admin@firewall> set session lag-flow-key-type ? +
+
> tag tag
+
+ > tuple tuple +
+
+ tag is the default behavior (tag + based on the CPU, tuple based on the FE). +
+
+ tuple is the new behavior, where + both CPU and FE use the same selection algorithm. +
+
Use the following command to display the algorithm:
+
+ admin@firewall> show session lag-flow-key-type +
+
+ dp0: tuple based on fe100 +
+
+ dp1: tuple based on fe100 +
+
+
PAN-190266
+
+
+ Fixed an issue that stopped the + all_task + process to stop responding at the + pan_sdwan_qualify_if_ini + function. +
+
+
PAN-189960
+
+
+ Fixed an issue on Panorama where you were unable to view the last + address object moved to the shared template list. +
+
+
PAN-189866
+
+
+ Fixed an issue with the web interface where group include lists used + server profiles instead of LDAP proxy. +
+
+
PAN-189783
+
+
+ Fixed an issue where container resource limits were not enforced for + all processes when running inside a container. +
+
+
PAN-189719
+
+
+ Fixed an issue on Panorama where + Test Server Connection failed in an + HTTP server profile with the following error message: + failed binding local connection end. +
+
+
PAN-189718
+
+
+ Fixed an issue where the number of sessions did not reach the expected + maximum value with Security profiles. +
+
+
PAN-189666
+
+
+ Fixed an issue where GlobalProtect portal connections failed after + random commits when multiple agent configurations were provisioned and + configuration selection criteria using certificate profile was used. +
+
+
PAN-189643
+
+
+ Fixed an issue where, when QoS was enabled on an IPSec tunnel, traffic + failed due to applying the wrong tunnel QoS ID. +
+
+
PAN-189518
+
+
+ Fixed an issue where incoming DNS packets with looped compression + pointers caused the + dnsproxyd + process to stop responding. +
+
+
PAN-189425
+
+
+ Fixed an issue on Panorama where + Export Panorama and devices config bundle + (Panorama > Setup > Operations) failed with the following error message: + Failed to redirect error to /var/log/pan/appweb3-panmodule.log + (Permission denied). +
+
+
PAN-189379
+
+
+ Fixed an issue where FQDN based Security policy rules did not match + correctly. +
+
+
PAN-189375
+
+
+ Fixed an issue where, when migrating the firewall, the firewall + dropped packets when trying to re-use the TCP session. +
+
+
PAN-189335
+
+
+ Fixed an issue where the + varrcvr + process restarted repeatedly, which caused the firewall to restart. +
+
+
PAN-189300
+
+
+ Fixed an issue where Panorama appliances in active/passive HA + configurations reported the false positive system log + Failed to sync vm-auth-key when a + VM authentication key was generated on the active appliance. +
+
+
PAN-189200
+
+
+ Fixed an issue where sinkholes did not occur for AWS Gateway Load + Balancer dig queries. +
+
+
PAN-189027
+
+
+ Fixed an issue where the dataplane CPU utilization provided from the + web interface or via SNMP was incorrect. +
+
+
PAN-188933
+
+
+ Fixed an issue where the UDP checksum wasn't correctly calculated for + VXLAN traffic after applying NAT. +
+
+
PAN-188912
+
+
+ Fixed an issue where authentication failed due to a process + responsible for handling authentication requests going into an + irrecoverable state. +
+
+
PAN-188519
+
+
+ (VM-Series firewalls only) Fixed an issue + where, when manually deactivating the license, the admin user did not + receive the option to download the token file and upload it to the + Customer Support Portal (CSP) to deactivate the license. +
+
+
PAN-188904
+
+
+ Fixed an issue where web pages and web page contents were not properly + loaded when cloud inline categorization was enabled. +
+
+
PAN-188506
+
+
+ Fixed an issue where the + ctd_dns_malicious_fwd counter + incorrectly increased incrementally. +
+
+
PAN-188403
+
+
+ Fixed an issue on the web interface where the interzone-default rule + hit count was not displayed. +
+
+
PAN-188348
+
+
+ Fixed an issue where encapsulating Security payload packets + originating from the firewall were dropped when strict IP address + check was enabled in a zone protection profile. +
+
+
PAN-188291
+
+
+ Fixed an issue where, when using Global Find on the web interface to + search for a given + Hostname Configuration (Device > Setup > Management), clicking the search result directed you to the appropriate Hostname + configuration, but did not change the respective + Template field automatically. +
+
+
PAN-188272
+
+
+ (PA-5200 Series and PA-7000 Series firewalls only) Fixed an issue where + Support UTF-8 For Log Output wasn't + visible on the web interface. +
+
+
PAN-188118
+
+
+ Fixed an issue with firewalls in FIPS mode that prevented device + telemetry from connecting. +
+
+
PAN-187763
+
+
+ Fixed an issue where DNS Security logs did not display a threat + category, threat name, or threat ID when domain names contained 64 or + more characters. +
+
+
PAN-187438
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where HSCI interfaces didn’t come up when using BiDi transceivers. +
+
+
PAN-187279
+
+
+ Fixed an issue where not all quarantined devices were displayed as + expected. +
+
+
PAN-186530
+
+
+ Fixed an issue where the current date was incorrectly printed as the + last license check date. +
+
+
PAN-186471
+
+
+ Fixed an issue where, when exporting to CSV in Global Find, the + firewall truncated names of rules that contained over 40 characters. +
+
+
PAN-186412
+
+
+ Fixed an issue where invalid + packet-ptr was seen in work + entries. +
+
+
PAN-186294
+
+
+ Fixed an issue where commits from Panorama failed on the firewall due + to the virtual router name character limit. +
+
+
PAN-186270
+
+
+ Fixed an issue where, when HA was enabled and a dynamic update + schedule was configured, the + configd + process unexpectedly stopped responding during configuration commits. +
+
+
PAN-185770
+
+
+ Fixed an issue where the firewall displayed the error message + Malformed Request when an email + address included an ampersand ( & ) when configuring an email + server profile. +
+
+
PAN-185466
+
+
+ Fixed an issue where WildFire submission did not work as expected. +
+
+
PAN-185394
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where not all changes to the template were reflected on the firewall. +
+
+
PAN-185360
+
+
+ Fixed an issue where, when Captive Portal Authentication was + configured, + l3svc_ngx_error.log and + l3svc_access.log did not roll + over after exceeding 10 megabytes, which caused the root partition to + reach full utilization. +
+
+
PAN-185287
+
+
+ (PA-7050 firewalls with Network Processing Cards (NPCs) only) Debug commands were added to address an issue where the firewall's + NPC Slot2 failed and multiple dataplane processes stopped responding. +
+
+
PAN-185234
+
+
+ (VM-Series firewalls only) Fixed an issue where + the packet buffer utilization was displayed as high even when no + traffic was traversing the firewall. +
+
+
PAN-184744
+
+
+ Fixed an issue where the firewall did not decrypt SSL traffic due to a + lack of internal resources allocated for decryption. +
