From bf90a299345076d5a3c1daf80d66af6f8afae7a3 Mon Sep 17 00:00:00 2001 From: Aaron Axvig Date: Mon, 18 May 2026 08:30:46 -0500 Subject: [PATCH] Add some reference files --- reference/PAN-OS/addressed/10.2.13-h1.html | 32 + reference/PAN-OS/addressed/10.2.13-h10.html | 696 +++++++++++ reference/PAN-OS/addressed/10.2.13-h16.html | 740 ++++++++++++ reference/PAN-OS/addressed/10.2.13-h18.html | 909 ++++++++++++++ reference/PAN-OS/addressed/10.2.13-h2.html | 41 + reference/PAN-OS/addressed/10.2.13-h21.html | 153 +++ reference/PAN-OS/addressed/10.2.13-h3.html | 479 ++++++++ reference/PAN-OS/addressed/10.2.13-h4.html | 272 +++++ reference/PAN-OS/addressed/10.2.13-h5.html | 80 ++ reference/PAN-OS/addressed/10.2.13-h7.html | 801 +++++++++++++ reference/PAN-OS/addressed/10.2.13.html | 1188 +++++++++++++++++++ reference/PAN-OS/addressed/10.2.16-h1.html | 255 ++++ reference/PAN-OS/addressed/10.2.16-h4.html | 404 +++++++ reference/PAN-OS/addressed/10.2.16-h6.html | 450 +++++++ reference/PAN-OS/addressed/10.2.16-h7.html | 394 ++++++ reference/PAN-OS/addressed/10.2.16.html | 495 ++++++++ reference/PAN-OS/addressed/12.1.4-h6.html | 41 + 17 files changed, 7430 insertions(+) create mode 100644 reference/PAN-OS/addressed/10.2.13-h1.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h10.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h16.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h18.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h2.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h21.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h3.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h4.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h5.html create mode 100644 reference/PAN-OS/addressed/10.2.13-h7.html create mode 100644 reference/PAN-OS/addressed/10.2.13.html create mode 100644 reference/PAN-OS/addressed/10.2.16-h1.html create mode 100644 reference/PAN-OS/addressed/10.2.16-h4.html create mode 100644 reference/PAN-OS/addressed/10.2.16-h6.html create mode 100644 reference/PAN-OS/addressed/10.2.16-h7.html create mode 100644 reference/PAN-OS/addressed/10.2.16.html create mode 100644 reference/PAN-OS/addressed/12.1.4-h6.html diff --git a/reference/PAN-OS/addressed/10.2.13-h1.html b/reference/PAN-OS/addressed/10.2.13-h1.html new file mode 100644 index 0000000..022a639 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h1.html @@ -0,0 +1,32 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272413
+
+
+ Fixed an issue where device telemetry did not generate logs after + upgrading the firewall. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h10.html b/reference/PAN-OS/addressed/10.2.13-h10.html new file mode 100644 index 0000000..7a23e13 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h10.html @@ -0,0 +1,696 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-289102
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, + PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and + CN-Series firewalls only) Fixed a race condition issue related to predict processing, which + resulted in a dataplane restart and traffic loss. +
+
+
PAN-288930
+
+
+ Fixed an issue where, when ACE was enabled, traffic from cloud + applications randomly matched an incorrect + cloud-apps policy rule. +
+
+
PAN-286475
+
+
+ Fixed an issue where the option to sort sequence numbers was missing + from Filters prefix list in the + advanced routing filters. +
+
+
PAN-285894
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused the firewall to reboot + unexpectedly, and traffic failures occurred. +
+
+
PAN-284908
+
+
+ Fixed an issue where retrieving filenames from OneDrive resulted in a + cache miss. +
+
+
PAN-284116
+
+
+ Fixed an issue where mTLS decryption bypass did not work when the + decryption profile was configured with the maximum TLS version as TLS + 1.3. +
+
+
PAN-284066
+
+
+ Fixed an issue where, after an upgrade, the SNMP polled values for + IF-MIB::ifInErrors displayed a + high number of errors that did not match the values in the CLI show + interface command. +
+
+
PAN-283467
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall unexpectedly rebooted and entered maintenance mode + due to a ctd-agent out-of-memory (OOM) condition. This occurred during + advanced services load testing and a high volume of IoT EAL log + forwarding. +
+
+
PAN-283331
+
+
+ Fixed an issue where selective pushes to managed devices failed when + the User ID Master Device was + configured. +
+
+
PAN-282640
+
+
+ Fixed an issue where custom reports showed incomplete data when + exported in CSV format from Panorama. +
+
+
PAN-281797
+
+
+ Fixed an issue where firewalls became unstable and stopped responding, + which resulted in an OOM condition. +
+
+
PAN-280698
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from + client hello messages that did not fit in a single packet, which + resulted in connection issues. +
+
+
PAN-280505
+
+
+ Fixed an issue where the web interface did not display a message to + commit prior changes before attempting a partial configuration load. +
+
+
PAN-280409
+
+
+ Fixed an issue where the popup window did not appear as expected for + Clientless VPN users. +
+
+
PAN-279706
+
+
+ (M-600 appliances only) Fixed an issue where + Panorama did not update all + panreplay database entries after + performing a commit and full push to all devices. +
+
+
PAN-279336
+
+
+ Fixed an issue where the CLI did not display a message to commit prior + changes before loading a partial configuration. +
+
+
PAN-279176
+
+
+ Fixed an issue where the configuration audit displayed inaccurate + information after partially loading the configuration via the CLI, + which caused the audit to flag the configuration as deleted or + changed. +
+
+
PAN-277755
+
+
+ Fixed an issue that caused the + request system private-data-reset + CLI command to fail. +
+
+
PAN-277617
+
+
+ Fixed an issue where deleting the NTP server address caused a commit + validation error. This occurred when the configuration included both + primary and secondary NTP servers and the secondary server was + removed. +
+
+
PAN-273949
+
+
+ Fixed an issue where the firewall generated the following error + message in the + snmpd + logs: pan_get_keystr_from_cryptod +
+
+ (pan_snmpinterface.c:181): Key X2F1dGhfa2V5 import from cryptod + failed. +
+
+
PAN-271432
+
+
+ Fixed an issue where the firewall was unable to decrypt SSL traffic + when using forward proxy and HSM with an ECDSA signing certificate. +
+
+
PAN-271175
+
+
+ Fixed an issue where the + all_task + process stopped responding with a SIGABRT. +
+
+
PAN-270849
+
+
+ Fixed a memory leak issue related to the + configd + process that occurred when running consecutive commits for multiple + days. +
+
+
PAN-270248
+
+
+ Fixed an issue where the firewall failed to forward logs to a SNMP + trap server if the SNMP manager IP address was unable to be resolved. +
+
+
PAN-270193
+
+
+ Fixed an issue where the Panorama management server changed its + certificate authority (CA) unexpectedly, which caused managed + firewalls to disconnect. +
+
+
PAN-269700
+
+
+ Fixed an issue where commits to service connection firewalls from + Panorama failed. +
+
+
PAN-269499
+
+
+ Fixed an issue where the firewall stopped responding when receiving a + high number of logs. +
+
+
PAN-268708
+
+
+ Fixed an issue where PDF summary and email reports displayed IPv6 + addresses instead of IPv4 addresses. +
+
+
PAN-268614
+
+
+ Fixed an issue on the web interface where, when all rules were + highlighted when a read-only admin user clicked the + Highlight Unused Rules checkbox. +
+
+
PAN-268313
+
+
+ Fixed an issue where the Priority Code Point (PCP) bits in the VLAN + header were not reset to 0 when a packet was received from one Layer 3 + tagged interface and forwarded to another, which resulted in dropped + packets. To use this fix, run the CLI command + set force-vlan-pcp-reset yes and + reboot the firewall. +
+
+
PAN-268017
+
+
+ Fixed an issue where the IP address-to-user mapping timeout was + triggered and the Inactivity TTL was refreshed unexpectedly +
+
+
PAN-265782
+
+
+ Fixed an issue on Panorama where, after you enabled multihop in a BFD + profile, you were unable to disable it via the web interface. +
+
+
PAN-264883
+
+
+ (PA-7080 appliances with LPCs only) Fixed an + issue where syslog forwarding over TCP stopped after upgrading. +
+
+
PAN-264040
+
+
+ Fixed an issue where AAAA DNS queries went out even when + IPv6 firewalling was disabled. +
+
+
PAN-262593
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome + web browser on Secure Web Gateway (SWG) nodes. +
+
+
PAN-261429
+
+
+ Fixed an issue where the + show auth radius-require-msg-authentic + command CLI displayed no output. +
+
+
PAN-260132
+
+
+ Fixed an issue where secondary IP addresses with a /32 prefix + configured on Layer 3 interfaces were not reachable in FRR mode. +
+
+
PAN-257117
+
+
+ Fixed an issue where CSV or PDF exports of zones did not contain all + zones. +
+
+
PAN-255914
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where a newly bootstrapped firewall required a + management server restart, relicensing, or license push from Panorama + to invoke the device certificate. +
+
+
PAN-255759
+
+
+ Fixed an issue where the firewall was unable to match HIP data with + the correct anti-malware object for Windows Defender. +
+
+
PAN-255654
+
+
+ Fixed an issue where, when QoS was enabled on aggregate interfaces, + the maximum aggregate interface throughput was capped, which limited + network traffic. This occurred even with default QoS settings and no + configured egress max-bandwidth. +
+
+
PAN-253187
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the class of service (CoS) priority bit was not modified, causing + access points to lose connectivity to the wireless controller when + traffic was routed through the firewall. +
+
+
PAN-241230
+
+
+ Fixed an issue where the SNMP get request status value for Panorama + connections was incorrect. +
+
+
PAN-224729
+
+
+ Fixed an issue where you were unable to create duplicate entries in + Advanced Routing AS path prepend in the BGP filter route map. +
+
+
PAN-224020
+
+
+ Fixed an issue where CIE validation checks on the firewall prevented + configuration pushes from Panorama, which resulted in commit failures + during new firewall deployment. This occurred when a template with an + Authentication Profile with the + Authentication Type as + Cloud Authentication Service was + pushed to a newly deployed firewall without internet access or without + a device certificate. +
+
+
PAN-222307
+
+
+ (M-600 appliances only) Fixed an issue where + the + reportd + process stopped responding. +
+
+
PAN-212182
+
+
+ Fixed an issue where TLS 1.3 connections failed if the server sent a + certificate request after sending its certificate. +
+
+
PAN-201298
+
+
+ Fixed an issue where unknown TCP traffic caused errors and high shared + memory usage. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h16.html b/reference/PAN-OS/addressed/10.2.13-h16.html new file mode 100644 index 0000000..0a2787c --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h16.html @@ -0,0 +1,740 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-298907
+
+
+ Fixed an issue on PA-VM in AWS where, in a two-arm deployment + integrated with Gateway Load Balancer (GWLB), the firewall did not + preserve the GENEVE source port for internet traffic, resulting in + increased latency. The fix ensures the firewall preserves the outer + UDP source port of GENEVE encapsulation when sending traffic back to + GWLB. +
