Added remaining PAN-OS 10.2 reference files
Test and deploy / deploy (push) Successful in 29s

This commit is contained in:
2026-07-29 12:45:46 -05:00
parent ead6108f2a
commit b36247faf4
39 changed files with 15821 additions and 0 deletions
+37
View File
@@ -0,0 +1,37 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 38%" />
<col style="width: 62%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-190311</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-220 and PA-220R firewalls and PA-800 Series firewalls only</tt
>) Fixed an issue where management connectivity to the firewall was
lost due to the expiration of the DHCP lease, which caused the IP
configuration on the management port to be purged in PAN-OS 10.2.0. To
upgrade, download PAN-OS 10.2.0 (no installation), then download and
install PAN-OS 10.2.0-h1.
</div>
</td>
</tr>
</tbody>
</table>
+147
View File
@@ -0,0 +1,147 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237871</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>WF-500 appliances and PAN-DB private cloud deployments only</tt
>) Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">device-client-cert</span> was set to
expire on December 31, 2023. With this fix, the expiration date has
been extended.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-198372</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+61
View File
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+96
View File
@@ -0,0 +1,96 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 38%" />
<col style="width: 62%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231823</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5916"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5916</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186143</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where no local changes could be made on a ZTP-enabled
device after an upgrade to PAN-OS 10.1.x.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182634</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-400 series firewalls only</tt>) Fixed an issue
where the firewall detected a Power Supply Unit (PSU) failure for the
opposite side when disconnecting a PSU from the device. This issue
occurred when redundant PSUs were connected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-178165</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="keyword cmdname"
>set system setting ctd ctd-agent-assigned-cores 0</span
>
to change assigned cores for the ctd-agent failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-175950</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IoT Security (without
<span class="ph">Strata Logging Service</span>) onboarding failed.
</div>
</td>
</tr>
</tbody>
</table>
+159
View File
@@ -0,0 +1,159 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239241</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the root certificate for WildFire appliances to December 31,
2032.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237871</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>WF-500 appliances and PAN-DB private cloud deployments only</tt
>) Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">device-client-cert</span> was set to
expire on December 31, 2023. With this fix, the expiration date has
been extended.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-198372</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+61
View File
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+689
View File
@@ -0,0 +1,689 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">WIF-495</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where edits made to an existing data
filtering profile resulted in matching traffic not being detected by
Enterprise DLP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231823</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5916"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5916</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190311</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-220 and PA-220R firewalls and PA-800 Series firewalls only</tt
>) Fixed an issue where management connectivity to the firewall was
lost due to the expiration of the DHCP lease, which caused the IP
configuration on the management port to be purged in PAN-OS 10.2.0. To
upgrade, download PAN-OS 10.2.0 (no installation), then download and
install PAN-OS 10.2.0-h1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190175 and PAN-190223</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address an OpenSSL infinite loop vulnerability in
the PAN-OS software (<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2022-0778"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2022-0778</a
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189665</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">FIPS-CC enabled firewalls only</tt>) Fixed an issue
where the firewall was unable to connect to log collectors after an
upgrade due to missing cipher suites.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-189565</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue after upgrading to PAN-OS 10.2 where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>tund</a
>
process stopped responding on multiple GlobalProtect clients.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189468</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall onboard packet processor used by the
PAN-OS content-inspection (CTD) engine can generate high dataplane
resource usage when overwhelmed by a session with an unusually high
number of packets. This can result in
<span class="ph systemoutput">resource-unavailable</span> messages due
to the content inspection queue filling up. Factors related to the
likelihood of an occurrence include enablement of content-inspection
based features that are configured in such a way that might process
thousands of packets in rapid succession (such as SMB file transfers).