+
+
PAN-184708
+
+
+ Fixed an issue where scheduled report emails (Monitor>PDF Reports>Email Scheduler) were not emailed as expected if they included a SaaS Application + Usage report. +
+
+
PAN-183524
+
+
+ Fixed an issue where GTPv2-c and GTP-U traffic was identified with + insufficient-data in the traffic + logs. +
+
+
PAN-183375
+
+
+ Fixed an issue where traffic arriving on a tunnel with a bad IP + address header checksum was not dropped. +
+
+
PAN-183126
+
+
+ Fixed an issue on Panorama where you were able to attempt to push a + number of active schedules to the firewall that was greater than the + firewall's maximum capacity. +
+
+
PAN-182875
+
+
+ Fixed an issue where certificate generation using SCEP did not take + more than one organizational unit (OU). +
+
+
PAN-182732
+
+
+ Fixed an issue where the GlobalProtect gateway inactivity timer wasn't + refreshed even though traffic was passing through the tunnel. +
+
+
PAN-182167
+
+
+ Removed a duplicate save filter Icon in the Audit Comment Archive for + Security Rule Audit Comments tab. +
+
+
PAN-181968
+
+
+ (PA-400 Series firewalls in active/passive HA configurations + only) Fixed an issue where, when HA failover occurred, link up on all + ports took longer than expected, which caused traffic outages. +
+
+
PAN-181334
+
+
+ Fixed an issue where users with custom admin roles and access domains + were unable to view address objects or edit Security rules. +
+
+
PAN-181129
+
+
+ Improved protection against unexpected packets and error handling for + traffic identified as SIP. +
+
+
PAN-180948
+
+
+ Fixed an issue where an external dynamic list fetch failed with the + error message + Unable to fetch external dynamic list. Couldn't resolve host name. + Using old copy for refresh. +
+
+
PAN-180690
+
+
+ Fixed an issue where the firewall dropped IPv6 Bi-Directional + Forwarding (BFD) packets when IP Spoofing was enabled in a Zone + Protection Profile. +
+
+
PAN-179174
+
+
+ Fixed an issue where exported PDF report of the ACC was the incorrect + color after upgrading from a PAN-OS 10.1 or later release. +
+
+
PAN-178951
+
+
+ Fixed an issue on the firewall where Agentless User-ID lost parent + Security group information after the Security group name of the nested + groups on Active Directory was changed. +
+
+
PAN-178728
+
+
+ Fixed an issue where the + dcsd + process stopped responding when attempting to read the config to + update its redis database. +
+
+
PAN-177942
+
+
+ Fixed an issue where, when grouping HA peers, access domains that were + configured using multi-vsys firewalls deselected devices or virtual + systems that were in other configured access domains. +
+
+
PAN-177562
+
+
+ Fixed an issue where PDF reports were not translated to the configured + local language. +
+
+
PAN-177201
+
+
+ Fixed an issue where, when a Panorama appliance on a PAN-OS 9.0 or + later release pushed built-in external dynamic lists to a firewall on + a PAN-OS 8.1 release, the external dynamic list was removed, but the + rule was still pushed to the firewall. With this fix, Panorama will + show a validation error when attempting to push a pre-defined external + dynamic list to a firewall on a PAN-OS 8.1 release. +
+
+
PAN-176989
+
+
+ Fixed an issue where the CLI command to show SD-WAN tunnel members + caused the firewall to stop responding. +
+
+
PAN-176379
+
+
+ Fixed an issue where, when multiple routers were configured under a + Panorama template, you were only able to select its own virtual router + for next hop. +
+
+
PAN-175244
+
+
+ Fixed an issue on Panorama where the + configd + process stopped responding when adding, deleting or listing an + authentication key. +
+
+
PAN-175142
+
+
+ Fixed an issue on Panorama where executing a debug command caused the + logrcvr + process to stop responding. +
+
+
PAN-175061
+
+
+ Fixed an issue where filtering threat logs using any value under + THREAT ID/NAME displayed the error + Invalid term. +
+
+
PAN-174953
+
+
+ Fixed an issue where the firewall didn't update URL categories from + the management plane to the dataplane cache. +
+
+
PAN-174781
+
+
+ Fixed an issue where the firewall did not send an SMTP 541 error + message to the email client after detecting a malicious file + attachment. +
+
+
PAN-174680
+
+
+ Fixed an issue where, when adding new configurations, Panorama didn't + display a list of suggested template variables when typing in a + relevant field. +
+
+
PAN-174027
+
+
+ Fixed an issue on Panorama where attempting to rename mapping for + address options caused a push to fail with the following error + message: + Error: Duplicate address name.. +
+
+
PAN-171927
+
+
+ Fixed an issue where incorrect results were displayed when filtering + logs in the Monitor tab. +
+
+
PAN-171300
+
+
+ Fixed an issue on Panorama where a password change in a template did + not reset an expired password flag on the firewall, which caused the + user to change their password when logging in to a firewall. +
+
+
PAN-170414
+
+
+ Fixed an issue related to an OOM condition in the dataplane, which was + caused by multiple panio commands + using extra memory. +
+
+
PAN-157199
+
+
+ (PA-220 firewalls only) Fixed an issue where + the GlobalProtect portal was not reachable with IPv6 addresses. +
+
+
PAN-142701
+
+
+ Fixed an issue where the firewall did not delete Stateless SCTP + sessions after receiving an SCTP Abort packet. +
+
diff --git a/reference/PAN-OS/addressed/10.2.5-h1.html b/reference/PAN-OS/addressed/10.2.5-h1.html new file mode 100644 index 0000000..8196488 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.5-h1.html @@ -0,0 +1,38 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-229705
+
+
+ Fixed an issue where running the + show rule-hit-count CLI command on + Panorama displayed the error message + Server error : Timed out while getting config lock. Please try + again. + when attempting to log in or run CLI commands. +
+
diff --git a/reference/PAN-OS/addressed/10.2.5-h4.html b/reference/PAN-OS/addressed/10.2.5-h4.html new file mode 100644 index 0000000..1595463 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.5-h4.html @@ -0,0 +1,103 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
diff --git a/reference/PAN-OS/addressed/10.2.5-h6.html b/reference/PAN-OS/addressed/10.2.5-h6.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.5-h6.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/10.2.5-h9.html b/reference/PAN-OS/addressed/10.2.5-h9.html new file mode 100644 index 0000000..2aa7c04 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.5-h9.html @@ -0,0 +1,152 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
+
PAN-248427
+
+
+ Fixed an issue where push operations took longer than expected to + complete. +
+
+
PAN-247403
+
+
+ (Panorama virtual appliances only) Fixed an + issue where the push scope CLI command took longer than expected, + which caused the web interface to be slow. +
+
+
PAN-245850
+
+