+
+
PAN-298505
+
+
+ Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, + the vsys ID changed in sequence, causing autocommit failures with + validation errors. This occurred when the multi-vsys firewall had + virtual systems created and pushed from Panorama, and the vsys ID was + not in a correct sequence because the unused vsys was deleted from + Panorama and pushed to devices. +
+
+
PAN-296519
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an + associated error in + Wifclient + caused the entire pool to close, which resulted in a complete + disconnection. +
+
+
PAN-296478
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10, + GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute + JavaScript links, resulting in an authorization error. This occurred + because the firewall was incorrectly injecting text into URLs when + JavaScript buttons or dropdown menus were clicked within the + Clientless VPN portal. +
+
+
PAN-296261
+
+
+ Fixed an issue where scheduled custom reports generated through + Panorama were blank (Monitor > Reports) due to a malformed JSON response from the + reportd + process. +
+
+
PAN-295342
+
+
+ Fixed an issue where the + pan_comm + process stopped responding due to insufficient time allocated to read + file descriptors when processing long messages. +
+
+
PAN-293879
+
+
+ Fixed an issue on the firewall where the VM monitor source remained in + the Getting All status, which + prevented dynamic address groups from updating IP addresses for new + EC2 instances. This issue occurred due to a race condition where two + threads that simultaneously retrieved IP address tag information from + AWS VM monitoring sources became stuck while reading the XML file. +
+
+
PAN-293673
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM + condition caused by a scheduled log export using FTP to an external + FTP server. +
+
+
PAN-292539
+
+
+ (CN-Series firewalls only) Fixed an issue where + the firewall generated incomplete or corrupted tech support files + (TSF) due to high disk usage on the management plane. +
+
+
PAN-291174
+
+
+ Fixed an issue where Real Time Streaming Protocol (RTSP) video streams + did not work when connected through GlobalProtect due to the firewall + blocking 200 OK responses. This occurred because of incorrect NAT + translations for the 200 OK message from the server. +
+
+
PAN-290996
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS + (Connections Per Second) per vsys on firewalls after upgrading to + PAN-OS 11.1.6-h3, even when active connections were present. +
+
+
PAN-290088
+
+
+ Fixed an issue where a memory leak occurred related to the + configd + process when pushing configurations from Panorama to a firewall. This + occurred when the configurations contained shared policy rules. +
+
+
PAN-289239
+
+
+ Fixed an issue on Panorama where a new virtual system (vsys) was + automatically created with the name of a device group. +
+
+
PAN-288158
+
+
+ (VM-Series firewalls) only Fixed an issue where + the firewall became inaccessible via the web interface and SSH and + remained in an initializing state. +
+
+
PAN-287842
+
+
+ Fixed an issue where the + comm + process stopped responding due to missing heartbeats, which resulted + in a system alert and HA communication loss on slot1. +
+
+
PAN-287818
+
+
+ Fixed an issue where sessions timed out sooner than expected due to + the pan_proxy_accumulation + _restore_timeout not initiating + when the accumulationsession_init + failed. +
+
+
PAN-287734
+
+
+ Fixed an issue where the error message + Scan ERR: Internal Err 1002 was + generated unexpectedly when WIF shared memory use was high. +
+
+
PAN-287035
+
+
+ Fixed an issue where, when an application stopped responding, a large + file was created in the /opt/panlogs directory, which caused the + partition to fill up. +
+
+
PAN-287023
+
+
+ Fixed an issue where a large number of logs caused the + logrcvr + process to stop responding. +
+
+
PAN-286615
+
+
+ Fixed an issue where the firewall double-freed shared memory when the + shared memory usage reached 100% when sending large payloads. This + occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced + WildFire (AWF), or Advanced URL Filtering were enabled. +
+
+
PAN-284003
+
+
+ Fixed an issue where clients did not receive a valid response when + when searching a website due to a compression error. +
+
+
PAN-286231
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to + multiple firewalls with different base configurations resulted in + configuration corruption, which caused the firewall to go down. +
+
+
PAN-279901
+
+
+ An issue was fixed where the firewall dropped fragmented TLS + ClientHello packets, which blocked access to certain websites. This + occurred because the packets arrived truncated, in varying sizes and + orders, and the firewall's heuristics failed to handle them correctly. +
+
+ To enable this fix, run: + debug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279500
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric + routing environments if the firewall did not see server-to-client + (s2c) packets of the TLS handshake. +
+
+ To use this fix, run the following CLI command: + debug dataplane set ssl-decrypt accumulate-client-hello + asym-disable yes. +
+
+
PAN-278288
+
+
+ Fixed an issue where IPv6 BGP peering established between virtual + routers even without dataplane connectivity. This occurred because the + firewall used the kernel for lookups instead of the dataplane. +
+
+ To use this fix, run the following CLI command: + set system setting loopback-workaround enable +
+
+
PAN-276795
+
+
+ Fixed an issue where the GlobalProtect client displayed an error + message when you clicked + Check Now and + Preferred Releases and + Base Releases were unchecked (Device > Software). +
+
+
PAN-272812
+
+
+ Fixed an issue where SNMP monitoring of tunnel interfaces displayed + zero values for received bytes and packets. +
+
+
PAN-271701
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and + Enhanced Application Log stopped working due to incorrect memory usage + accounting, which caused memory usage to remain at 99% after an + extended period of time. +
+
+
PAN-266653
+
+
+ Fixed an issue where unexpected path monitor failures caused the + firewall to stop responding. +
+
+
PAN-267444
+
+
+ Fixed an issue where large file downloads or uploads failed or + remained in an incomplete state when using DLP HTTP2 mirror mode. +
+
+
PAN-266279
+
+
+ Fixed an issue on Panorama where the default version of IKE gateway + was not set to IKEv2 only mode, which caused VPN establishment issues + if the firewall recognized a new configuration as IKEv1. +
+
+
PAN-261825
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or + Advanced URL Filtering were enabled. This occurred when the payload + size was greater than 3.5 KB. +
+
+
PAN-259741
+
+
+ Fixed an issue where the firewall dropped GRE keepalive packets that + were encapsulated under another GRE tunnel. +
+
+
PAN-259076
+
+
+ Fixed an issue where the firewall displayed an OCSP/CRL check failure + when accessing websites. +
+
+
PAN-255860
+
+
+ (PA-5200 firewalls only) Fixed an issue where + the + all_pktproc + process stopped responding when the firewall was under a heavy traffic + load. +
+
+
PAN-255619
+
+
+ Fixed an intermittent issue where file downloads from websites failed + when decrypting HTTP/2 traffic. +
+
+
PAN-253485
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration + failed on the active firewall with the error + op command for client dagger timed out as client is not + available. +
+
+
PAN-250146
+
+
+ Fixed an issue on the web interface where templates incorrectly showed + that telemetry was enabled when it was not enabled. With this fix, the + telemetry setting is not displayed in the template on the web + interface. +
+
+
PAN-247575
+
+
+ Fixed an issue where the error message + import of failed. Please check the validity of the key pair and try + again + for unmatched keys for EC certificates. +
+
+
PAN-245064
+
+
+ (Multi-vsys firewalls only) Fixed an issue + where commits failed on the firewall after selecting + Export or push device config bundle + on Panorama and a force push was required. +
+
+
PAN-242602
+
+
+ Fixed an issue where GlobalProtect clients experienced slow SMB-V3 + download throughput when passing through a Prisma IPSec tunnel and the + firewall and the SMB-V3 session owner dataplane was the same as the + IPSec-ESP tunnel on the multi-dataplane firewall. +
+
+
PAN-241536
+
+
+ Fixed an issue on Panorama where admin users with the Custom Panorama + Admin role were unable to add, edit, or delete route filters under + Routing Profiles. +
+
+
PAN-231386
+
+
+ Fixed an issue where the + configd + process stopped responding during certificate verification. +
+
+
PAN-220293
+
+
+ Fixed an issue where the firewall management plane could not display + BGP peer details when using the CLI command + show advanced-routing bgp peer detail logical-router. This was due to the + bgp_frr.py script failing to + parse the IPv6 address family section of the + show ip bgp neighbors json + output. +
+
+
PAN-202905
+
+
+ Fixed an issue on the firewall web interface where the + Next Hop value was not displayed in + the static route configuration, the + admin-dist values were empty, and + the path-monitor parameters were not listed in the management server + web interface when the firewall was configured in FRR mode. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h18.html b/reference/PAN-OS/addressed/10.2.13-h18.html new file mode 100644 index 0000000..f580648 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h18.html @@ -0,0 +1,909 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-304756
+
+
+ Fixed an issue on Panorama where, after you disabled the shared + optimization feature, a full configuration push to multi-vsys devices + caused a validation error. +
+
+
PAN-299354
+
+
+ Added a CLI command to adjust the local pool cache size of the + detector_threat + process to address an issue where the local-reuse memory pool borrowed + from the global pool, which impacted performance during session + deletion. +
+
+
PAN-299228
+
+
+ Fixed an issue where a session process consumed excessive CPU + resources, even when Data Loss Prevention (DLP) was not enabled. This + occurred due to the active threat list being iterated twice when + active threats were present in the session. +
+
+
PAN-298907
+
+
+ Fixed an issue on PA-VM in AWS where, in a two-arm deployment + integrated with Gateway Load Balancer (GWLB), the firewall did not + preserve the GENEVE source port for internet traffic, resulting in + increased latency. The fix ensures the firewall preserves the outer + UDP source port of GENEVE encapsulation when sending traffic back to + GWLB. +
+
+
PAN-298505
+
+
+ Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, + the vsys ID changed in sequence, causing autocommit failures with + validation errors. This occurred when the multi-vsys firewall had + virtual systems created and pushed from Panorama, and the vsys ID was + not in a correct sequence because the unused vsys was deleted from + Panorama and pushed to devices. +
+
+
PAN-297775