This can cause poor performance for the affected session and other
sessions using the same packet processor. PA-3000 series and VM-Series
firewalls are not impacted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189361</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to distribute antivirus
signature updates to firewalls with an Advanced Threat Prevention
license only.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189298</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where existing traffic sessions were not synced after
restarting the active dataplane when it became passive.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189230</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue that
caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process to stop responding with floating point exception (FPE) when
there was a module of 0 on the queue number.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189214</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that prevented antivirus signature update packages that
are normally available to install from displaying properly on the
firewall when the Advanced Threat Prevention license is present on a
firewall without a Threat Prevention license.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189206</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Device Group and Template administrator roles
didn't support a context switch between the Panorama and firewall web
interfaces.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189106</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where you were unable to successfully
downgrade to a PAN-OS 10.1 release unless you uninstalled the ZTP
Plugin 2.0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189094</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading a CN-Series firewall from a
PAN-OS 10.1 release to PAN-OS 10.2.0, show session commands did not
return output.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189032</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Advanced Routing was enabled on the
firewall, an OSPFv3 interface configured with the p2mp link type
caused commits to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a successful upgrade to PAN-OS 10.2,
logging into the firewall or Panorama web interface from the same
internet browser window or session from which the firewall or Panorama
was upgraded did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188883</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when pre-generated license key files were
manually uploaded via the web interface, they weren't properly
recognized by PAN-OS and didn't display a serial number or initiate a
reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188828</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where web pages and web page contents did
not properly load when cloud inline categorization was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188009</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a firewall import to Panorama running a PAN-OS
10.1 release or a PAN-OS 10.2 release resulted in corrupted private
information when the master key was not used.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187846</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a selective push pushed an incorrect
configuration to the managed firewalls, which caused the firewalls to
display as out of sync. This issue occurred if the Panorama-pushed
version for the
<span class="ph uicontrol">Shared Policy and Template</span>
configuration were 20 or more versions older than the current local
running configuration on Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187769</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed a Data Plane Development Kit (DPDK) issue where interfaces
remained in a link-down state after an Azure hot plug event. This
issue occurred due to a hot plug of Accelerated Networking interfaces
on the Azure backend caused by host updates, which led to Virtual
Function unregister/Register messages on the VM side.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186886</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where individual configuration objects were not
viewable after committing selective configuration changes on a
multi-vsys firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after logging in, Panorama displayed a 500 error
page after five minutes of logging for dynamic group template admin
types with access to approximately 115 managed devices or 120 dynamic
groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186516</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log queries that included WildFire submission
logs returned more slowly than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-186487</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with snmpd.log overflow caused by continuous hourly
repeating errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186402</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-440 Series firewalls only</tt>) Fixed an issue
where the firewall's maximum tunnel limit was incorrect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186137</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the firewall management interface incorrectly displayed 10G port
speed as an option even though 10G speed is not supported and can't be
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185616</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent fewer logs to the system log
server than expected. With this fix, the firewall accommodates a
larger send queue for syslog forwarding to TCP syslog receivers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185164</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where processing corrupted IoT messages caused the
<span class="ph systemoutput">wificlient</span> process to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184224</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where you were unable to select a template
variable in
<span class="ph uicontrol"
>Templates &gt; Device &gt; Log Forwarding Card &gt; Log Forwarding
Card Interface &gt; Network &gt; IP address location</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183826</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after clicking
<span class="ph uicontrol">WildFire Analysis Report</span>, the web
interface failed to display the report with the following error
message: <span class="ph systemoutput">refused to connect</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183567</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where ZTP Plugin 2.0 was not available for
download before upgrading Panorama to PAN-OS 10.2.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182492</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the WildFire analysis report was not viewable
from the firewall WildFire submission log entry page.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181839</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama Global Search reported
<span class="ph uicontrol">No Matches found</span> while still
returning results for matching entries on large configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181039</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with DNS cache depletion that caused continuous DNS
retries.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181031</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CN-NGFW (DP) folder on the CN-MGMT pod
eventually consumed a large amount of space in the /var/log/pan
because the old registered stale next-generation firewall logs were
not being cleared.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-180338</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CTD loop count wasn't accurately incremented.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-180095</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama serial-number-based redistribution
agents did not redistribute HIP reports.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-179966</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to a PAN-OS 8.1 release, the
port on the firewall stayed up, but the port on the connected device
reported down. This occurred because, on force mode, autoneg was
disabled by default. With this fix, autoneg is enabled by default on
force mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-179420</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a selective push to managed firewalls
failed after renaming an existing device group, template, or template
stack that was already pushed to the managed firewalls and you
selectively committed specific configuration objects from the renamed
device group, template, or template stack.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-179321</b></div>
</td>
<td class="entry relcol">
<div class="p">
A validation error was added to inform an administrator when a policy
field contained the value <span class="ph uicontrol">any</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-178195</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the URL filtering logs generated by traffic
analyzed by Advanced URL filtering cloud inline categorization didn't
display the URL name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-177072</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where Panorama did not show new logs from
firewalls.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-176889</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the log collector continuously disconnected from
Panorama due to high latency and a high number of packets in Send-Q.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-176693</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-300 and M-700 appliances only</tt>) Fixed an
issue where the Activity (ACT) LEDs on the RJ-45 ports did not blink
when processing network traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-174607</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where, when Security profiles were
attached to a policy, files that were downloaded across TLS sessions
decrypted by the firewall were malformed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-145833</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3200 Series firewalls only</tt>) Fixed an issue
where the firewall stopped recording dataplane diagnostic data in
dp-monitor.log after a few hours of uptime.