+ Fixed an issue on Panorama appliances in active/passive HA + configurations where the firewalls entered an HA out-of-sync status + and jobs failed on the passive appliance with the error message + Could not merged running config from file. +
+
+
PAN-244746
+
+
+ Fixed an issue where changes committed on Panorama were not reflected + on the firewall after a successful push. +
+
+
PAN-235840
+
+
+ Fixed an issue where, after a configuration push from Panorama to + managed firewalls, the status displayed as + None and the push took longer than + expected. +
+
+
PAN-228515
+
+
+ Fixed an issue where the Elasticsearch cluster health status displayed + as yellow or red due to Elasticsearch SSH tunnel flaps. +
+
+
PAN-216941
+
+
+ (M-700 Appliances in Log Collector mode only) + Fixed an issue where Panorama stopped processing and saving logs. +
+
diff --git a/reference/PAN-OS/addressed/10.2.5.html b/reference/PAN-OS/addressed/10.2.5.html new file mode 100644 index 0000000..1132cdc --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.5.html @@ -0,0 +1,3257 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
+ PAN-231823 +
+
+
+ A fix was made to address + CVE-2024-5916. +
+
+
PAN-227179
+
+
+ Fixed an issue where routes were not updated in the forwarding table. +
+
+
PAN-225340
+
+
+ Fixed an issue where GlobalProtect users were unable to connect after + upgrading to PAN-OS 10.2.4 due to an incorrect client authentication + configuration being selected. +
+
+
PAN-225183
+
+
+ Fixed an issue where SSH tunnels were unstable due to ciphers used as + part of the high availability SSH configuration. +
+
+
PAN-224273
+
+
+ Fixed an issue where the + debug dataplane pow status CLI + command did not display extended NIC statistics. +
+
+
PAN-223501
+
+
+ (PA-5200 Series and PA-7000 Series firewalls only) Fixed an issue where diagnostic information for the dataplane in + the dp-monitor.log file was not complete. +
+
+
PAN-223317
+
+
+ Fixed an issue where SSL traffic failed with the error message: + Error: General TLS protocol error. +
+
+
PAN-223185
+
+
+ Fixed an issue where the + distributord + process stopped responding. +
+
+
PAN-222712
+
+
+ (PA-5450 firewalls only) Fixed a low frequency + DPC restart issue. +
+
+
PAN-221984
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where an interface went down after a hotplug event + and was only recoverable by restarting the firewall. +
+
+
PAN-221881
+
+
+ Fixed an issue where log ingestion to Panorama failed, which resulted + in missing logs under the + Monitor tab. +
+
+
PAN-221836
+
+
+ Fixed an issue where improper SNI detection caused incorrect URL + categorization. +
+
+
PAN-221708
+
+
+ Fixed an issue where temporary files remained under + /opt/pancfg/tmp/sw-images/ even + after manually uploading the content or AV file to the firewall. +
+
+
PAN-221647
+
+
+ Fixed an issue where the + Apps seen value was not reflected on + Panorama. +
+
+
PAN-220910
+
+
+ Fixed an issue where an internal management plane NIC caused a kernel + panic when doing a transmit due to the driver reinitializing under + certain failure or change conditions on the same interface during + transmit. +
+
+
PAN-220899
+
+
+ Fixed an issue where you were unable to choose the manual + GlobalProtect gateway. +
+
+
PAN-220747
+
+
+ Fixed an issue where logs were not visible after restarting the log + collector. +
+
+
PAN-220626
+
+
+ Fixed an issue where system warning logs were written every 24 hours. +
+
+
PAN-220448
+
+
+ Fixed an issue where the GlobalProtect client connection remained at + the prelogin stage when Kerberos SSO failed and was unable to fall + back to the realm authentication. +
+
+
PAN-220401
+
+
+ Fixed an issue where, during a reboot, an unexpected error message was + displayed that the syslog configuration file format was too old. +
+
+
PAN-220281
+
+
+ (PA-7080 firewalls only) Fixed an issue where + auto-committing changes after rebooting the Log Forwarding Card (LFC) + caused the + logrcvr + process to fail to read the configuration file. +
+
+
PAN-219690
+
+
+ Fixed an issue where GlobalProtect authentication failed when + authentication was SAML with CAS and the portal was resolved with + IPv6. +
+
+
PAN-219686
+
+
+ Fixed an issue where a device group push operation from Panorama + failed with the following error on managed firewalls: + vsys <vsys1> plugins unexpected here vsys is invalid Commit + failed. +
+
+
PAN-219659
+
+
+ Fixed an issue where root partition frequently filled up and the + following error message was displayed: + Disk usage for / exceeds limit, xx percent in use, cleaning + filesystem. +
+
+
PAN-219640
+
+
+ Fixed an issue where a transformation migration script error caused a + commit failure with the error message + user-id-agent unexpected here. + This occurred after upgrading the firewall from a PAN-OS 9.1 release + to a PAN-OS 10.0 release. +
+
+
PAN-219573
+
+
+ Fixed an issue where tag names did not correctly display special + characters. +
+
+
PAN-219508
+
+
+ (VM-Series, PA-400 Series, PA-1400, PA-3400, and PA-5400 Series + firewalls only) Fixed an issue where Bidirectional Forwarding Detection (BFD) + packets experienced a delay in processing, which caused the BFD + connection to flap. +
+
+
PAN-219498
+
+
+ Fixed an issue where the + Threat ID/Name detail in Threat logs + was not included in syslog messages sent to Splunk. +
+
+
PAN-219351
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding during Layer 7 processing. +
+
+
PAN-219253
+
+
+ Fixed an issue where, after making changes in a template, the + Commit and Push option was grayed + out. +
+
+
PAN-218947
+
+
+ Fixed an issue where logs were not displayed in Elasticsearch under + ingestion load. +
+
+
PAN-218697
+
+
+ Fixed an issue where the ElasticSearch status frequently changed to + red or yellow after a PAN-OS upgrade. +
+
+
PAN-218644
+
+
+ Fixed an issue where the firewall generated incorrect VSA attribute + codes when radius was configured with EAP-based authentication + protocols. +
+
+
PAN-218620
+
+
+ Fixed an issue where scheduled configuration exports and SCP server + connection testing failed. +
+
+
PAN-218404
+
+
+ Fixed an issue where + ikemgr + stopped responding due to receiving + CREATE_CHILD messages with a + malformed SA payload. +
+
+
PAN-218335
+
+
+ Fixed an issue with hardware destination MAC filtering on the Log + Processing Card (LPC) that caused the logging card interface to be + susceptible to unicast flooding. +
+
+
PAN-218318
+
+
+ Fixed an issue where the firewall changed the time zone automatically + instead of retrieving the correct time zone from the NTP server. +
+
+
PAN-218264
+
+
+ (PA-3400 and PA-1400 Series firewalls only) + Fixed an issue where packet drops occurred due to slow servicing of + internal hardware queries. +
+
+
PAN-218151
+
+
+ Fixed an issue where a configuration push to a new firewall did not + work and displayed validation errors. +
+
+
PAN-218107
+
+
+ Fixed an issue with ciphers used for SSH tunnels where packet lengths + were too large, which made the SSH tunnel unstable. +