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release, + the Visible Virtual System field referenced the vsys name instead of + the vsys ID, which caused inter-vsys routing to fail. This occurred + when a vsys display name matched one of the vsys IDs. If you're using + a multivsys environment, you must upgrade your firewalls to a fixed + PAN-OS version. The best practice is to upgrade both the firewalls and + Panorama to a fixed PAN-OS version. +
+
+ If you don't upgrade Panorama to a fixed version, you'll encounter + PAN-245064, where a commit on a multivsys firewall fails with the + message + vsys name should end with a number vsys is invalid + after you + Export or push device config bundle + from 11.1.1 Panorama. +
+
+ After you upgrade Panorama to a fixed version, you'll encounter + PAN-214177, which causes an + Export or Push device config bundle + from Panorama to the firewall to fail. The workaround for PAN-214177 + is to first push only the template configuration and then push the + device group configurations. +
+
+
PAN-296519
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an + associated error in + Wifclient + caused the entire pool to close, which resulted in a complete + disconnection. +
+
+
PAN-296478
+
+
+ Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10, + GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute + JavaScript links, resulting in an authorization error. This occurred + because the firewall was incorrectly injecting text into URLs when + JavaScript buttons or dropdown menus were clicked within the + Clientless VPN portal. +
+
+
PAN-296261
+
+
+ Fixed an issue where scheduled custom reports generated through + Panorama were blank (Monitor > Reports) due to a malformed JSON response from the + reportd + process. +
+
+
PAN-295342
+
+
+ Fixed an issue where the + pan_comm + process stopped responding due to insufficient time allocated to read + file descriptors when processing long messages. +
+
+
PAN-293879
+
+
+ Fixed an issue on the firewall where the VM monitor source remained in + the Getting All status, which + prevented dynamic address groups from updating IP addresses for new + EC2 instances. This issue occurred due to a race condition where two + threads that simultaneously retrieved IP address tag information from + AWS VM monitoring sources became stuck while reading the XML file. +
+
+
PAN-293673
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM + condition caused by a scheduled log export using FTP to an external + FTP server. +
+
+
PAN-292539
+
+
+ (CN-Series firewalls only) Fixed an issue where + the firewall generated incomplete or corrupted tech support files + (TSF) due to high disk usage on the management plane. +
+
+
PAN-291174
+
+
+ Fixed an issue where Real Time Streaming Protocol (RTSP) video streams + did not work when connected through GlobalProtect due to the firewall + blocking 200 OK responses. This occurred because of incorrect NAT + translations for the 200 OK message from the server. +
+
+
PAN-291172
+
+
+ Fixed an issue where administrators were unable to gather path + monitoring failure information when troubleshooting high dataplane CPU + utilization. +
+
+
PAN-291009
+
+
+ Fixed an issue where, after a web server returned a 401 or 403 error, + the firewall was unable to decrypt HTTP/2 traffic, and the firewall + rejected all subsequent streams from the client. +
+
+
PAN-290996
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS + (Connections Per Second) per vsys on firewalls after upgrading to + PAN-OS 11.1.6-h3, even when active connections were present. +
+
+
PAN-290665
+
+
+ Fixed an issue with firewalls enabled with Security profiles where + certain traffic conditions caused high dataplane CPU utilization and + packet buffer exhaustion, which caused LACP flapping conditions. +
+
+
PAN-290088
+
+
+ Fixed an issue where a memory leak occurred related to the + configd + process when pushing configurations from Panorama to a firewall. This + occurred when the configurations contained shared policy rules. +
+
+
PAN-289239
+
+
+ Fixed an issue on Panorama where a new virtual system (vsys) was + automatically created with the name of a device group. +
+
+
PAN-288158
+
+
+ (VM-Series firewalls) only Fixed an issue where + the firewall became inaccessible via the web interface and SSH and + remained in an initializing state. +
+
+
PAN-287842
+
+
+ Fixed an issue where the + comm + process stopped responding due to missing heartbeats, which resulted + in a system alert and HA communication loss on slot1. +
+
+
PAN-287818
+
+
+ Fixed an issue where sessions timed out sooner than expected due to + the pan_proxy_accumulation + _restore_timeout not initiating + when the accumulationsession_init + failed. +
+
+
PAN-287734
+
+
+ Fixed an issue where the error message + Scan ERR: Internal Err 1002 was + generated unexpectedly when WIF shared memory use was high. +
+
+
PAN-287035
+
+
+ Fixed an issue where, when an application stopped responding, a large + file was created in the /opt/panlogs directory, which caused the + partition to fill up. +
+
+
PAN-287023
+
+
+ Fixed an issue where a large number of logs caused the + logrcvr + process to stop responding. +
+
+
PAN-286615
+
+
+ Fixed an issue where the firewall double-freed shared memory when the + shared memory usage reached 100% when sending large payloads. This + occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced + WildFire (AWF), or Advanced URL Filtering were enabled. +
+
+
PAN-284003
+
+
+ Fixed an issue where clients did not receive a valid response when + when searching a website due to a compression error. +
+
+
PAN-286231
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to + multiple firewalls with different base configurations resulted in + configuration corruption, which caused the firewall to go down. +
+
+
PAN-279901
+
+
+ An issue was fixed where the firewall dropped fragmented TLS + ClientHello packets, which blocked access to certain websites. This + occurred because the packets arrived truncated, in varying sizes and + orders, and the firewall's heuristics failed to handle them correctly. +
+
+ To enable this fix, run: + debug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279500
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric + routing environments if the firewall did not see server-to-client + (s2c) packets of the TLS handshake. +
+
+ To use this fix, run the following CLI command: + debug dataplane set ssl-decrypt accumulate-client-hello + asym-disable yes. +
+
+
PAN-279364
+
+
+ (VM-Series firewalls with multiple NICs only) + Fixed an issue were the queue count in the task dump displayed an + incorrect number of queues for SR-IOV interfaces due to the queue + mapping logic incorrectly using a non-multi-NIC function. +
+
+
PAN-279191
+
+
+ Fixed an issue where a GlobalProtect gateway stopped responding when + handling HTTP/1.1 traffic with web inspection enabled. +
+
+
PAN-278288
+
+
+ Fixed an issue where IPv6 BGP peering established between virtual + routers even without dataplane connectivity. This occurred because the + firewall used the kernel for lookups instead of the dataplane. +
+
+ To use this fix, run the following CLI command: + set system setting loopback-workaround enable +
+
+
PAN-276795
+
+
+ Fixed an issue where the GlobalProtect client displayed an error + message when you clicked + Check Now and + Preferred Releases and + Base Releases were unchecked (Device > Software). +
+
+
PAN-272812
+
+
+ Fixed an issue where SNMP monitoring of tunnel interfaces displayed + zero values for received bytes and packets. +
+
+
PAN-271701
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and + Enhanced Application Log stopped working due to incorrect memory usage + accounting, which caused memory usage to remain at 99% after an + extended period of time. +
+
+
PAN-268168
+
+
+ Fixed an issue where uploading files that were 5GB or larger to Google + Drive or YouTube failed when a decryption policy rule for http2 was + enabled. +
+
+
PAN-267444
+
+
+ Fixed an issue where large file downloads or uploads failed or + remained in an incomplete state when using DLP HTTP2 mirror mode. +
+
+
PAN-266653
+
+
+ Fixed an issue where unexpected path monitor failures caused the + firewall to stop responding. +
+
+
PAN-266279
+
+
+ Fixed an issue on Panorama where the default version of IKE gateway + was not set to IKEv2 only mode, which caused VPN establishment issues + if the firewall recognized a new configuration as IKEv1. +
+
+
PAN-261825
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or + Advanced URL Filtering were enabled. This occurred when the payload + size was greater than 3.5 KB. +
+
+
PAN-259741
+
+
+ Fixed an issue where the firewall dropped GRE keepalive packets that + were encapsulated under another GRE tunnel. +
+
+
PAN-259076
+
+
+ Fixed an issue where the firewall displayed an OCSP/CRL check failure + when accessing websites. +
+
+
PAN-255860
+
+
+ (PA-5200 firewalls only) Fixed an issue where + the + all_pktproc + process stopped responding when the firewall was under a heavy traffic + load. +
+
+
PAN-255619
+
+
+ Fixed an intermittent issue where file downloads from websites failed + when decrypting HTTP/2 traffic. +
+
+
PAN-253485
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration + failed on the active firewall with the error + op command for client dagger timed out as client is not + available. +
+
+
PAN-250146
+
+
+ Fixed an issue on the web interface where templates incorrectly showed + that telemetry was enabled when it was not enabled. With this fix, the + telemetry setting is not displayed in the template on the web + interface. +
+
+
PAN-247575
+
+
+ Fixed an issue where the error message + import of failed. Please check the validity of the key pair and try + again + for unmatched keys for EC certificates. +
+
+
PAN-245064
+
+
+ (Multi-vsys firewalls only) Fixed an issue + where commits failed on the firewall after selecting + Export or push device config bundle + on Panorama and a force push was required. +
+
+
PAN-242602
+
+
+ Fixed an issue where GlobalProtect clients experienced slow SMB-V3 + download throughput when passing through a Prisma IPSec tunnel and the + firewall and the SMB-V3 session owner dataplane was the same as the + IPSec-ESP tunnel on the multi-dataplane firewall. +
+
+
PAN-241536
+
+
+ Fixed an issue on Panorama where admin users with the Custom Panorama + Admin role were unable to add, edit, or delete route filters under + Routing Profiles. +
+
+
PAN-231386
+
+
+ Fixed an issue where the + configd + process stopped responding during certificate verification. +
+
+
PAN-220293
+
+
+ Fixed an issue where the firewall management plane could not display + BGP peer details when using the CLI command + show advanced-routing bgp peer detail logical-router. This was due to the + bgp_frr.py script failing to + parse the IPv6 address family section of the + show ip bgp neighbors json + output. +
+
+
PAN-202905
+
+
+ Fixed an issue on the firewall web interface where the + Next Hop value was not displayed in + the static route configuration, the + admin-dist values were empty, and + the path-monitor parameters were not listed in the management server + web interface when the firewall was configured in FRR mode. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h2.html b/reference/PAN-OS/addressed/10.2.13-h2.html new file mode 100644 index 0000000..0b0f4b5 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h2.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-259351