</div>
</td>
</tr>
</tbody>
</table>
+61
View File
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195517</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">CommitAll</span> operations from Panorama
to Prisma Access device groups failed due to missing configuration
files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194107</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the expiry date for the Advanced Threat
Protection license was incorrect for BND3 payg VM-Series firewalls on
Amazon Web Services (AWS), Oracle Cloud Infrastructure (OCI), Google
Cloud Platform (GCP), and Microsoft Azure.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-186075</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall rebooted after receiving large packets while in DPDK mode
on Azure virtual machines running CX4 (MLx5) drivers.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-192999</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2022-0028"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2022-0028</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+159
View File
@@ -0,0 +1,159 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237935</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the offline PAN-DB, Panorama, and WildFire certificates which
were previously set to expire on September 2, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237871</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>WF-500 appliances and PAN-DB private cloud deployments only</tt
>) Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">device-client-cert</span> was set to
expire on December 31, 2023. With this fix, the expiration date has
been extended.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-198372</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+61
View File
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+580
View File
@@ -0,0 +1,580 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231823</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5916"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5916</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193579</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where new logs viewed from the CLI (show log
&lt;log_type&gt;) and new syslogs forwarded to a syslog server
contained additional, erroneous entries.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192930</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the default port was not TCP/443,
implicitly used SSL applications were blocked by the Security policy
as an SSL application and did not shift to the correct application.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192880</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall was configured for jumbo
frames, an internal interface was not set with the correct MTU, which
caused byte frames larger than 1500 to be dropped when a DF bit was
set.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192725</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to forward logs to Panorama
when configured with IPv6 addressing only.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192089</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the IPSec tunnel did not
gray out after disabling it.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191629</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the hourly summary log was limited to 100,001 lines when summarized,
which resulted in inconsistent report results when using summary logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191513</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on multi-vsys firewalls where the DLP cloud service
continued to exclude an application added to a shared application
group (<span class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">Application Filters</span></span
>) from non-file traffic inspection. This issue occurred when the
application was removed from the application group or filter that was
added to the
<span class="ph uicontrol">App Exclusion List</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Objects</span
><span class="ph uicontrol">DLP</span
><span class="ph uicontrol">Data Filtering Profiles</span></span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191470</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where encrypted passwords were sent to
firewalls on PAN-OS 10.1 releases during a multi-device group push,
which caused client-based External Dynamic Lists (EDL) to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to use the web interface to
override IPsec tunnels pushed from Panorama
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191288</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall restarted due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxy</a
>
process crash.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190811</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
logs were forwarded through the management interface instead of the
configured log interface to be used for forwarding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190675</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an IoT cloud connectivity issue with the firewall dataplane when
the <span class="ph uicontrol">Data Services</span> service route was
used and the egress interface had VLAN tagging.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190492</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama log collector group level SSH
settings were not migrated to the new format when upgrading from a
PAN-OS 9.1 release to a PAN-OS 10.0 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189429</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak that occurred when enabling XFF (x-forwarded-for)
logging in a Security policy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189395</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-400 Series firewalls only</tt>) Fixed an issue
where running a PAN-OS 10.2 release caused dataplane processes to
restart unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189010</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a deadlock in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process caused both the web interface and the CLI to be inaccessible.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188872</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an OOM condition caused by a memory leak issue on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188833</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where shared address objects used as a source or
destination in policies were cloned but not freed back after
configuration commits.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped allocating new sessions with
increments in the counter session_alloc_failure. This was caused by
GPRS tunneling protocol (GTP-U) tunnel session aging processing issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187558</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the following error message flooded the system
log:
<span class="ph systemoutput">Incremental update to DP failed</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187429</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-3400 Series firewalls and PA-5410, PA-5420, and PA-5430
firewalls only</tt
>) Fixed an issue where the CLI and SNMP MIB walk did not display the
model and serial number of the fan tray and PSUs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where tunnel-monitoring interface was incorrectly shown