+
+
PAN-218001
+
+
+ (PA-400 Series firewalls only) Fixed an issue + where shut down commands rebooted the system instead of correctly + triggering a shutdown. +
+
+
PAN-217681
+
+
+ Fixed an issue caused by out of order TCP segments where the TCP + retransmission failed when the TCP segment had the FIN flag and the + TCP data was truncated. +
+
+
PAN-217582
+
+
+ (VM-Series firewalls on Google Cloud Platform environments only) Fixed an issue where firewalls failed to load the virtual machine + information source configuration. +
+
+
PAN-217581
+
+
+ Fixed an issue where the firewall did not initiate scheduled log + uploads to the FTP server. +
+
+
PAN-217489
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where the passive firewall MAC flapping occurred when the passive + firewall was rebooted. +
+
+
PAN-217465
+
+
+ Fixed an issue where the Panorama web interface became unresponsive + and displayed the error message + 504 Gateway Not Reachable. +
+
+
PAN-217431
+
+
+ (PA-5400 Series firewalls with DPC (Data Processing Cards) only) Fixed an issue with slot 2 DPCs where URL Filtering did not work as + expected after upgrading to PAN-OS 10.1.9. +
+
+
PAN-217284
+
+
+ Fixed an intermittent issue where an LACP flap occurred when the LACP + transmission rate was set to Fast. +
+
+
PAN-217169
+
+
+ Fixed an issue where the logrcvr stopped forwarding logs to the syslog + server after a restart or crash. +
+
+
PAN-216996
+
+
+ Fixed an issue where multiple User-ID alerts were generated every 10 + minutes. +
+
+
PAN-216957
+
+
+ Fixed an issue where allow list checks in an authentication profile + did not work if the group Distinguished Name contains the ampersand ( + & ) character. +
+
+
PAN-216913
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the + brdagent + process stopped responding due to missed heartbeats, which caused the + firewall to reboot. This occurred when the + brdagent + process and DPDK-managed ports became out of sync after the Azure + infrastructure triggered a hotplug event. +
+
+
PAN-216821
+
+
+ Fixed an issue where the + reportd + process stopped responding after upgrading an M-200 appliance to + PAN-OS 10.2.4. +
+
+
PAN-216662
+
+
+ Fixed an issue where a custom Antispyware profile did not open and + displayed the following error message: + The server is not responding. Please wait and try your operation + again later. +
+
+
PAN-216366
+
+
+ Fixed an issue where, when custom signatures used a certain syntax, + false positives were generated on devices on a PAN-OS 10.0 release. +
+
+
PAN-216360
+
+
+ Fixed an issue on Panorama where + No Default Selections under + Push to Devices was intermittently + deselected after performing a commit operation. +
+
+
PAN-216170
+
+
+ (PA-400 Series firewalls in HA configurations only) Fixed an issue where an HA switchover took longer than expected to + bring up ports on the newly active firewall. +
+
+
PAN-216054
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while + it was idle. +
+
+
PAN-216048
+
+
+ Fixed an issue where, when upgrading from a PAN-OS 9.1 release to a + PAN-OS 10.0 release, commits failed with the error message: + hip profiles unexpected here. +
+
+
PAN-216043
+
+
+ Fixed an issue where wifclient stopped responding due to shared memory + corruption. +
+
+
PAN-215911
+
+
+ Fixed an issue that resulted in a race condition, which caused the + configd + process to stop responding. +
+
+
PAN-215808
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.1, the log + forwarding rate toward the syslog server was reduced. With this fix, + the overall log forwarding rate has also been improved. +
+
+
PAN-215780
+
+
+ Fixed an issue where changes to Zone Protection profiles made via XML + API were not reflected in the zone protection configuration. +
+
+
PAN-215778
+
+
+ Fixed an issue where API Get requests for + /config timed out due to + insufficient buffer size. +
+
+
PAN-215655
+
+
+ Fixed an issue where, after a multidynamic group push, Security policy + rules with the target device tag were added to a firewall that did not + have the tag. +
+
+
PAN-215503
+
+
+ Fixed a memory-related issue where the + MEMORY_POOL address was mapped + incorrectly. +
+
+
PAN-215496
+
+
+ Fixed an issue where 100G ports did not come up with BIDI QSFP + modules. +
+
+
PAN-215338
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where the inner VLAN tag for Q-in-Q traffic was stripped when + forwarding. +
+
+
PAN-215317
+
+
+ Fixed an issue where the dataplane stopped responding unexpectedly + with the error message + comm exited with signal of 10. +
+
+
PAN-215066
+
+
+ Fixed an issue on Panorama where push scope rendering caused the + Commit and Push or + Push to Devices operation window to + hang for several minutes. +
+
+
PAN-215058
+
+
+ Fixed a memory leak related to the + logdb + process. +
+
+
PAN-214990
+
+
+ Fixed an issue where firewall copper ports flapped intermittently when + device telemetry was enabled. +
+
+
PAN-214815
+
+
+ Fixed an issue where SNMP queries were not replied to due to an + internal process timeout. +
+
+
PAN-214753
+
+
+ Fixed an issue where retrieving WildFire Analysis reports when + choosing WildFire log entries under + Detailed Log View displayed the + error + Fetching WildFire server xxx report failed! +
+
+
PAN-214727
+
+
+ Fixed an issue where a memory leak related to the + useridd + process resulted in an OOM condition, which caused the process to stop + responding. +
+
+
PAN-214669
+
+
+ Fixed an issue where FIN and RESET packets were sent in reverse order. +
+
+
PAN-214201
+
+
+ Fixed an issue where, after exporting custom reports to CSV format, + the letter b appeared at the + beginning of each column. +
+
+
PAN-214187
+
+
+ Fixed an issue where superreaders were able to execute the + request restart system CLI + command. +
+
+
PAN-214026
+
+
+ Fixed an issue where, when using an ECMP + weighted-round-robin algorithm, + traffic was not redistributed among the links proportionally as + expected from the configuration. +
+
+
PAN-213949
+
+
+ Fixed an issue where the VPN responder stopped responding when it + received a CREATE_CHILD message with no security association (SA) + payload. +
+
+
PAN-213942
+
+
+ (PA-400 Series firewalls) Fixed an issue where + the firewall required an explicit allow rule to forward broadcast + traffic. +
+
+
PAN-213932
+
+
+ Fixed an issue where, when an incorrect log filter was configured, the + commit did not fail. +
+
+
PAN-213931
+
+
+ Fixed an issue where the + logrcvr + process cache was not in sync with the mapping on the firewall. +
+
+
PAN-213746
+
+
+ Fixed an issue on Panorama where the Hostkey displayed as + undefined if an SSH Service Profile + Hostkey configured in a template from the template stack was + overridden. +
+
+
PAN-213463
+
+
+ (PA-5200 Series firewalls only) Fixed an issue + where unplugging a PAN-SFP-CG transceiver from an interface with its + link speed setting set to 1000 caused the firewall to incorrectly read + that interface as up. +