+
+
+ A fix was made to address + CVE-2024-3393. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h21.html b/reference/PAN-OS/addressed/10.2.13-h21.html new file mode 100644 index 0000000..995af6b --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h21.html @@ -0,0 +1,153 @@ + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
+
+
Fixes were made to address the following CVEs:
+ +
+
PAN-269254
+
+
+ Fixed an issue where high CPU utilization caused GlobalProtect VPN + tunnels to flap, users to be disconnected, and the CLI to become + unresponsive. This occurred when a large number of GlobalProtect users + were actively processing application traffic. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h3.html b/reference/PAN-OS/addressed/10.2.13-h3.html new file mode 100644 index 0000000..cf4f035 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h3.html @@ -0,0 +1,479 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-274570
+
+
+ Fixed an issue where the + devsrvr + process restarted after a failed commit due to an invalid memory + access. +
+
+
PAN-273994
+
+
+ A fix was made to address + CVE-2025-0111. +
+
+
PAN-273971
+
+
+ A fix was made to address + CVE-2025-0108. +
+
+
PAN-273278
+
+
+ A fix was made to address + CVE-2025-0109. +
+
+
PAN-273215
+
+
+ Fixed an issue where a syntax error in the index generation script + caused a high management plane CPU load after upgrading. +
+
+
PAN-273021
+
+
+ Fixed an issue where 25G port links did not come up due to a change in + the handling of 25G DAC modules. +
+
+
PAN-271926
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC + error when the firewall was configured to decrypt and inspect TLS + traffic. +
+
+
PAN-270549
+
+
+ Fixed an issue where some TLS connections were not handled correctly, + which led to instability in the dataplane. +
+
+
PAN-269899
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected when querying for device tags. +
+
+
PAN-269731
+
+
+ Fixed an issue where Panorama did not display logs from firewalls + after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) + getting restarted continuously. +
+
+
PAN-269624
+
+
+ Fixed an issue where GlobalProtect clients failed to connect with the + error message + The device or feature requires a GlobalProtect subscription + license. +
+
+
PAN-268972
+
+
+ Fixed an issue where Panorama was slower than expected when using a + high number of device group tags in a non-shared context. +
+
+
PAN-268909
+
+
+ Fixed an issue where IP address tags were removed from firewalls after + a management server or + useridd + process restart. This occurred when a Panorama serial-number based + configuration was used for User-ID redistribution. +
+
+
PAN-268727
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy + was enabled and header insertion modified packets. +
+
+
PAN-268319
+
+
+ Fixed an issue where + Receive Time and + Time Generated were not visible as + attributes in the Filter Builder for + system logs and URL filtering logs. +
+
+
PAN-268260
+
+
+ Fixed an issue on hardware firewalls where, when SSL decryption was + enabled and Client Hello messages spanned multiple TCP segments, some + SSL decrypted sessions failed. +
+
+
PAN-267781
+
+ Fixed an issue where Panorama did not display the Source Dynamic Address + Group. +
+
PAN-267671
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to the + all_task + process restarting with an OOM condition due to a memory leak on the + reportd + process. +
+
+
PAN-267001
+
+
+ Fixed an issue where multicast streams were unstable with ECMP and + dropped every 30 seconds. +
+
+
PAN-266312
+
+
+ Fixed an issue where BFD sessions took longer than expected to + establish after an HA failover due to BGP. +
+
+
PAN-265179
+
+
+ Fixed an issue where a kernel race condition caused the firewall to + reboot with a kernel panic. +
+
+
PAN-261739
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port + counters read from MAC. +
+
PAN-259002
+
+
+ Fixed an issue where frequent external dynamic list updates caused the + configd + process to restart. +
+
+
PAN-256051
+
+
+ Fixed an issue on the firewall where enabling flow basic caused the + firewall to stop responding due to a + masterd + process restart. +
+
+
PAN-249597
+
+
+ Fixed an issue where the Policy page + on the Panorama web interface was slower than expected when a device + group had a large number of managed devices. +
+
+
PAN-246949
+
+
+ Fixed an issue where custom admin users were not able to click + OK in the push scope selection + window when device group or template were disabled under commit in the + admin roles. +
+
+
PAN-240739
+
+
+ Fixed an issue where the ECMP FIB update on the dataplane didn't clear + the pending change flag, which caused the next non-ECMP FIB update to + miss the latest generation ID and age out after 5 minutes +
+
+
PAN-225213
+
+
+ Fixed an issue where + Push All Changes displayed changes + that were already committed in the push scope for another device group + after performing a selective commit and selective push to the first + device group. +
+
+
PAN-215038
+
+
+ Fixed an issue where the output of the + request logging-service-forwarding status + CLI command did not display the correct information after successfully + onboarding a firewall to Cloud Delivered Licensing (CDL). +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h4.html b/reference/PAN-OS/addressed/10.2.13-h4.html new file mode 100644 index 0000000..9e5a75e --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h4.html @@ -0,0 +1,272 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-279604
+
+
+ Fixed an issue where scheduled SaaS application usage reports were + generated incorrectly, and the login page was displayed instead of the + report content. +
+
+
PAN-276822
+
+
+ Fixed an issue where the packet buffer size increased significantly + when WildFire File Forwarding was continued after a threat detection + and then canceled. +
+
+
PAN-274592
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the firewall did not fail over when the active firewall + experienced data plane issues. +
+
+
PAN-273277
+
+ Fixed an issue where GlobalProtect clients on macOS devices were + prompted to enter their username and password for Kerberos SSO + authentication. +
+
PAN-273153
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to excessive polling of the + MonitorDirect.getTasks API by the + Task Manager. +
+
+
PAN-272006
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump + as a large core when the CPLD (Complex Programmable Logic Device) sent + a Non-Maskable Interrupt (NMI) to the CPU. +
+
+
PAN-271301
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments with + GWLB integrated only) Fixed an issue where DNS queries timed out when overlay routing was + enabled. +
+
+
PAN-268489
+
+
Fixed a Threat log PCAP ID overwrapping issue.
+
+
PAN-267704
+
+
+ Fixed an issue where the firewall did not send an ICMP error packet to + Envoy when the MSS was exceeded +
+
+
PAN-267660
+
+
+ Fixed an issue where UserID stopped working when the + show object registered user CLI + command was used with start-point and limit options. +
+
+
PAN-265399
+
+
+ Fixed an issue where DNS queries for uppercase internal domain (SRV + record) timed out when DNS Security was enabled. +
+
+
PAN-264762
+
+
+ Fixed an issue where the firewall showed the status of SFP+ interfaces + as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was + connected. +
+
+
PAN-263465
+
+
+ Fixed an issue where the + logrcvr + process stopped responding due to a memory leak and buffer overrun. +
+
+
PAN-261074
+
+
+ Fixed an issue where the firewall delayed video file transfers over + SMB when Exclude Video Traffic from + the Tunnel feature was enabled and no applications were added to the + list. +
+
+
PAN-260827
+
+
+ Fixed an issue where the firewall consumed excessive CPU while + processing traffic for a workload running on a GKE cluster, which + caused reduced throughput. +
+
+
PAN-253921
+
+
+ Fixed an issue where the firewall displayed the following error + message: + critical userid register 0 fail to integrate the update of + registered ip addresses since 2 seconds ago; critical system log + alerts observed. +
+
+
PAN-253213
+
+
+ Fixed an issue where the firewall sent HIP notifications every time it + received a HIP report instead of every two hours. +
+
+
PAN-246304
+
+
+ Fixed an issue on Panorama where commits failed due to a timeout in + the + sysd + process during decryption. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h5.html b/reference/PAN-OS/addressed/10.2.13-h5.html new file mode 100644 index 0000000..a528f57 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h5.html @@ -0,0 +1,80 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-279746
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client + Hello arrived at the firewall in multiple out-of-order segments and + the traffic was not subject to SSL decryption. +
+
+
PAN-268815
+
+
+ Fixed an issue that caused the firewall to reboot due to the + wifclient exiting multiple times + when using IoT Security. +
+
+
PAN-268800
+
+
+ Fixed an issue where a large number of logs caused the + logrcvr + process to stop responding. +
+
+
PAN-268705
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP + traffic after upgrading to PAN-OS 10.1.14. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13-h7.html b/reference/PAN-OS/addressed/10.2.13-h7.html new file mode 100644 index 0000000..27427ca --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13-h7.html @@ -0,0 +1,801 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-286255
+
+
+ Fixed an issue where, when the firewall received an unexpected + termination request for SSL sessions, the dataplane experienced a slow + buffer resource leak. +
+
+
PAN-283813
+
+
+ Fixed an issue on Panorama where the web interface performance was + slower than usual when retrieving read-only configurations from + Panorama. +
+
+
PAN-282394
+
+
+ Fixed an issue where a firewall was only able to display a maximum of + 14 permitted IP addresses from a Panorama Template Variable. +
+
+
PAN-282236
+
+
+ Fixed an issue where large IPv6 packets were reassembled incorrectly + on the firewall when the packets arrived fragmented over an IPv4 + tunnel. +
+
+
PAN-279621
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward + traffic was run. +
+
+
PAN-279400
+
+
+ Fixed an issue where, when + Restrict Certificate Extensions was + enabled on decryption profiles, the basic constraints extension was + overwritten incorrectly. +
+
+
PAN-278150
+
+
+ Fixed an issue where the firewall removed the Authentication Key + Identifier (AKID) from the certificate during SSL decryption, which + caused Python 3.13 to fail with a certificate verification error. +
+
+
PAN-277417
+
+
+ Fixed an memory leak issue related to TLS inbound decryption. +
+
+
PAN-277234
+
+
+ Fixed an issue where a device group import resulted in a Security + policy rule being created with + Application set to + none. +
+
+
PAN-277147
+
+
+ Fixed an issue where daily scheduled reports were not generated and + emailed. +
+
+
PAN-276678
+
+
+ Fixed an issue where Panorama became unresponsive while performing a + dynamic address update without a lock. +
+
+
PAN-275077