as up instead of down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186913</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Validate Device Group</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Commit</span
><span class="ph uicontrol">Commit and Push</span></span
>) incorrectly issued a commit all operation instead of a validate all
operation. This issue occurred when multiple device groups were
included in the push.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186750</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to a PAN-OS 10.1 release, SaaS
reports generated on Panorama did not display
<span class="ph uicontrol">Applications at a glance</span> and most
charts were missing data on the right side of the chart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185844</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Decryption Log entries were associated with the
wrong Security policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185558</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama log migration failed when old logs
migrated to a newer format. This was due to older indices failing to
close.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184474</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall had Advanced Routing enabled,
a static route remained active after an interface went down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183579</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SD-WAN path monitoring failed over the interface
directly connected to the ISP due to an unsupported ICMP probe format.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183319</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits remained at 99% due to
multiple firewalls sending out CSR singing requests every 10 minutes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182087</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commit failures occurred due to validity checks
performed against self-signing certificates not evaluating
<span class="ph uicontrol">Authentication Key Identifier</span> and
<span class="ph uicontrol">Subject Key Identifier</span> fields were
present.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-180396</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama displayed an error when generating a
ticket to disable GlobalProtect for Prisma Access.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-180147</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">bcm.log</span> and
<span class="ph systemoutput"
>brdagent_stdout.log-&lt;datestamp&gt;</span
>
files filled up the root disk space.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-178450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where icons weren't displayed for clientless VPN
applications.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-177671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SIP traffic traversing the firewall was
sent with a high Quality of Service (QoS) differentiated service code
(DSCP) value, the DSCP value was reset to the default setting (CS0)
for the first data packet.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-177455</b></div>
</td>
<td class="entry relcol">
<div class="p">
<tt class="ph tt"
>PA-7000 Series firewalls with HA clustering enabled and using HA4
communication links only</tt
>) Fixed an issue where loading PAN-OS 10.2.0 on the firewall caused
the PA-7000 100G NPC (Network Processing Card) to go offline. As a
result, the firewall failed to boot normally and entered maintenance.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-176156</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where executing the
<span class="ph userinput">show running resource-monitor</span> with
the <span class="ph systemoutput">ingress-backlogs</span> option
enabled displayed the error message `Dataplane is not up or invalid
target-dp(*.dp*)`.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-174345</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a process
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
stopped responding after upgrading the firewall.
</div>
</td>
</tr>
</tbody>
</table>
+103
View File
@@ -0,0 +1,103 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
</tbody>
</table>
+103
View File
@@ -0,0 +1,103 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+206
View File
@@ -0,0 +1,206 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205830</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with multi-vsys firewalls where custom applications and
shared objects pushed from Panorama did not populate in their
respective lists on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205805</b></div>
</td>
<td class="entry relcol">
Fixed an issue where Generic routing encapsulation (GRE) traffic was
only allowed in one direction when tunnel content inspection (TCI) was
enabled.
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a commit operation remained at 55% for longer
than expected if more than 7,500 Security policy rules were
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where file identification failed for files with minimal
data with large headers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202535</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Device Telemetry configuration for a region
was unable to be set or edited via the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201872</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SMB performance caused overall network latency
after an upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201714</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with GlobalProtect where attempting to authenticate
with the GlobalProtect gateway returned a 502 error code.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201357</b></div>
</td>
<td class="entry relcol">
<div class="p">
The CLI command
<span class="ph userinput"
>debug dataplane set pow no-desched yes</span
>
was added to address an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding and caused traffic issues.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200946</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where GRE tunnels went down due to recursive routing when the passive
firewall was booting up. When the passive firewall became active and
no recursive routing was configured, the GRE tunnel remained down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198718</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5280 firewalls only</tt>) Fixed an issue where
memory allocation failures caused increased decryption failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196583</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Cisco TrustSEc plugin triggered a flood of
redundant register/unregister messages due to a failed IP address tag
database search.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-195756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused an API request timeout when parsing
requests using large header buffers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195713</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clientless VPN applications were not displayed in
the GlobalProtect portal page.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-182732</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect gateway inactivity timer wasn't
refreshed even though traffic was passing through the tunnel.