+
+
PAN-213296
+
+
+ Fixed an issue where Single Log-out (SLO) was not correctly triggered + from the firewall toward the client, which caused the client to not + initiate the SLO request toward the identity provider (IdP). This + resulted in the IdP not making the SLO callback to the firewall to + remove the user. +
+
+
PAN-213162
+
+
+ Fixed an issue where an SD-WAN object was not displayed under a child + device group. +
+
+
PAN-213077
+
+
+ Fixed an issue where the + sysdagent + process stopped responding, which caused interfaces and the subsequent + connections behind them to fail. +
+
+
PAN-213060
+
+
+ Fixed an issue where Panorama did not show the target under the + Entities column. +
+
+
PAN-212978
+
+
+ Fixed an issue where the firewall stopped responding when executing an + SD-WAN debug CLI command. +
+
+
PAN-212889
+
+
+ Fixed an issue on Panorama where different threat names were used when + querying a threat under + Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after + clicking a threat name in + Threat Monitor and filtering it in + the global filters. +
+
+
PAN-212859
+
+
+ Fixed an issue where the + pan_task stopped responding + briefly during a commit due to a contention with + brdagent updating the + configuration. +
+
+
PAN-212848
+
+
+ Fixed an issue where attempting to change the disk-usage cleanup + threshold to 90 resulted in the error message + Server error : op command for client dagger timed out as client is + not available. +
+
+
PAN-212726
+
+
+ Fixed an issue where RTP/RTCP packets were dropped for SIP calls by + SIP ALG when the source NAT translation type was persistent + Dynamic IP And Port. +
+
+
PAN-212577
+
+
+ (PA-5200 Series and PA-7080 firewalls only) + Fixed an issue where commits took longer than expected when more than + 45,000 Security policy rules were configured. +
+
+
PAN-212576
+
+
+ Fixed an issue where firewall HA clusters in active/active + configurations with Advanced Routing enabled did not relay to ping + requests sent to a virtual IP address. +
+
+
PAN-212530
+
+
+ Fixed an issue on log collectors where root partition reached 100% + utilization. +
+
+
PAN-212057
+
+
+ Fixed an issue where Advanced Threat Prevention caused SSL delays when + no URL licenses were present. +
+
+
PAN-211997
+
+
+ Fixed an issue where large OSPF control packets were fragmented, which + caused the neighborship to fail. +
+
+
PAN-211887
+
+
+ Fixed an issue on Panorama that caused recently committed changes to + not be displayed when previewing the changes to push to device groups. +
+
+
PAN-211843
+
+
+ Fixed an issue where renaming a Zone Protection profile failed with + the error message + Obj does not exist. +
+
+
PAN-211602
+
+
+ Fixed an issue where, when viewing a WildFire Analysis report via the + web interface, the + detailed log view was not accessible + if the browser window was resized. +
+
+
PAN-211575
+
+
+ Fixed an issue where a local commit on Panorama remained at 99% for + longer than expected before completing. +
+
+
PAN-211519
+
+
+ Fixed an issue where RTP/RTCP packets were dropped for SIP calls by + SIP ALG when the source NAT translation type was persistent + Dynamic IP And Port. +
+
+
PAN-211441
+
+
+ Fixed a memory leak issue related to SSL crypto operations that + resulted in failed commits. +
+
+
PAN-211422
+
+
+ Fixed an issue where the + show session packet-buffer-protection buffer-latency + CLI command randomly displayed incorrect values. +
+
+
PAN-211398
+
+
+ Fixed an issue where dataplane processes stopped responding when + handling HTTP/2 streams. +
+
+
PAN-211191
+
+
+ Fixed an issue where the firewall restarted after initiating a + mgmtsrvr + process restart. +
+
+
PAN-211041
+
+
+ (Panorama virtual appliances only) Fixed an + issue where DHCP assigned interfaces did not send + ICMP unreachable - Fragmentation needed + messages when the received packets were higher than the maximum + transmission unit (MTU). +
+
+
PAN-210921
+
+
+ (Panorama appliances in Legacy Mode only) Fixed + an issue where + Blocked Browsing Summary by Website + in the user activity report contained scrambled characters. +
+
+
PAN-210883
+
+
+ Fixed an issue where SSL proxy traffic was dropped when DoS zone + protection was enabled. +
+
+
PAN-210740
+
+
+ Fixed a memory leak issue related to the + slotd + process. +
+
+
PAN-210738
+
+
+ Fixed an issue where fragmented UDP packets were dropped. +
+
+
PAN-210736
+
+
+ Fixed an issue where configuration changes related to the SSH service + profile were not reflected when pushed from Panorama. With this fix, + the deletion of ciphers, MAC, and kex fields of SSH server profiles + and HA profiles won't clear the values under template stacks and will + retain the values configured from templates. +
+
+
PAN-210661
+
+
+ Fixed an issue where firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
+
+
PAN-210640
+
+
+ Fixed an issue where applications were not displayed after + authenticating into the clientless VPN. +
+
+
PAN-210563
+
+
+ Fixed an issue on Panorama where Security policy rules with a + Tag target did not appear in the + pre-rule list of a Dynamic Address Group that was part of the tag. +
+
+
PAN-210511
+
+
+ Fixed an issue where Panorama commits failed due to an invalid + community value error. +
+
+
PAN-210502
+
+
+ Fixed an issue where Panorama was unable to convert to PAN-OS 9.1 + syntax for WF-500 appliances. +
+
+
PAN-210456
+
+
+ Fixed an issue where high latency occurred on PA-850-ZTP when SSL + decryption was enabled. +
+
+
PAN-210452
+
+
+ Fixed an issue where application PCAP was not generated when Security + policy rules were used as a filter. +
+
+
PAN-210451
+
+
+ Fixed an issue where the firewall did not send the source IP address + of the user to the RADIUS server with the + set authentication radius-vsa-on client-source-ip + CLI command. +
+
+
PAN-210429
+
+
+ (VM-Series firewalls only) Fixed an issue where + the HTTP service failed to come up on DHCP dataplane interfaces after + rebooting the firewall, which resulted in health-check failure on + HTTP/80 with a 503 error code on the public load balancer. +
+
+
PAN-210397
+
+
+ Fixed an issue on Panorama where VM-Series firewalls in HA + configurations hosted on Amazon Web Services (AWS) were not displayed + under Deploy Master Key. +
+
+
PAN-210364
+
+
+ Fixed an issue where high latency was observed when accessing internal + web applications, which interrupted development activities related to + the web server. +
+
+
PAN-210325
+
+
+ Fixed an issue on the firewall where the configuration log always + displayed commit-all operations as successful even when the commit + failed. +
+
+
PAN-210216
+
+
+ A debug command was added to address an issue with firewalls in high + availability configurations. +
+
+
PAN-210158
+
+
+ (CN-Series firewalls only) Fixed an issue where + the dataplane stopped responding after a container restart. +
+
+
PAN-210000
+
+