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain + URLs as Alert instead of taking a Sinkhole action, even when + configured to Sinkhole malicious DNS domains. +
+
+
PAN-274797
+
+
+ Fixed an issue where a DPC on slot 3 failed intermittently due to the + pktlog_forwarding + process restarting, which resulted in an unexpected HA failover. +
+
+
PAN-274726
+
+
+ Fixed an issue where Wildfire signature generation was enabled on all + nodes in a cluster instead of only the active node. +
+
+
PAN-273964
+
+
+ Fixed an issue where SNMP scans to a firewall timed out after + upgrading to a PAN-OS 10.2 release. +
+
+
PAN-273453
+
+
+ Fixed an issue where restarting the firewall did not initiate an + autocommit job, which caused the firewall to stop responding and the + HA interface to go down. +
+
+
PAN-273141
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file + transfer download throughput when passing through an IPSec tunnel. +
+
+
PAN-272959
+
+
+ Fixed an issue where the firewall generated BGP update packets larger + than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames + were enabled globally. +
+
+
PAN-272395
+
+
+ Fixed an issue where informational logs caused the + distributord + process log file to be frequently overwritten. +
+
+
PAN-272175
+
+
+ Fixed an issue where session rematch caused ACE cloud application + traffic to match the wrong policy. +
+
+
PAN-271425
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue with SSL inbound decryption on firewalls on a vwire + setup with asymmetric routing. +
+
+ To use this fix, enter the CLI command + set system setting ssl-decrypt ha-vwire-mac-learn global yes on both firewalls in an HA pair. +
+
+
PAN-271184
+
+
+ Fixed an issue where Device Telemetry failed due to an issue with the + encoding of characters in the log file path. +
+
+
PAN-269956
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused internal path monitor + failures. +
+
+
PAN-269677
+
+
+ Fixed an issue where Panorama did not check for a NULL pointer when + querying logs, which caused logs to not display on the web interface. +
+
+
PAN-269291
+
+
+ Fixed an issue where the scheduled report generation script did not + return debug information. +
+
+
PAN-269106
+
+
+ Fixed an issue where the wifclient stopped responding during server + certificate verification for MICA gRPC connections and caused the + dataplane to restart when using a cloud-based ML detection engine + (MICA). On certain platforms, this caused the firewall to reboot + periodically. +
+
+
PAN-269052
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile + even though the Security policy rule did not have a URL filtering + profile configured. +
+
+
PAN-269027
+
+
+ Fixed an issue related to external dynamic lists that caused commit + times on the firewall to be higher than expected. +
+
+
PAN-268951
+
+
+ Fixed a CPS counter query issue that caused SNMP polling timeouts on + the firewall. +
+
+
PAN-268118
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where, + after a failover, irrelevant routing FIB entries were seen in the + routing table on the newly active firewall. +
+
+
PAN-267707
+
+
+ Fixed an issue where BFD sessions did not come up even when BGP + peering was established. +
+
+
PAN-267097
+
+
+ Fixed an issue where the replay database size increased significantly + due to local and special configurations not being purged after + commits. +
+
+
PAN-266900
+
+
+ Fixed an issue on the Panorama web interface where you were unable to + click OK after selecting an install + package type and file from the dropdown and selecting a firewall. +
+
+
PAN-265791
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused the dataplane to go down. +
+
+
PAN-265646
+
+
+ Fixed an issue where the config lock icon was not visible for a custom + role-based admin when a Superuser admin had acquired the config lock. +
+
+
PAN-264708
+
+
+ Fixed an issue where a selective push was blocked when a configuration + load was done. +
+
+
PAN-264678
+
+
+ Fixed an issue where + Preview Changes did not display + configuration changes in + Commit and push > Push Scope. +
+
+
PAN-264169
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where the firewall sent correlated event logs to the syslog server + using the management interface instead of the log interface. +
+
+
PAN-263654
+
+
+ Fixed an issue where multiple DNS responses with different CNAME + values caused evasion false positive alerts. +
+
+
PAN-263559
+
+
+ Fixed an issue where the dataplane stopped responding and the firewall + unexpectedly rebooted due to multiple process restarts. +
+
+
PAN-262729
+
+
+ (Panorama appliances only) Fixed an issue where + the + configd + process experienced continuous high CPU utilization and repeatedly + restarted. +
+
+
PAN-262540
+
+
+ Fixed an issue where application traffic transactions that reused TCP + ports did not work with decryption. +
+
+
PAN-262383
+
+
+ Fixed an issue where the firewall was unable to decompress the HTTP2 + header, which caused the session to be classified as unknown-tcp + instead of web-browsing. +
+
+
PAN-260300
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the + all_pktproc + process where DPC slot 3 stopped responding. +
+
+
PAN-260131
+
+
+ Fixed an issue where Wildfire content installation failed for WF-500B + clusters when deployed from Panorama using the deployment schedule. +
+
+
PAN-260015
+
+
+ Fixed an issue on the firewall where the dataplane restarted due to + insufficient allocation of memory buffers. +
+
+
PAN-254577
+
+
+ Fixed an issue where a core file was created on the Log Forwarding + Card due to a third-party software issue. +
+
+
PAN-249581
+
+
+ Fixed an issue where stale BGP routes were advertised to peers even + when they were not present in the local RIB table. +
+
+
PAN-249011
+
+
+ Fixed an issue where the firewall became unresponsive when committing + a configuration change with a large number of uncommitted changes in + the replay database. +
+
+
PAN-241772
+
+
+ Fixed an issue where, when TLSv1.3 was used, an incorrect error + message invalid padding was + displayed instead of the expected error message + Invalid server certificate. +
+
+
PAN-241126
+
+
+ Fixed an issue where the client IP address was incorrect in the + authentication logs for Captive Portal authentication events when the + client used IPv6. +
+
+
PAN-238594
+
+
+ Fixed an issue where the firewall rebooted when a QSFP28 cable was + removed from the port while the port was passing traffic. +
+
+
PAN-237010
+
+
+ Fixed an issue on Panorama where local commits took longer than + expected after an upgrade. +
+
+
PAN-233868
+
+
+ Fixed an issue where the firewall took an incorrect action for + overlapping custom and edl-url-categories in a policy rule. +
+
+
PAN-233581
+
+
+ Fixed an issue on firewalls in active/active HA configurations where + SYN+ACK packets of asymmetric TCP sessions were dropped because of a + session synchronization issue. +
+
+
PAN-224833
+
+
+ Fixed an issue where the firewall dropped DHCPv6 relay packets if + there were duplicate link-local addresses on different sub-interfaces. +
+
+
PAN-212735
+
+
+ Fixed an issue where sessions that were previously in sw-cut-through + mode (software fast forwarding) and persisted after an HA failover + were no longer subject to software fast forwarding, which led to + increased dataplane CPU load after HA failover. +
+
diff --git a/reference/PAN-OS/addressed/10.2.13.html b/reference/PAN-OS/addressed/10.2.13.html new file mode 100644 index 0000000..5a6ea3f --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.13.html @@ -0,0 +1,1188 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-268823
+
+
+ Fixed an issue where + Monitor > Log Display did not + display all logs when you applied a filter. +
+
+
PAN-268501
+
+
+ Fixed an issue where the firewall was unable to generate a TSF file + due to a full root partition. +
+
+
PAN-268339
+
+
+ Fixed an issue where + syslog-ng failed to start due to + the syslog-ng.config file being corrupted when upgrading from PAN-OS + 10.2.9-h1 to PAN-OS 10.2.11. +
+
+
PAN-267660
+
+
+ Fixed an issue where UserID stopped working when the + show object registered user CLI + command was used with start-point and limit options. +
+
+
PAN-266698
+
+
+ Fixed an issue where an email was able to be transferred to the + destination MTA even when the firewall detected a suspicious file with + a reset-bot action when it was encrypted by STARTTLS. +
+
+
PAN-266695
+
+
+ Fixed an issue on Panorama where a cyclic nested address group + configuration caused the + configd + process to stop responding after a commit. +
+
+
PAN-266427
+
+
+ Fixed an issue on the firewall where, when a high number of SD-WAN + branch sites or interfaces were not connected, SD-WAN processes and + tund + processes stopped responding due to a high probing rate. +
+
+
PAN-265963
+
+
+ Fixed an issue where the + escd + process caused a memory leak when session resiliency was enabled on + the firewall. +
+
+
PAN-265900
+
+
+ Fixed an issue where the firewall stopped responding due to a + tund + process or SD-WAN process restart. +
+
+
PAN-265742
+
+
+ Fixed an issue on the Panorama web interface where the + OK button on the GlobalProtect + gateway configuration dialog box was not clickable. +
+
+
PAN-265686
+
+
+ Fixed an issue where the GlobalProtect portal logged passwords in + cleartext. +
+
+
PAN-264249
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using + SNMP. +
+
+
PAN-264246
+
+
+ Fixed an issue where the Authentication Portal did not work properly + with session cookies when the request to the portal contained the + header Sec-Fetch-Site=cross-site. +
+
+
PAN-263973
+
+
+ Fixed an issue where log collectors had a low incoming log rate. +
+
+
PAN-263843
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall received no-license packet buffers instead of memory + based packet buffer numbers. +
+
+
PAN-263749
+
+
+ Fixed an issue where disk space that was used by file descriptors was + not freed, which caused the root partition to become full and Panorama + to be inaccessible. +
+
+
PAN-263674
+
+
+ (VM-Series firewalls in HA configurations only) + Fixed an issue where the firewall rebooted due to multiple HA + failovers. +
+
+
PAN-263291
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when + the GlobalProtect clientless VPN was configured. +
+
+
PAN-263287
+
+
+ The PAN-COMMON-MIB.my file was updated to support new object + identifiers (OID) to poll interface use via SNMP with table + identifiers. +
+
+
PAN-263270
+
+
+ Fixed an issue where, after a commit was performed from Strata Cloud + Manager, the SD-WAN configuration containing BGP routes did not + display on the hub firewall. +
+
+
PAN-262946
+
+
+ Fixed an issue on the firewall where logging in via the CLI or web + interface did not work due to increased memory usage. +
+
+
PAN-261936
+
+
+ Fixed an issue where WildFire submission logs were not displayed when + filtered by Sender Address. +
+
+
PAN-261673
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled, + traffic was dropped because of the + flow_parse_ip_hdr counter related + to an Nvidia driver issue. +
+
+
PAN-261602
+
+
+ Fixed an issue where GlobalProtect Decryption logs were not forwarded + to Panorama. +
+
+
PAN-260842
+
+
+ A CLI command was introduced to address an issue where TCP packets + were out of order. +
+
+
PAN-260796
+
+