</div>
</td>
</tr>
</tbody>
</table>
+244
View File
@@ -0,0 +1,244 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210513</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Captive Portal authentication via SAML did not
work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where domain information wasn't populated in IP
address-to-username matching after a successful GlobalProtect
authentication using an authentication override cookie.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208079</b></div>
</td>
<td class="entry relcol">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where the PAN-DB engine did not start when using a
VM-Series firewall Flex based CPU.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-207562</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the shard count displayed by the
<span class="ph systemoutput"
>show log-collector-es-cluster health</span
>
CLI command was higher than the recommended limit. The recommended
limit can be calculated with the formula
20*heap-memory*no-of-data-nodes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206963</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-700 Appliances only</tt>) A CLI command was added
to check the status of each physical port of a bond1 interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206921</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client pre-login was
successful, but the certificate authentication failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the push scope was displaying duplicate shared
objects for each device group that were listed under the
<span class="ph uicontrol">shared-object</span> group.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206069</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to boot up on older Intel
CPUs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205698</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect authentication did not work on
Apple MacOS devices when the authentication method used was CIE with
SAML Authentication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204892</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the web interface was not accessible
and displayed the error
<span class="ph uicontrol">504 Gateway Not Reachable</span> due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mgmtsrvr</a
>
process not responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204838</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">dot1q</span> VLAN tag in ARP reply
packets were not displayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204572</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where python scripts were not working as expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-197339</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where template configuration for the User-ID agent was
not reflected on the template stack on Panorama appliances on PAN-OS
10.2.1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-196954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue related to the
<span class="ph systemoutput">distributord</span> process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-195149</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewall administrators were unable to log in to
the web interface when RADIUS two-factor authentication was used.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-186270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when high availability (HA) was enabled and a
dynamic update schedule was configured, the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process unexpectedly stopped responding during configuration commits.
</div>
</td>
</tr>
</tbody>
</table>
+48
View File
@@ -0,0 +1,48 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">device-client-cert</span> was set to
expire on December 31, 2023. With this fix, the expiration date has
been extended.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-198372</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+103
View File
@@ -0,0 +1,103 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+138
View File
@@ -0,0 +1,138 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 38%" />
<col style="width: 62%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><span class="ph uicontrol">PAN-218285</span></td>
<td class="entry relcol">
Fixed an issue where after switching the SPN by suspending the active
SPN, the forwarding rule was not correctly pointing to the new active
node when moved from 3 rules (TCP/UDP/ICMP) to 1 Layer 3 default rule in
GCP.
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217484</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>rasmgr</a
>
process used 100% CPU due to a maximum duration timer not being set,
which caused the GlobalProtect gateway to be unavailable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><span class="ph uicontrol">PAN-217431</span></td>
<td class="entry relcol">
Fixed an issue with slot 2 DPCs where URL Filtering did not work as
expected after upgrading to PAN-OS 10.1.9.
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><span class="ph uicontrol">PAN-216710</span></td>
<td class="entry relcol">
Fixed an issue with firewalls in active/active HA configurations where
GlobalProtect disconnected when the original suspected active-primary
firewall became active-secondary.
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><span class="ph uicontrol">PAN-216036</span></td>
<td class="entry relcol">
Fixed an issue where the
<span class="ph codeph">all_pktproc</span> process stopped responding,
which caused the firewall to enter a nonfunctional state.
</td>
</tr>
<tr class="row">
<td class="entry"><span class="ph uicontrol">PAN-215823</span></td>
<td class="entry relcol">
Fixed an issue on log collectors where the
<span class="ph uicontrol">reportd</span> process stopped responding.
</td>
</tr>
<tr class="row">
<td class="entry"><span class="ph uicontrol">PAN-215496</span></td>
<td class="entry relcol">
Fixed an issue where 100G ports did not come up with BIDI QSFP modules.
</td>
</tr>
<tr class="row">
<td class="entry"><span class="ph uicontrol">PAN-214406</span></td>
<td class="entry relcol">
Fixed an issue with Elasticsearch where ES tunnels werent started and
were forked incorrectly, which caused them to fail.
</td>
</tr>
<tr class="row">
<td class="entry"><span class="ph uicontrol">PAN-213079</span></td>
<td class="entry relcol">
Fixed an issue with Captive Portal SAML authentication by increasing the
number of retries in the Nginx configuration.