+ Fixed an issue where, when traffic and Threat logs exceeded the + threshold of 90% total allowed size, alarms were not generated for + other log types. +
+
+
PAN-209937
+
+
+ Fixed an issue where certificate-based authentication for + administrators were unable to log in to the Panorama or firewall web + interface and received the following error message: + Bad Request - Your browser sent a request that this server could + not understand. +
+
+
PAN-209930
+
+
+ Fixed an issue where cloned rules pushed from Panorama were not shown + on the managed firewall. +
+
+
PAN-209872
+
+
+ Fixed an issue where dataplane ports responded to ICMP requests fewer + than 64 bytes with nonzero padding bytes in the ICMP response. +
+
+
PAN-209696
+
+
+ Fixed an issue where link-local address communication for IPv6, BFD, + and OSPFv3 neighbors was dropped when IP address spoofing check was + enabled in a Zone Protection profile. +
+
+
PAN-209683
+
+
+ Fixed an issue where Panorama was unable to retrieve IP + address-to-username mapping from a firewall on a PAN-OS 8.1 release. +
+
+
PAN-209617
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where the passive firewall created an incorrect SCTP association due + to the HA sync messages from the active firewall having an incorrect + value. +
+
+
PAN-209585
+
+
+ The Palo Alto Networks QoS implementation now supports a new QoS mode + called lockless QoS for PA-3400, PA-5410, PA-5420, PA-5430, and + PA-5440 firewalls. For firewalls with higher bandwidth QoS + requirements, the lockless QoS dedicates cores to the QoS function + that improves QoS performance, resulting in improved throughput and + latency. +
+
+
PAN-209501
+
+
+ Fixed an issue where the GlobalProtect + logdb quota was not displayed in + the + show system logdb quota output. +
+
+
PAN-209375
+
+
+ Fixed an issue on the firewall where log filtering did not work as + expected. +
+
+
PAN-209172
+
+
+ Fixed an issue where the firewall was unable to handle GRE packets for + Point-to-Point Tunneling Protocol (PPTP) connections. +
+
+
PAN-209108
+
+
+ Fixed an issue where a Panorama in Management Only mode was unable to + display logs from log collectors due to missing schema files. +
+
+
PAN-208902
+
+
+ Fixed an issue where, when a client sent a TCP/FIN packet, the + firewall displayed the end reason as + aged-out instead of + tcp-fin. +
+
+
PAN-208792
+
+
+ Fixed an issue where authentication failed when the service route for + RADIUS traffic was configured as + use default for IPv4 addresses and + included the dataplane interface as the destination route. +
+
+
PAN-208567
+
+
+ Fixed an issue with email formatting where, when a scheduled email + contained two or more attachments, only one attachment was visible. +
+
+
PAN-208343
+
+
+ Fixed an issue where telemetry regions were not visible on Panorama. +
+
+
PAN-208325
+
+
+ (PA-5400 Series, PA-3400 Series, and PA-400 Series only) Fixed an issue where the firewall was unable to automatically renew + the device certificate. +
+
+
PAN-208316
+
+
+ Fixed an issue where user-group names were unable to be configured as + the source user via the + test security-policy-match + command. +
+
+
PAN-208201
+
+
+ Fixed an issue on the firewall where the modified date and time was + incorrectly updated after a commit operation, PAN-OS upgrade, or + reboot. +
+
+
PAN-208198
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where, after rebooting the passive firewall, interfaces were briefly + shown as powered up, and then shown as down or shutdown. +
+
+
PAN-208187
+
+
+ Fixed an issue where REST API requests did not work for GlobalProtect + gateway tunnels. +
+
+
PAN-208090
+
+
+ Fixed an issue where the ACC report did not display data when querying + the filter for the fields Source and + Destination IP. +
+
+
PAN-208039
+
+
+ (PA-7000 Series firewalls with SMC-B only) + Fixed an issue where the details of configuration changes were not + included in configuration logs on the syslog server. +
+
+
PAN-207842
+
+
+ Fixed an issue where WildFire Analysis reports were not visible when + the WF-500 appliance was on private cloud. +
+
+
PAN-207741
+
+
+ Fixed an issue where Large Scale VPN (LSVPN) Portal authentication + failed with the error + invalid http response. return error(Authentication failed; Retry + authentication + when the satellite connected to more than one portal. +
+
+
PAN-207700
+
+
+ Fixed an issue where the + show system info and + show system ztp status CLI + commands displayed a different Zero Touch Provisioning (ZTP) status if + a firewall upgrade was initiated from Panorama before the initial + commit push succeeded. +
+
+
PAN-207661
+
+
+ Fixed an issue with firewalls in active/active HA configurations where + the virtual floating IP address configuration under a Panorama + template was overridden and displayed + From Template Override: undefined + as a source. +
+
+
PAN-207604
+
+
+ Fixed an issue where system logs continuously generated the log + message + Not enough space to load content to SHM. +
+
+
PAN-207457
+
+
+ Fixed an issue where the MLAV allow list did not work for some types + of traffic. +
+
+
PAN-207240
+
+
+ Fixed an issue where + mprelay + repeatedly restarted, which caused commits to remain at 70% before + failing with the error message + A communication error happened during the configuration commit to + the data plane, please try again. +
+
+
PAN-206765
+
+
+ Fixed an issue where log forwarding filters involving negation did not + work. +
+
+
PAN-206640
+
+
+ Fixed an issue where the + ikemgr process stopped + responding, which caused IPSec tunnels to go down. +
+
+
PAN-206396
+
+
+ Fixed an issue where HIP report flip and HIP check failed when a user + was part of multiple user groups with different domains. +
+
+
PAN-206391
+
+
+ Fixed an issue where shared objects were seen under the push scope + with every configuration push. +
+
+
PAN-206333
+
+
+ Fixed an issue where the + Include/Exclude IP filter under + Data Distribution did not work + correctly. +
+
+
PAN-206278
+
+
+ Fixed an issue where a critical system log was generated when the boot + drive for PA-7000 Series firewall Switch Management Cards (SMCs) + failed. +
+
+
PAN-206221
+
+
+ Fixed an issue where scheduled configuration pushes with + Include Device and Network Templates + selected did not work. +
+
+
PAN-205513
+
+
+ Fixed an issue where the stats dump file generated by Panorama for a + device firewall differed from the stats dump file generated by the + managed device. +
+
+
PAN-205369
+
+
+ Fixed an issue where connections to + Strata Logging Service were initialized from + the firewall even when + Strata Logging Service forwarding was + disabled. +
+
+
PAN-205086
+
+
+ Fixed an issue where DNS Security categories were able to be deleted + from spyware profiles. +
+
+
PAN-204718
+
+
+ (PA-5200 Series firewalls only) Fixed an issue + where, after upgrading to PAN-OS 10.1.6-h3, a TACACS user login + displayed the following error message during the first login attempt: + Could not chdir to home directory /opt/pancfg/home/user: Permission + denied. +