+ Fixed an issue where servers were not accessible through an active SSL + GlobalProtect VPN tunnel until a new connection was established or the + session was cleared on the firewall. +
+
+
PAN-260752
+
+
+ Fixed an issue where the firewall did not support TLSv1.3 in the + Clientless VPN, which caused the portal page to not load. +
+
+
PAN-260604
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput + utilization stats in NetFlow analyzer tools. +
+
+
PAN-260564
+
+
+ Fixed an issue on firewalls in HA configurations where a network loop + was detected by switches after suspending HA on the active firewall. +
+
+
PAN-260546
+
+
+ (PA-440 firewalls only) Fixed an issue where + the system clock reset to the epoch date and time after 8 to 12 weeks + of shelf life or no power. +
+
+
PAN-260316
+
+
+ Fixed an issue where the + all_task + process stopped responding and the firewall rebooted. +
+
+
PAN-260290
+
+
+ Fixed an issue for fixed model licenses to support new content size + requirements by reducing the total sessions supported to be equivalent + to their flex memory counterpart +
+
+
PAN-260279
+
+
+ Fixed an issue where selective push operations failed with the error + message: + Failed to generate selective push configuration. Schema validation + failed. Please try a full push. +
+
+
PAN-259910
+
+
+ Fixed an issue where the firewall reported the same value over + consecutive SNMP polls when asynchronous mode was enabled. +
+
+
PAN-259870
+
+
+ (PA-7000b firewalls only) Fixed an issue where + Luna Network Hardware Security Modules (HSM) did not work after an + upgrade or downgrade. +
+
+
PAN-259767
+
+
+ Fixed an issue where GlobalProtect users were unable to connect when + the option + Block sessions if the certificate was not issued to the + authenticating device + was enabled in the certificate profile. +
+
+
PAN-259727
+
+
+ (Panorama appliances in HA configurations only) + Fixed an issue where Panorama became unresponsive and displayed a 504 + gateway timeout error when accessing the web interface or the CLI. +
+
+
PAN-258996
+
+
+ Fixed an issue where the firewall displayed the SFP ports as + PowerDown when the SFP + transceiver was removed and reinserted or the port was shut down and + brought back up on the peer device. +
+
+
PAN-258912
+
+
+ (PA-7000b firewalls only) Fixed an issue where + the firewall web interface displayed an incorrect HSM client version + when the client was upgraded to version 7.2.0.220. +
+
+
PAN-258570
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the + varrcvr + process progressively using more memory when WildFire file forwarding + is handling PE files. +
+
+
PAN-258166
+
+
+ (PA-220 firewalls only) Fixed an issue where + the root partition frequently reached 100%. +
+
+
PAN-257736
+
+
+ (PA-5450 firewalls only) Fixed an issue where + traffic to benign applications was was impacted by holding TCP + sequential segments for MLC inspection and not releasing the full + chain after a benign verdict was received. +
+
+
PAN-257601
+
+
+ (PA-5450 firewalls only) Fixed an issue where + Networking Cards (NC) experienced an internal link fault which caused + path monitoring failure on the Dataplane Processing Card (DPC). +
+
+
PAN-257327
+
+
+ (PA-5440 firewalls only) Fixed an issue where a + failover event occurred unexpectedly on the firewall. +
+
+
PAN-256560
+
+
+ Fixed an issue where exporting a + Custom Report to CSV format did not + display the full report if it contained non-ASCII characters. +
+
+
PAN-256115
+
+
+ Fixed an issue where, after replacing a Panorama appliance or log + collector, the secondary Panorama appliance or log collector displayed + a disconnected status for the + inter-log collector connection. +
+
+
PAN-255653
+
+
+ Fixed an HA failover issue where, when Management Processing Card + (MPC) or Base Card (BC) failures occurred, the HA link went down, + which caused fpp-down events on one firewall. +
+
+
PAN-255190
+
+
+ Fixed an issue where the TCP timeout value was reflected incorrectly + when using application override for a custom application in TAP mode. +
+
+
PAN-253829
+
+
+ Fixed an issue where the CLI command + show running security-policy + timed out when the Security policy was large. +
+
+
PAN-252300
+
+
+ Fixed an issue where you were unable to select device groups in the + push scope for user accounts. +
+
+
PAN-252270
+
+
+ Fixed an issue on the firewall where changes were incorrectly applied + after a reboot or a restart of the + configd + process. +
+
+
PAN-251385
+
+
+ Fixed an issue where the + configd + process stopped responding when processing system logs. +
+
+
PAN-251035
+
+
+ Fixed an issue where selective push operations did not push + certificate changes to the firewall. +
+
+
PAN-250928
+
+
+ (PA-5450 firewalls in active/active HA configurations only) Fixed an issue where firewall traffic was silently dropped when + sent to the peer owner. +
+
+
PAN-250585
+
+
+ Fixed an issue where the firewall CPU use increased after upgrading + from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system + resource reporting by the REST API. +
+
+
PAN-247857
+
+
+ (PA-7050 firewalls in HA configurations only) + Fixed an issue on the firewall where a dataplane process restarted + when updating the routing table. +
+
+
PAN-247190
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall was unable to connect to Panorama after manually + uploading the license key. +
+
+
PAN-246699
+
+
+ Fixed an issue on Panorama where + Rule Usage and + Apps Seen under Security policy + rules stopped incrementing. +
+
+
PAN-244039
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the firewall dropped packets when attempting to reuse a TCP session. +
+
+
PAN-243235
+
+
+ Fixed an issue where Panorama stopped responding and rebooted + repeatedly after an upgrade. +
+
+
PAN-242479
+
+
+ Fixed an issue where a high number of packets caused high packet + descriptors on the firewall when handling EtherIP traffic. +
+
+
PAN-241022
+
+
+ Fixed an issue where rib-out routes were not displayed due to the next + hop of BGP local routes not getting matched with export filters. +
+
+
PAN-241004
+
+
+ Fixed an issue where DNS Proxy dropped client requests of the type + ns for a root domain. +
+
+
PAN-240990
+
+
+ Fixed an issue where + l3svc.py displayed incorrect + logs. +
+
+
PAN-239165
+
+
+ Fixed an issue where adding an interface in a route filter resulted in + an OSPF LSA Type-5 packet check failure, which caused redistributed + routes to be removed. +
+
+
PAN-238610
+
+
+ Fixed an issue with the Panorama Virtual Appliance where, after the + mgmtsrvr + restarted on the passive appliance, stale IP address tags were pushed + to the connected firewalls with the message + clear all registered ip addresses. +
+
+
PAN-237246
+
+
+ Fixed an issue where the + all_pktproc + process repeatedly restarted, which caused the firewall to go into a + nonfunctional state. +
+
+
PAN-233965
+
+
+ Fixed an issue where the + tund + process stopped responding, which caused push operation to managed + firewalls or making changes to local firewalls to fail. +
+
+
PAN-232530
+
+
+ Fixed an issue where the + useridd + process ran out of memory and restarted when the number of user or + user groups exceeded the threshold. +
+
+
PAN-229686
+
+
+ Fixed an issue where eBGP remained in an idle state after disabling + and enabling BGP configurations. +
+
+
PAN-229526
+
+
+ Fixed an issue where the + mprelay + process stopped responding due to a netflow session refresh taking + longer than expected to complete. +
+
+
PAN-224472
+
+
+ Fixed an issue where the TCP timeout did not refresh for sessions + using challenge-ACK, which caused the session to timeout. +
+
+
PAN-222590
+
+
+ Fixed an issue where a semicolon appeared at the end of file names of + data filtering logs. +
+
+
PAN-218873
+
+
+ Fixed an issue where a HIP mask was reused when an existing IP address + user mapping was updated by a new IP address user mapping that had a + different username but the same IP address. +
+
+
PAN-218279
+
+
+ Fixed an issue on Panorama where hostname variables displayed as + unknown when exporting template or + template stack variables in CSV format. +
+
+
PAN-214122
+
+
+ Fixed an issue where the + ikemgr + process stopped responding when processing a high number of IKEv2 SA + requests. +
+
+
PAN-213045
+
+
+ (WF-500-B appliances only) Fixed an issue where + the WildFire appliance failed to fetch device certificates due to a + syntax error in the system database format. +
+
+
PAN-195661
+
+
+ Fixed an issue where the firewall did not insert the IP address tag + into the dynamic address group after a device server restart, which + caused traffic that matched the dynamic address group Security policy + rule base failed. +
+
+
PAN-193285
+
+
+ Fixed an issue where the policy optimizer feature did not add entries + back to the mongodb database + after removing them during an upgrade or downgrade. +
+
+
PAN-188998
+
+
+ Fixed an issue where the firewall logged excessive SSL VPN debug + information. +
+
diff --git a/reference/PAN-OS/addressed/10.2.16-h1.html b/reference/PAN-OS/addressed/10.2.16-h1.html new file mode 100644 index 0000000..db64ce4 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.16-h1.html @@ -0,0 +1,255 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-290996
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS + (Connections Per Second) per vsys on firewalls after upgrading to + PAN-OS 11.1.6-h3, even when active connections were present. +
+
+
PAN-290803
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom + image, and VM-Series plugin information was not displayed in the + system information. +
+
+
PAN-290088
+
+
+ Fixed an issue where a memory leak occurred related to the + configd + process when pushing configurations from Panorama to a firewall. This + occurred when the configurations contained shared policy rules. +
+
+
PAN-289763
+
+
+ (PA-5400f firewalls only) Fixed an issue where + SD-WAN SaaS monitoring did not work with URL monitoring. +
+
+
PAN-288929
+
+
+ Fixed an issue where the + preferred_wnd value provided by + CTD (Content Threat Detection) was disregarded due to TCP bandwidth + estimation, which prevented the window from closing. +
+
+
PAN-288363
+
+
+ Fixed an issue where the MIB ID returned an incorrect value via SNMP. +
+
+
PAN-287818
+
+
+ Fixed an issue where sessions timed out sooner than expected due to + the pan_proxy_accumulation + _restore_timeout not initiating + when the accumulationsession_init + failed. +
+
+
PAN-287601
+
+
+ Fixed an issue on Panorama where commits took longer than expected. +
+
+
PAN-287056
+
+
+ Fixed an issue where BGP export policy rules with next-hop matching + failed to block the advertisement of static routes, and the firewall + incorrectly matched the egress interface IP address instead of the + original next-hop IP address of the static route, which caused the + deny rule to fail. +
+
+
PAN-287035
+
+
+ Fixed an issue where, when an application stopped responding, a large + file was created in the /opt/panlogs directory, which caused the + partition to fill up. +
+
+
PAN-287023
+
+
+ Fixed an issue where a large number of logs caused the logrcvr process + to stop responding. +
+
+
PAN-287002
+
+
+ A fix was made to address + CVE-2025-0133. +
+
+
PAN-286306
+
+
+ Fixed an issue where, when getting transceiver information from ESCC + for SFP 25G modules, the transceiver code was incorrectly updated with + Unknown instead of + 25GBase-SR. +