</td>
</tr>
<tr class="row">
<td class="entry">
<span class="ph uicontrol">PAN-212726</span>
<div class="p"><span class="ph uicontrol">PAN-211519</span></div>
</td>
<td class="entry relcol">
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP
ALG when the source NAT translation type was persistent
<span class="ph uicontrol">Dynamic IP And Port</span>.
</td>
</tr>
<tr class="row">
<td class="entry"><span class="ph uicontrol">PAN-211870</span></td>
<td class="entry relcol">
Fixed an issue where path monitoring failure occurred, which caused high
availability failover.
</td>
</tr>
<tr class="row">
<td class="entry"><span class="ph uicontrol">PAN-195912</span></td>
<td class="entry relcol">
Fixed an issue where connections from the firewall to
<span class="ph">Strata Logging Service</span> failed.
</td>
</tr>
</tbody>
</table>
+308
View File
@@ -0,0 +1,308 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 38%" />
<col style="width: 62%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-222035</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where when multiple portals were configured in Prisma
Access deployments, CIE SAML authentication failed on the secondary
portal.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-221068</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall restarted after a failed push from
Panorama, which resulted in autocommit failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-219355</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where disk space became full due to a GPSVC FD leak.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-219333</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a secondary Prisma Access Portal address with
port 8443 did not work.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-218620</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled configuration exports and SCP server
connection testing failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218368</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with incorrect VLAN tagging on Intel based platforms
that occurred when opening a response page from a virtual-wire
subinterface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-218340</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process that affected selective pushes on Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-218267</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a partial commit and push operation from Panorama
to managed firewalls did not work as expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-218046</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Virtual Routers</span> (<span
class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">Virtual Routers</span></span
>) setting was not available when configuring a custom admin role
<span class="ph menucascade"
><span class="ph uicontrol">Device</span
><span class="ph uicontrol">Admin Roles</span></span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-217053</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding after a selective push to multiple device
groups failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215899</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with Panorama appliances in high availability (HA)
configurations where configuration synchronization between the HA
peers failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215767</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a high availability failover, IKE SA
negotiation failed with the error message
<span class="ph systemoutput">INVALID_SPI</span>, which resulted in
temporary loss of traffic over some proxy IDs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215324</b></div>
</td>
<td class="entry relcol">
(<tt class="ph tt"
>PA-5400 Series firewalls with Jumbo Frames enabled only</tt
>) Fixed an issue with CPU throttling and buffer depletion.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215315</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane stopped responding due to ager and
inline packet processing occurring concurrently on different cores for
the same session.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-214463</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IKE rekey negotiation failed with a third-party
vendor and the firewall acting as the initiator received a response
with the VENDOR_ID payload and the error message
<span class="ph systemoutput"
>unexpected critical payload (type 43)</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-213973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process stopped responding during a cleanup of authentication server
context.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-212978</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when executing an
SD-WAN configuration or operational CLI command.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-210366</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where deleting a device group when a selective
configuration push was in progress caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-208240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when attempting to replace an existing
certificate, importing a new certificate with the same name as the
existing certificate failed due to mismatched public and private keys.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+221
View File
@@ -0,0 +1,221 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 38%" />
<col style="width: 62%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-223501</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where diagnostic information for the dataplane in the
dp-monitor.log file was not complete.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-222712</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed a low frequency
DPC restart issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-221984</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where an interface went down after a hotplug event
and was only recoverable by restarting the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-221836</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where improper SNI detection caused incorrect URL
categorization.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-219508</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series, PA-400 Series, PA-1400, PA-3400, and PA-5400 Series
firewalls only</tt
>) Fixed an issue where Bidirectional Forwarding Detection (BFD)
packets experienced a delay in processing, which caused the BFD
connection to flap.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-217489</b></div>
</td>
<td class="entry relcol">
Fixed an issue with firewalls in active/passive high availability (HA)
configurations where the passive firewall MAC flapping occurred when the
passive firewall was rebooted.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-216043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where wifclient stopped responding due to shared memory
corruption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215655</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a multi-dynamic group push, Security
policies with the target device tag was added to a firewall that did
not have the tag.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215066</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where push scope rendering caused the
commit and push or push operation window to hang for several minutes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-214187</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where superreaders were able to execute the
<span class="ph userinput">request restart system</span> CLI command.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-211191</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall restarted after initiating a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mgmtsrvr</a
>
process restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-210661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-210429</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the HTTP service failed to come up on DHCP dataplane interfaces after
rebooting the firewall, which resulted in health-check failure on
HTTP/80 with a 503 error code on the public load balancer.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-195439</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the dataplane interface status went down after
a hotplug event triggered by Azure infrastructure.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-169586</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled log view reports in emails didn't match
the monitor page query result for the same time interval.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+38
View File
@@ -0,0 +1,38 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-229705</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where running the
<span class="ph userinput">show rule-hit-count</span> CLI command on
Panorama displayed the error message
<span class="ph systemoutput"
>Server error : Timed out while getting config lock. Please try
again.</span
>
when attempting to log in or run CLI commands.