+
+
PAN-204683
+
+
+ Fixed an issue where logs were unable to be generated due to old logs + not getting purged and + /opt/panlogs reaching over 100% + usage. +
+
+
PAN-204530
+
+
+ Fixed an issue where giving up FTP or SCP sessions for log export took + longer than expected after a failure to export the log when one of the + destination hosts designated in the scheduled log export was + unresponsive. +
+
+
PAN-204420
+
+
+ (WF-500 appliances only) Fixed an issue where, + after an upgrade to a PAN-OS 10.1 release, SNMP traps were not sent to + the SNMP server. This occurred due to SNMP trap server settings not + being enabled. +
+
+
PAN-204233
+
+
+ Fixed an issue where, when the firewall received a 513 error from the + WildFire cloud, the firewall attempted to repeatedly send the same + file. +
+
+
PAN-204215
+
+
+ (PA-7000 Series firewalls with Log Processing Cards (LPCs) only) Fixed an issue where performing a commit operation resulted in the + following error messages: + log forwarding is setup for data but log-card interface is not + setup + or + log forwarding is setup for traffic but log-card interface is not + setup. +
+
+
PAN-203791
+
+
+ (PA-3400 and PA-5400 Series firewalls only) + Fixed an issue where the log type correlation was not configurable and + displayed as + $.Format.Correlation (Device > Server Profile > syslog ><Profile-name> + > Customer log format > log type). +
+
+
PAN-203655
+
+
+ Fixed an issue where enabling + event-specific traps (Device > Setup > Operations > Miscellaneous > SNMP + Setup), the new deviating device system logs included incorrect + information. +
+
+
PAN-203611
+
+
+ Fixed an issue where URL categorization was not recognized for URLs + that contained more than 100 characters. +
+
+
PAN-203222
+
+
+ Fixed an issue where commit-all operations took longer than expected + due to cURL failures and timeouts related to external dynamic list + retrieval. +
+
+
PAN-203168
+
+
+ Fixed an issue where the WIF state was not cleaned up promptly after + usage, which caused allocation failure. This fix increased the + wif_state quota. +
+
+
PAN-202981
+
+
+ Fixed an issue on Panorama where global find did not return results + for existing universally unique identifiers (UUID). +
+
+
PAN-202963
+
+
+ Fixed an issue where the system log message + dsc HA state is changed from 1 to 0 + was generated with the severity + High. With this fix, the severity + was changed to Info. +
+
+
PAN-202524
+
+
+ Fixed an issue where the session ID was missing in the session details + section of the + ingress-backlogs XML API output. +
+
+
PAN-202516
+
+
+ Fixed an issue where the firewall stopped responding if it received an + illegal packet with SRC port = 0 encapsulated within a VXLAN packet. +
+
+
PAN-201855
+
+
+ Fixed an issue where, after cloning a template, a certificate with the + block private key option enabled was corrupted. +
+
+
PAN-201721
+
+
+ Fixed an issue with firewalls in HA configurations where HA setup + generated the error + mismatch due to device update + during a content update even though the version was the same. +
+
+
PAN-201515
+
+
+ Fixed an issue with the web interface where the cursor disappeared + under the Policies and + Objects tabs on the search bar if + the cursor was moved quickly. +
+
+
PAN-201466
+
+
+ Fixed an issue where the system log generated on GlobalProtect + satellite did not provide the reason for failures to connect to the + GlobalProtect portal or gateway. +
+
+
PAN-200757
+
+
+ Fixed an issue with client certificate generation on Panorama, which + resulted in a firewall being unable to connect to a log collector. +
+
+
PAN-200394
+
+
+ Fixed an issue where, after a push from Panorama to one or more device + groups in a multi-vsys environment, vulnerability profile exceptions + were not seen on all firewalls. +
+
+
PAN-199819
+
+
+ Fixed an issue where, if a decryption profile allowed TLS1.3, but the + server only supported TLS1.2, and the cipher used by the first + connection to the server was a CBC SHA2 cipher suite, the connection + failed. +
+
+
PAN-199687
+
+
+ Fixed an issue where content updates failed when using prelicensed + keys during the bootstrap process. +
+
+
PAN-199557
+
+
+ Fixed an issue on Panorama where virtual memory usage exceeded the set + limit, which caused the + configd + process to restart. +
+
+
PAN-198453
+
+
+ Fixed an issue where you were unable to resize the + Description pop-up window (Policies > Security > Prerules). +
+
+
PAN-198050
+
+
+ Fixed an issue where + Connection to update server is successful + messages displayed even when connections failed. +
+
+
PAN-197493
+
+
+ Fixed an issue where having multiple terminal service agents with the + same hostname caused the firewall to reboot. +
+
+
PAN-197467
+
+
+ Fixed an issue on Panorama where the WildFire + Test-Configuration feature did not + work as expected. +
+
+
PAN-197388
+
+
+ Fixed an issue where, when the firewall forwarded Threat logs via + email, the email client truncated the sender and recipient email + addresses when they were put between angle brackets (<, >). +
+
+
PAN-196956
+
+
+ Fixed an issue where URL Filtering logs did not display matching + entries when filtered by device name. +
+
+
PAN-196923
+
+
+ Fixed an issue where the interface option did not have a source + address in the cURL command, which caused a DNS lookup error and + resulted in DNS lookup failing for device Telemetry. +
+
+
PAN-196597
+
+
+ Fixed an issue where the + dnsproxyd + process stopped responding due to corruption. +
+
+
PAN-196417
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where firewalls experienced slow SNMP responses, which caused the SNMP + server to time out before polling completion. +
+
+
PAN-196345
+
+
+ Fixed an issue where scheduled dynamic content updates failed to be + retrieved by managed firewalls from Panorama when connectivity was + slow. +
+
+
PAN-195788
+
+
+ Fixed an issue where zip files did not download when applying Security + inspection and the following error message displayed: + resources-unavailable. +
+
+
PAN-195439
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the dataplane interface status went down after + a hotplug event triggered by Azure infrastructure. +
+
+
PAN-195251
+
+
+ Fixed an issue where IPSec tunnel re-key generated the critical log + message tunnel-status-up. +
+
+
PAN-193521
+
+
+ Fixed an issue where + Panorama > Device > Deployment > Software + did not display software after running + check now for managed devices. +
+
+
PAN-190903
+
+
+ Fixed an issue where MAC addresses in threat capture were swapped + between the source MAC and destination MAC addresses. +
+
+
PAN-190435
+
+
+ Fixed an issue where, after committing a configuration change, the + Task Manager commit + Status went directly from 0% to + Completed instead of reflecting the + accurate commit job process. +
+
+
PAN-190055
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall did not follow the set Jumbo MTU value. +