+
+
PAN-284744
+
+
+ A fix was made to address + CVE-2025-4229. +
+
+
PAN-278288
+
+
+ Fixed an issue where IPv6 BGP peering established between virtual + routers even without dataplane connectivity. This occurred because the + firewall used the kernel for lookups instead of the dataplane. +
+
+
PAN-268787
+
+
+ Fixed an issue where users were unable to log in to Panorama and the + following error message was displayed: + + Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of + devices. +
+
diff --git a/reference/PAN-OS/addressed/10.2.16-h4.html b/reference/PAN-OS/addressed/10.2.16-h4.html new file mode 100644 index 0000000..2c57de8 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.16-h4.html @@ -0,0 +1,404 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-297349
+
+
+ Fixed an issue where the MIB ID returned an incorrect value via SNMP. +
+
+
PAN-295342
+
+
+ Fixed an issue where the + pan_comm + process stopped responding due to insufficient time allocated to read + file descriptors when processing long messages. +
+
+
PAN-294770
+
+
+ (Firewalls in active/passive HA configurations) + Fixed an issue on firewalls where, after failover, certain subnets + were missing from the Link State Database, which prevented OSPF routes + from being immediately learned due to a Type-7 to Type-5 LSA + translation conflict in the ABR when the same LSA was advertised by + two peers in the NSSA area. +
+
+
PAN-293673
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM + condition caused by a scheduled log export using FTP to an external + FTP server. +
+
+
PAN-292539
+
+
+ (CN-Series firewalls only) Fixed an issue where + the firewall generated incomplete or corrupted tech support files + (TSF) due to high disk usage on the management plane. +
+
+
PAN-289239
+
+
+ Fixed an issue on Panorama where a new virtual system (vsys) was + automatically created with the name of a device group. +
+
+
PAN-287842
+
+
+ Fixed an issue where the + comm + process stopped responding due to missing heartbeats, which resulted + in a system alert and HA communication loss on slot1. +
+
+
PAN-287838
+
+
+ (Panorama appliances only) Fixed an issue on + the web interface where resetting the rule hit counter for multiple + policy rules failed with the error message + Failed to reset rule-hit job. +
+
+
PAN-287734
+
+
+ Fixed an issue where the error message + Scan ERR: Internal Err 1002 was + generated unexpectedly when WIF shared memory use was high. +
+
+
PAN-286615
+
+
+ Fixed an issue where the firewall double-freed shared memory when the + shared memory usage reached 100% when sending large payloads. This + occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced + WildFire (AWF), or Advanced URL Filtering were enabled. +
+
+
PAN-286231
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to + multiple firewalls with different base configurations resulted in + configuration corruption, which caused the firewall to go down. +
+
+
PAN-284003
+
+
+ Fixed an issue where clients did not receive a valid response when + searching a website due to a compression error. +
+
+
PAN-282277
+
+
+ Fixed an issue where an OOM condition on the + logrcvr + process caused interface flapping, and the interface unexpectedly went + down and then recovered without intervention. +
+
+
PAN-280536
+
+
+ Fixed an issue where firewalls that were connected to the same Cloud + Identity Engine displayed inconsistent group membership information, + with some firewalls showing only a subset of users belonging to a + group. +
+
+
PAN-279901
+
+
+ An issue was fixed where the firewall dropped fragmented TLS + ClientHello packets, which blocked access to certain websites. This + occurred because the packets arrived truncated, in varying sizes and + orders, and the firewall's heuristics failed to handle them correctly. +
+
+ To enable this fix, run: + debug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279500
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric + routing environments if the firewall did not see server-to-client + (s2c) packets of the TLS handshake. +
+
+ To use this fix, run the following CLI command: + debug dataplane set ssl-decrypt accumulate-client-hello + asym-disable yes. +
+
+
PAN-278288
+
+
+ Fixed an issue where IPv6 BGP peering established between virtual + routers even without dataplane connectivity. This occurred because the + firewall used the kernel for lookups instead of the dataplane. +
+
+
PAN-276484
+
+
+ Fixed an issue where Panorama did not display license information for + Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes. +
+
+
PAN-277034
+
+
+ Fixed an issue where WildFire reports were not fully displayed and + were not downloadable due to static resources not being found. +
+
+
PAN-267614
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to high CPU utilization on the + mongodb + process. +
+
+
PAN-220293
+
+
+ Fixed an issue where the firewall management plane could not display + BGP peer details when using the CLI command + show advanced-routing bgp peer detail logical-router + <LR>. This was due to the + bgp_frr.py script failing to + parse the IPv6 address family section of the + show ip bgp neighbors json + output. +
+
+
PAN-231386
+
+
+ Fixed an issue where the + configd + process stopped responding during certificate verification. +
+
+
PAN-202905
+
+
+ Fixed an issue on the firewall web interface where the + Next Hop value was not displayed in + the static route configuration, the + admin-dist values were empty, and + the path-monitor parameters were not listed in the management server + web interface when the firewall was configured in FRR mode. +
+
+
PAN-191026
+
+
+ Fixed an issue where the + debug log receiver statistics CLI + command did not display entries for hipmatch logs. +
+
diff --git a/reference/PAN-OS/addressed/10.2.16-h6.html b/reference/PAN-OS/addressed/10.2.16-h6.html new file mode 100644 index 0000000..dd5fb2b --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.16-h6.html @@ -0,0 +1,450 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Issue IDDescription
+
PAN-304756
+
+
+ Fixed an issue on Panorama where, after you disabled the shared + optimization feature, a full configuration push to multi-vsys devices + caused a validation error. +
+
+
PAN-297775
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release, + the Visible Virtual System field referenced the vsys name instead of + the vsys ID, which caused inter-vsys routing to fail. This occurred + when a vsys display name matched one of the vsys IDs. If you're using + a multivsys environment, you must upgrade your firewalls to a fixed + PAN-OS version. The best practice is to upgrade both the firewalls and + Panorama to a fixed PAN-OS version. +
+
+ If you don't upgrade Panorama to a fixed version, you'll encounter + PAN-245064, where a commit on a multivsys firewall fails with the + message + vsys name should end with a number vsys is invalid + after you + Export or push device config bundle + from Panorama. +
+
+ After you upgrade Panorama to a fixed version, you'll encounter + PAN-214177, which causes an + Export or Push device config bundle from Panorama to the firewall to fail. The workaround for PAN-214177 + is to first push only the template configuration and then push the + device group configurations. +
+
+
PAN-297349
+
+
+ Fixed an issue where the MIB ID returned an incorrect value via SNMP. +
+
+
PAN-294770
+
+
+ (Firewalls in active/passive HA configurations) + Fixed an issue on firewalls where, after failover, certain subnets + were missing from the Link State Database, which prevented OSPF routes + from being immediately learned due to a Type-7 to Type-5 LSA + translation conflict in the ABR when the same LSA was advertised by + two peers in the NSSA area. +
+
+
PAN-293673
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM + condition caused by a scheduled log export using FTP to an external + FTP server. +
+
+
PAN-292539
+
+
+ (CN-Series firewalls only) Fixed an issue where + the firewall generated incomplete or corrupted tech support files + (TSF) due to high disk usage on the management plane. +
+
+
PAN-291716
+
+
+ Fixed an issue where during a commit, the firewall experienced an + out-of-memory (OOM) condition due to a memory leak and displayed an + error message. This issue caused the device to stop responding and + reboot unexpectedly. +
+
+
PAN-291288
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a + pan_task + process restart related to page allocation failures. +
+
+
PAN-289239
+
+
+ Fixed an issue on Panorama where a new virtual system (vsys) was + automatically created with the name of a device group. +
+
+
PAN-288097
+
+
+ Fixed an issue where on the firewall where the + routed + process stopped responding after changing the MTU or any link state + parameters when OSPF and PIM were enabled on the same interface. +
+
+
PAN-287734
+
+
+ Fixed an issue where the error message + Scan ERR: Internal Err 1002 was + generated unexpectedly when WIF shared memory use was high. +
+
+
PAN-286615
+
+
+ Fixed an issue where the firewall double-freed shared memory when the + shared memory usage reached 100% when sending large payloads. This + occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced + WildFire (AWF), or Advanced URL Filtering were enabled. +
+
+
PAN-286231
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to + multiple firewalls with different base configurations resulted in + configuration corruption, which caused the firewall to go down. +
+
+
PAN-285208
+
+
+ Fixed an issue where the firewall did not automatically recover after + a machine check exception (MCE) occurred. +
+
+
PAN-284067
+
+
+ Fixed a cumulative memory leak in the + devsrvr + process that occurred whenever the CLI command + show running application statistics + was issued. This memory leak would gradually consume system memory and + produce an OOM condition, causing the firewall to reboot. +
+
+
PAN-284003
+
+
+ Fixed an issue where clients did not receive a valid response when + searching a website due to a compression error. +
+
+
PAN-280536
+
+
+ Fixed an issue where firewalls that were connected to the same Cloud + Identity Engine displayed inconsistent group membership information, + with some firewalls showing only a subset of users belonging to a + group. +
+
+
PAN-279901
+
+
+ An issue was fixed where the firewall dropped fragmented TLS + ClientHello packets, which blocked access to certain websites. This + occurred because the packets arrived truncated, in varying sizes and + orders, and the firewall's heuristics failed to handle them correctly. +
+
+ To enable this fix, run: + debug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes +
+
+
PAN-279500
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric + routing environments if the firewall did not see server-to-client + (s2c) packets of the TLS handshake. +
+
+ To use this fix, run the following CLI command: + debug dataplane set ssl-decrypt accumulate-client-hello + asym-disable yes. +
+
+
PAN-279364
+
+
+ (VM-Series firewalls with multiple NICs only) + Fixed an issue were the queue count in the task dump displayed an + incorrect number of queues for SR-IOV interfaces due to the queue + mapping logic incorrectly using a non-multi-NIC function. +
+
+
PAN-278288
+
+