</div>
</td>
</tr>
</tbody>
</table>
+103
View File
@@ -0,0 +1,103 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+152
View File
@@ -0,0 +1,152 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248427</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where push operations took longer than expected to
complete.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247403</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
issue where the push scope CLI command took longer than expected,
which caused the web interface to be slow.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-245850</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances in active/passive HA
configurations where the firewalls entered an HA out-of-sync status
and jobs failed on the passive appliance with the error message
<span class="ph systemoutput"
>Could not merged running config from file.</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-244746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes committed on Panorama were not reflected
on the firewall after a successful push.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-235840</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a configuration push from Panorama to
managed firewalls, the status displayed as
<span class="ph uicontrol">None</span> and the push took longer than
expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-228515</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch cluster health status displayed
as yellow or red due to Elasticsearch SSH tunnel flaps.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-216941</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-700 Appliances in Log Collector mode only</tt>)
Fixed an issue where Panorama stopped processing and saving logs.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+103
View File
@@ -0,0 +1,103 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25.062656641604008%" />
<col style="width: 74.93734335839599%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-tdr_dlv_5zb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+134
View File
@@ -0,0 +1,134 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where stale BGP routes were advertised to peers even
when they were not present in the local RIB table.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-228877</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5200 Series, PA-5400 Series, and PA-7000 Series firewalls
only</tt
>) Fixed an issue with out-of-memory (OOM) conditions that caused slot
restarts due to
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_cmd</a
>
consuming more than 300MB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-223852</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
stopped responding when network packet broker or decryption broker
chains failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-223652</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where data was not thread safe and led to concurrent
read/write issues that caused GPSVC to stop working unexpectedly.
</div>
</td>
</tr>
</tbody>
</table>
+260
View File
@@ -0,0 +1,260 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231823</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5916"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5916</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-229865</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where
upgrading to PAN-OS 10.2.5 failed if the firewall was on a PAN-OS 10.1
release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-229705</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where running the
<span class="ph systemoutput">show rule-hit-count</span> CLI command
on Panorama displayed the error message
<span class="ph systemoutput"
>Server error : Timed out while getting config lock. Please try
again.</span
>
when attempting to log in or run CLI commands.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-227639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">ACC</span> displayed an incorrect DNS-base
application traffic byte count.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227523</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address customer and internal bugs (<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2023-38802"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2023-38802</a
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-227376</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory overrun caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the OSPF neighbor state remained in
<span class="ph systemoutput">exstart</span> when the OSPF network had
more than 40 routes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-223787</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-400 Series and PA-1400 Series firewalls only</tt
>) Fixed an issue where commits failed with the error message
<span class="ph systemoutput"
>Error unserializing profile objects failed to handle
CONFIG_UPDATE_START</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-221728</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective pushes did not work after upgrading to
PAN-OS 10.2.4.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process stopped responding at
<span class="ph systemoutput"
>pan_cloud_agent_get_curl_connection()</span
>
and the URL cloud could not be connected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214273</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Elasticsearch logs were not cleared, which caused
the root partition to fill up.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-205015</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where not all users were included in the user group
after an incremental sync between the firewall and the Cloud Identity
Engine.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204868</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where disk utilization was continuously high due to the
log purger not sufficiently reducing the utilization level.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198509</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed due to insufficient CFG memory.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a rare issue where a<span class="ph systemoutput"
>BuildXmlCache</span
>
job failed on the firewall.
</div>
</td>
</tr>
</tbody>
</table>