+
+
PAN-189442
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused the firewall to reboot. +
+
+
PAN-189423
+
+
+ Fixed an issue where exporting correlation logs generated an empty + file. +
+
+
PAN-189328
+
+
+ Fixed an issue where traffic belonging to the same session was sent + out from different ECMP enabled interfaces. +
+
+
PAN-187989
+
+
+ Fixed an issue where a user who did not have permissions of other + access domains were able to view the commit and configuration lock. +
+
+
PAN-186956
+
+
+ Fixed an issue where SD-WAN DIA VIF did not become active if default + gateways for member interfaces did not respond to pings. +
+
+
PAN-186182
+
+
+ Fixed an issue where software buffer 3 was depleted when URL proxy was + enabled and SSL sessions were decrypted to inject the block page. This + issue occurred when an HTTP/2 block page was displayed for a large + POST request. +
+
+
PAN-185249
+
+
+ Fixed an issue where + Template Stack overrides (Dynamic Updates > App & Threats > Schedule) were not able to be reverted via the web interface. +
+
+
PAN-185135
+
+
+ (VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the physical port counters (including SNMP) on + the dataplane interfaces increased when DPDK was enabled. +
+
+
PAN-184630
+
+
+ Fixed an issue where TLS clients, such as those using OpenSSL 3.0, + enforced the TLS renegotiation extension (RFC 5746). +
+
+
PAN-183297
+
+
+ Fixed an issue where, when the firewall received a large amount of + user information, the firewall was unable to output IP + address-to-username mapping information via XML API. +
+
+
PAN-182960
+
+
+ Additional error logs were added for an issue where, when multiple + Panorama web interface sessions were opened, active lock did not show + up on the web interface for any session. +
+
+
PAN-182734
+
+
+ Fixed an issue where, on an Advanced Routing Engine, BGP peering + flapped after a commit. +
+
+
PAN-180082
+
+
+ Fixed an issue where errors in + brdagent + logs caused dataplane path monitoring failure. +
+
+
PAN-177227
+
+
+ (VM-Series firewalls on Amazon Web Services environments only) Fixed an issue where traffic sent from a GENEVE tunnel to the + firewall was dropped if the firewall attempted to encapsulate traffic + into an IPSec tunnel. +
+
+
PAN-176412
+
+
+ Fixed an issue where changing the password of a local database user + did not work. +
+
+
PAN-172977
+
+
+ Fixed an issue where session offloading did not occur on a tap + interface under a high packet load. +
+
+
PAN-172600
+
+
+ Fixed an issue where the CLI command + show rule-hit-count did not + provide all details of the rule from the device group. +
+
+
PAN-169586
+
+
+ Fixed an issue where scheduled log view reports in emails didn't match + the monitor page query result for the same time interval. +
+
+
PAN-168102
+
+
+ Fixed an issue where the API format to check heap usage of a node + showed a JSON error. +
+
+
PAN-160633
+
+
+ (PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls + only) Fixed an issue where the dataplane restarted repeatedly due to an + internal path monitoring failure until a power cycle. +
+
+
PAN-151692
+
+
+ Fixed a permission issue where a Panorama administrator was unable to + download or install Dynamic Updates (Panorama > Device Deployment). +
+
diff --git a/reference/PAN-OS/addressed/10.2.6-h1.html b/reference/PAN-OS/addressed/10.2.6-h1.html new file mode 100644 index 0000000..1595463 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.6-h1.html @@ -0,0 +1,103 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
diff --git a/reference/PAN-OS/addressed/10.2.6-h3.html b/reference/PAN-OS/addressed/10.2.6-h3.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.6-h3.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/10.2.6-h6.html b/reference/PAN-OS/addressed/10.2.6-h6.html new file mode 100644 index 0000000..b5886c1 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.6-h6.html @@ -0,0 +1,134 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
+
PAN-249581
+
+
+ Fixed an issue where stale BGP routes were advertised to peers even + when they were not present in the local RIB table. +
+
+
PAN-228877
+
+
+ (PA-5200 Series, PA-5400 Series, and PA-7000 Series firewalls + only) Fixed an issue with out-of-memory (OOM) conditions that caused slot + restarts due to + pan_cmd + consuming more than 300MB. +
+
+
PAN-223852
+
+
+ Fixed an issue where + all_pktproc + stopped responding when network packet broker or decryption broker + chains failed. +
+
+
PAN-223652
+
+
+ Fixed an issue where data was not thread safe and led to concurrent + read/write issues that caused GPSVC to stop working unexpectedly. +
+
diff --git a/reference/PAN-OS/addressed/10.2.6.html b/reference/PAN-OS/addressed/10.2.6.html new file mode 100644 index 0000000..a754f53 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.6.html @@ -0,0 +1,260 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
+ PAN-231823 +
+
+
+ A fix was made to address + CVE-2024-5916. +
+
+
PAN-229865
+
+
+ (PA-220 firewalls only) Fixed an issue where + upgrading to PAN-OS 10.2.5 failed if the firewall was on a PAN-OS 10.1 + release. +
+
+
PAN-229705
+
+
+ Fixed an issue where running the + show rule-hit-count CLI command + on Panorama displayed the error message + Server error : Timed out while getting config lock. Please try + again. + when attempting to log in or run CLI commands. +
+
+
PAN-227639
+
+
+ Fixed an issue where the + ACC displayed an incorrect DNS-base + application traffic byte count. +
+
+
PAN-227523
+
+
+ A fix was made to address customer and internal bugs (CVE-2023-38802). +
+
+
+ PAN-227376 +
+
+
+ Fixed an issue where a memory overrun caused the + all_task + process to stop responding. +
+
+
PAN-225240
+
+
+ Fixed an issue where the OSPF neighbor state remained in + exstart when the OSPF network had + more than 40 routes. +
+
+
PAN-223787
+
+
+ (PA-400 Series and PA-1400 Series firewalls only) Fixed an issue where commits failed with the error message + Error unserializing profile objects failed to handle + CONFIG_UPDATE_START. +
+
+
PAN-221728
+
+
+ Fixed an issue where selective pushes did not work after upgrading to + PAN-OS 10.2.4. +
+
+
PAN-216775
+
+
+ Fixed an issue where the + devsrvr + process stopped responding at + pan_cloud_agent_get_curl_connection() + and the URL cloud could not be connected. +
+
+
PAN-214273
+
+
+ Fixed an issue where Elasticsearch logs were not cleared, which caused + the root partition to fill up. +
+
+
PAN-205015
+
+
+ Fixed an issue where not all users were included in the user group + after an incremental sync between the firewall and the Cloud Identity + Engine. +
+
+
PAN-204868
+
+
+ Fixed an issue where disk utilization was continuously high due to the + log purger not sufficiently reducing the utilization level. +
+
+
PAN-198509
+
+
+ Fixed an issue where commits failed due to insufficient CFG memory. +
+
+
PAN-198043
+
+
+ Fixed a rare issue where aBuildXmlCache + job failed on the firewall. +
+