+ Fixed an issue where IPv6 BGP peering established between virtual + routers even without dataplane connectivity. This occurred because the + firewall used the kernel for lookups instead of the dataplane. +
+
+
PAN-276484
+
+
+ Fixed an issue where Panorama did not display license information for + Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes. +
+
+
PAN-267614
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to high CPU utilization on the + mongodb + process. +
+
+
PAN-231386
+
+
+ Fixed an issue where the + configd + process stopped responding during certificate verification. +
+
+
PAN-202905
+
+
+ Fixed an issue on the firewall web interface where the + Next Hop value was not displayed in + the static route configuration, the + admin-dist values were empty, and + the path-monitor parameters were not listed in the management server + web interface when the firewall was configured in FRR mode. +
+
+
PAN-191026
+
+
+ Fixed an issue where the + debug log receiver statistics CLI + command did not display entries for hipmatch logs. +
+
diff --git a/reference/PAN-OS/addressed/10.2.16-h7.html b/reference/PAN-OS/addressed/10.2.16-h7.html new file mode 100644 index 0000000..4dfd8e9 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.16-h7.html @@ -0,0 +1,394 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
+
+
Fixes were made to address the following CVEs:
+ +
+
PAN-316911
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where a newly bootstrapped firewall required a + management server restart, relicensing, or license push from Panorama + to invoke the device certificate. +
+
+
PAN-313828
+
+
+ Fixed an issue where the firewall did not forward traffic due to + memory issues on a forwarding component. +
+
+
PAN-308507
+
+
+ (Panorama managed firewalls only) Fixed an + issue where the firewall intermittently failed to maintain active log + forwarding streams to Strata Logging Service (SLS) even when duplicate + logging and enhanced application logging were enabled. +
+
+
PAN-305415
+
+
+ Fixed an issue where commits caused high dataplane CPU utilization and + briefly increased Packet Descriptors, which disrupted traffic. +
+
+
PAN-303051
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the + reportd + process due to retaining memory that was temporarily used for report + generation instead of releasing the memory for reuse, which resulted + in continuous accumulation and memory exhaustion. +
+
+
PAN-301409
+
+
+ Fixed an issue where Panorama failed to perform a selective push to a + managed device when device tags were added or modified on the policy + rules. The selective push failed with the error message + Failed to generate selective push configuration. Schema validation + failed. Please try a full push. +
+
+
PAN-297610
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade + due to the + fsck + command scanning drive partitions in parallel with the root partition, + which caused the process to take an extended amount of time. +
+
+
PAN-297295
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high + packet rates on the synthetic path in DPDK mode. +
+
+
PAN-295470
+
+
+ Fixed an issue on the firewall where the + useridd + process continuously increased its memory consumption, which resulted + in an OOM condition that caused the firewall to restart. +
+
+
PAN-292393
+
+
+ Fixed an issue where TFTP file transfers intermittently timed out in + active-active HA pairs when the TFTP control channel was processed by + one firewall and the data channel was processed by the other. This + occurred because the firewall receiving the data channel failed to + match the predicted session due to asynchronous processing of HA + messages. +
+
+
PAN-291067
+
+
+ Fixed an issue where the + devsrvr + process periodically exceeded its virtual memory limit and restarted, + which led to intermittent outages. +
+
+
PAN-289249
+
+
+ Fixed an issue where a memory leak occurred on the + reportd + process when a WildFire update was initiated while device telemetry + data collection was in progress. This resulted in an OOM condition. +
+
+
PAN-286094
+
+
+ Fixed an issue where the firewall did not forward logs to SLS when + using a proxy server configuration due to an OCSP validation failure. +
+
+
PAN-285208
+
+
+ Fixed an issue where the firewall did not automatically recover after + a machine check exception (MCE) occurred. +
+
+
PAN-242952
+
+
+ Fixed an issue where high SSL traffic depleted flex memory, which + prevented the firewall from revalidating SSLVPN client CAs during + configuration pushes. +
+
diff --git a/reference/PAN-OS/addressed/10.2.16.html b/reference/PAN-OS/addressed/10.2.16.html new file mode 100644 index 0000000..9e66ee5 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.16.html @@ -0,0 +1,495 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-289102
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, + PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and + CN-Series firewalls only) Fixed a race condition issue related to predict processing, which + resulted in a dataplane restart and traffic loss. +
+
+
PAN-287611
+
+
+ Fixed an issue where, after upgrading, the firewall incorrectly + calculated the UDP checksum for RTP traffic after NAT and Security + policy application, which led to dropped packets and silent calls in + applications. +
+
+
PAN-286897
+
+
+ Fixed an issue where the + pan_task + process stopped responding when the firewall attempted to forward + files to the WildFire public cloud, which caused the dataplane to + experience heartbeat failures. +
+
+
PAN-286475
+
+
+ Fixed an issue where the option to sort sequence numbers was missing + from Filters prefix list in the + advanced routing filters. +
+
+
PAN-285941
+
+
+ Fixed an issue where high memory consumption occurred on the + logrcvr + process. +
+
+
PAN-285894
+
+
+ Fixed an issue where the + all_task + process stopped responding, which caused the firewall to reboot + unexpectedly, and traffic failures occurred. +
+
+
PAN-285590
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments + only) Fixed an issue where the firewall CPU usage reached 100% after + upgrading to PAN-OS 11.1.6-h1. +
+
+
PAN-284908
+
+
+ Fixed an issue where retrieving filenames from OneDrive resulted in a + cache miss. +
+
+
PAN-284840
+
+
+ (PA-5220 firewalls only) Fixed an issue where + custom reports were delayed when sent via email instead of being sent + at the scheduled time. +
+
+
PAN-284069
+
+
+ Fixed an issue where, after an upgrade, the total number of logout + records in the HIP database incorrectly displayed as zero. +
+
+
PAN-284066
+
+
+ Fixed an issue where, after an upgrade, the SNMP polled values for + IF-MIB::ifInErrors displayed a + high number of errors that did not match the values in the CLI show + interface command. +
+
+
PAN-283664
+
+
+ Fixed an issue where a slow NAT leak occurred when persistent NAT was + enabled. This occurred when ICMP sessions matched the persistent + Dynamic IP and Port (DIPP) rule and no predict sessions were involved + in that rule. +
+
+
PAN-283428
+
+
+ (PA-7050 Firewalls only) Fixed an issue where, + after an upgrade, the dataplane CPU reached 100% due to packet buffer + exhaustion, which resulted in general packet processing issues. +
+
+
PAN-281797
+
+
+ Fixed an issue where firewalls became unstable and stopped responding, + which resulted in an OOM condition. +
+
+
PAN-280505
+
+
+ Fixed an issue where the web interface did not display a message to + commit prior changes before attempting a partial configuration load. +
+
+
PAN-280409
+
+
+ Fixed an issue where the popup window did not appear as expected for + Clientless VPN users. +
+
+
PAN-279706
+
+
+ (M-600 appliances only)) Fixed an issue where + Panorama did not update all + panreplay database entries after + performing a commit and full push to all devices. +
+
+
PAN-277617
+
+
+ Fixed an issue where deleting the NTP server address caused a commit + validation error. This occurred when the configuration included both + primary and secondary NTP servers and the secondary server was + removed. +
+
+
PAN-273727
+
+
+ Fixed an issue where the firewall skipped the DNS policy rule of a + domain external dynamic list (EDL) during an EDL refresh. +
+
+ To use this fix, run the following CLI command and commit: + set deviceconfig setting ctd custom-edl-domains-continuous-reload + yes/no +
+
+
PAN-271701
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and + Enhanced Application Log stopped working due to incorrect memory usage + accounting, which caused memory usage to remain at 99% after an + extended period of time. +
+
+
PAN-270379
+
+
+ Fixed an issue where socket files created in the /tmp directory were + not cleared. +
+
+
PAN-268614
+
+
+ Fixed an issue on the web interface where, when all rules were + highlighted when a read-only admin user clicked the + Highlight Unused Rules checkbox. +
+
+
PAN-268313
+
+
+ Fixed an issue where the Priority Code Point (PCP) bits in the VLAN + header were not reset to 0 when a packet was received from one Layer 3 + tagged interface and forwarded to another, which resulted in dropped + packets. +
+
+ To use this fix, run the CLI command + set force-vlan-pcp-reset yes and + reboot the firewall. +
+
+
PAN-267707
+
+
+ Fixed an issue where BFD sessions did not come up even when BGP + peering was established. +
+
+
PAN-265782
+
+
+ Fixed an issue on Panorama where, after you enabled multihop in a BFD + profile, you were unable to disable it via the web interface. +
+
+
PAN-260132
+
+
+ Fixed an issue where secondary IP addresses with a /32 prefix + configured on Layer 3 interfaces were not reachable in FRR mode. +
+
+
PAN-260015
+
+
+ Fixed an issue on the firewall where the dataplane restarted due to + insufficient allocation of memory buffers. +
+
+
PAN-255654
+
+
+ Fixed an issue where, when QoS was enabled on aggregate interfaces, + the maximum aggregate interface throughput was capped, which limited + network traffic. This occurred even with default QoS settings and no + configured egress max-bandwidth. +
+
+
PAN-253187
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the class of service (CoS) priority bit was not modified, causing + access points to lose connectivity to the wireless controller when + traffic was routed through the firewall. +
+
+
PAN-240606
+
+
+ Fixed an issue where licenses expired a day before the expiry date. +
+
+
PAN-224729
+
+
+ Fixed an issue where you were unable to create duplicate entries in + Advanced Routing AS path prepend in the BGP filter route map. +
+
+
PAN-224020
+
+
+ Fixed an issue where CIE validation checks on the firewall prevented + configuration pushes from Panorama, which resulted in commit failures + during new firewall deployment. This occurred when a template with an + Authentication Profile with the + Authentication Type as + Cloud Authentication Service was + pushed to a newly deployed firewall without internet access or without + a device certificate. +
+
+
PAN-220435
+
+
+ (VM-Series firewalls only) Fixed an issue where + the GlobalProtect client failed to install on the firewall. +
+
diff --git a/reference/PAN-OS/addressed/12.1.4-h6.html b/reference/PAN-OS/addressed/12.1.4-h6.html new file mode 100644 index 0000000..1e6eccd --- /dev/null +++ b/reference/PAN-OS/addressed/12.1.4-h6.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
+
+
+ A fix was made to address + CVE-2026-0257. +
+